inklee

Subprocessor List

Last updated: 2026-06-03

ProviderPurposeData categoriesRegion / transfer notesStatus
SupabaseAuthentication, Postgres database, object storage, Row Level SecurityArtist account data, client booking request data, magic-link token hashes, audit logsEU (Frankfurt)Confirmed live. Supabase Inc. DPA in force; sub-processor list at https://supabase.com/legal/dpa.
VercelApplication hosting, edge functions, CDNAll in-transit traffic; minimal operational logsEU functions region; operational and edge logs may transit to the US (DPF / SCCs)Confirmed live. Vercel DPA in force; verify EU function region setting in production.
ResendTransactional email deliveryRecipient email, sender, subject and body of transactional emails (including booking notifications), delivery metadataEU region preferred; some routing may be US-based (DPF / SCCs)Confirmed live.
StripePayment processing for in-app card deposits via Stripe Connect (Express accounts; destination charges with on_behalf_of + application_fee_amount)Card data entered directly into Stripe's hosted fields. Inklee never sees or stores card numbers. Inklee stores only Stripe identifiers (payment-intent ID, refund ID), deposit amount and status, and the platform-fee amount.Global; transfers under DPF / SCCsConfirmed live. Stripe is the independent controller of card data and the regulated PSP. The artist is the merchant of record for the deposit; the deposit settles into the artist's own Stripe account; Inklee never holds funds, only receives its platform fee. PSD2 / merchant-of-record re-confirmation requested from counsel.
Plausible AnalyticsCookie-free website analyticsAggregated, non-identifying traffic metadata; IP address hashed and discardedEUConfirmed live.
SentryError and performance monitoringStack traces, request metadata, potentially incidental personal data depending on contextEU region preferred; SCCs as fallbackConfirmed live. Configure data-scrubbing rules to minimise incidental personal data capture.
UpstashRate limiting (Redis)IP addresses and request metadata; no booking contentEU region preferred; verify EU in productionConfirmed live.
CloudflareDNS, CDN, security, email routing (where used)Connection metadata; routed email if Cloudflare Email Routing is enabledGlobal edge network; transfers under DPF / SCCsConfirmed live.
Google (OAuth)Optional sign-in for artistsIdentifier returned by Google OAuth (Google account ID, email, name, profile image)Global; transfers under DPF / SCCsConfirmed live.
GitHub (if applicable)Source control; not a runtime subprocessorNone for user data at runtimen/aListed for transparency; not a runtime data flow.
Meta PixelMarketing trackingn/an/aNot in use. Not deployed at the time of drafting. If enabled in future, this list must be updated and a consent banner introduced.