inklee

Subprocessor List

Last updated: 2026-08-17

ProviderPurposeData categoriesRegion / transfer notesStatus
SupabaseAuthentication, Postgres database, object storage, Row Level SecurityArtist account data, client booking request data, magic-link token hashes, audit logsEU (Frankfurt)Confirmed live. Supabase Inc. DPA in force; sub-processor list at https://supabase.com/legal/dpa.
VercelApplication hosting, edge functions, CDNAll in-transit traffic; minimal operational logsEU functions region; operational and edge logs may transit to the US (DPF / SCCs)Confirmed live. Vercel DPA in force; verify EU function region setting in production.
ResendTransactional email deliveryRecipient email, sender, subject and body of transactional emails (including booking notifications), delivery metadataEU region preferred; some routing may be US-based (DPF / SCCs)Confirmed live.
StripePayment processing for in-app card deposits via Stripe Connect (Custom accounts; destination charges with on_behalf_of + application_fee_amount)Card data entered directly into Stripe's hosted fields. Inklee never sees or stores card numbers. Inklee stores only Stripe identifiers (payment-intent ID, refund ID), deposit amount and status, and the platform-fee amount.Global; transfers under DPF / SCCsConfirmed live. Stripe is the independent controller of card data and the regulated PSP. The artist is the merchant of record for the deposit; the deposit settles into the artist's own Stripe account; Inklee never holds funds, only receives its platform fee.
Plausible AnalyticsCookie-free website analyticsAggregated, non-identifying traffic metadata; IP address hashed and discardedEUConfirmed live.
SentryError and performance monitoringStack traces, request metadata, potentially incidental personal data depending on contextEU region preferred; SCCs as fallbackConfirmed live. Configure data-scrubbing rules to minimise incidental personal data capture.
UpstashRate limiting (Redis)IP addresses and request metadata; no booking contentEU region preferred; verify EU in productionConfirmed live.
CloudflareDNS, CDN, security, email routing (where used)Connection metadata; routed email if Cloudflare Email Routing is enabledGlobal edge network; transfers under DPF / SCCsConfirmed live.
Google (OAuth)Optional sign-in for artistsIdentifier returned by Google OAuth (Google account ID, email, name, profile image)Global; transfers under DPF / SCCsConfirmed live.
Expo (push delivery)Delivering push notifications to the Inklee mobile appPush notification title and body (booking and message alerts) and the device push token. Client email addresses are redacted from the payload before sending.US; each message is relayed onward to Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) to reach the device; transfers under SCCs / DPF where applicableConfirmed live. Expo is the push relay; Google FCM and Apple APNs are the onward carriers that deliver to the device.
CARTOMap tiles for the public studio mapVisitor IP address as part of loading map tiles; no account or booking dataGlobal CDN; transfers under SCCsConfirmed live. Strictly necessary to display the map you requested; loaded only on map surfaces.
Google Maps PlatformMap and place-search features (Maps and Places JavaScript) on artist-facing surfacesIP address and interaction data of the signed-in artist using the featureGlobal; transfers under DPF / SCCsConfirmed live. Loaded on logged-in artist surfaces to provide the mapping and place-lookup features; not loaded on public client-facing pages.
Google Search ConsoleSearch-performance analytics for Inklee's own websiteAggregated search queries and impressions for inklee.app; no artist or client personal dataGlobal; transfers under DPF / SCCsConfirmed live. Used by Inklee to monitor how the site appears in Google Search.
GitHubEncrypted off-site database backups (GitHub Actions artifacts) and source controlAn AES-256-encrypted nightly dump of the production database, which includes Client Booking Request Data. No plaintext user data is stored.US; transfers under GitHub's DPA and SCCsConfirmed live. Art. 28 processor for the backup flow: the encrypted database is transferred nightly and retained for 21 days, then deleted. Source-control repositories themselves hold no production user data.
Meta PixelMarketing trackingn/an/aNot in use. Not deployed at the time of drafting. If enabled in future, this list must be updated and a consent banner introduced.