Subprocessor List
Last updated: 2026-08-17
| Provider | Purpose | Data categories | Region / transfer notes | Status |
|---|---|---|---|---|
| Supabase | Authentication, Postgres database, object storage, Row Level Security | Artist account data, client booking request data, magic-link token hashes, audit logs | EU (Frankfurt) | Confirmed live. Supabase Inc. DPA in force; sub-processor list at https://supabase.com/legal/dpa. |
| Vercel | Application hosting, edge functions, CDN | All in-transit traffic; minimal operational logs | EU functions region; operational and edge logs may transit to the US (DPF / SCCs) | Confirmed live. Vercel DPA in force; verify EU function region setting in production. |
| Resend | Transactional email delivery | Recipient email, sender, subject and body of transactional emails (including booking notifications), delivery metadata | EU region preferred; some routing may be US-based (DPF / SCCs) | Confirmed live. |
| Stripe | Payment processing for in-app card deposits via Stripe Connect (Custom accounts; destination charges with on_behalf_of + application_fee_amount) | Card data entered directly into Stripe's hosted fields. Inklee never sees or stores card numbers. Inklee stores only Stripe identifiers (payment-intent ID, refund ID), deposit amount and status, and the platform-fee amount. | Global; transfers under DPF / SCCs | Confirmed live. Stripe is the independent controller of card data and the regulated PSP. The artist is the merchant of record for the deposit; the deposit settles into the artist's own Stripe account; Inklee never holds funds, only receives its platform fee. |
| Plausible Analytics | Cookie-free website analytics | Aggregated, non-identifying traffic metadata; IP address hashed and discarded | EU | Confirmed live. |
| Sentry | Error and performance monitoring | Stack traces, request metadata, potentially incidental personal data depending on context | EU region preferred; SCCs as fallback | Confirmed live. Configure data-scrubbing rules to minimise incidental personal data capture. |
| Upstash | Rate limiting (Redis) | IP addresses and request metadata; no booking content | EU region preferred; verify EU in production | Confirmed live. |
| Cloudflare | DNS, CDN, security, email routing (where used) | Connection metadata; routed email if Cloudflare Email Routing is enabled | Global edge network; transfers under DPF / SCCs | Confirmed live. |
| Google (OAuth) | Optional sign-in for artists | Identifier returned by Google OAuth (Google account ID, email, name, profile image) | Global; transfers under DPF / SCCs | Confirmed live. |
| Expo (push delivery) | Delivering push notifications to the Inklee mobile app | Push notification title and body (booking and message alerts) and the device push token. Client email addresses are redacted from the payload before sending. | US; each message is relayed onward to Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) to reach the device; transfers under SCCs / DPF where applicable | Confirmed live. Expo is the push relay; Google FCM and Apple APNs are the onward carriers that deliver to the device. |
| CARTO | Map tiles for the public studio map | Visitor IP address as part of loading map tiles; no account or booking data | Global CDN; transfers under SCCs | Confirmed live. Strictly necessary to display the map you requested; loaded only on map surfaces. |
| Google Maps Platform | Map and place-search features (Maps and Places JavaScript) on artist-facing surfaces | IP address and interaction data of the signed-in artist using the feature | Global; transfers under DPF / SCCs | Confirmed live. Loaded on logged-in artist surfaces to provide the mapping and place-lookup features; not loaded on public client-facing pages. |
| Google Search Console | Search-performance analytics for Inklee's own website | Aggregated search queries and impressions for inklee.app; no artist or client personal data | Global; transfers under DPF / SCCs | Confirmed live. Used by Inklee to monitor how the site appears in Google Search. |
| GitHub | Encrypted off-site database backups (GitHub Actions artifacts) and source control | An AES-256-encrypted nightly dump of the production database, which includes Client Booking Request Data. No plaintext user data is stored. | US; transfers under GitHub's DPA and SCCs | Confirmed live. Art. 28 processor for the backup flow: the encrypted database is transferred nightly and retained for 21 days, then deleted. Source-control repositories themselves hold no production user data. |
| Meta Pixel | Marketing tracking | n/a | n/a | Not in use. Not deployed at the time of drafting. If enabled in future, this list must be updated and a consent banner introduced. |