Sub-processor table
| Processor | Purpose | Region | Transfer mechanism | DPA |
|---|---|---|---|---|
| Cloudflare, Inc. | Edge delivery (Workers, Pages, KV, Queues), CDN, R2 object storage, Images, Turnstile bot detection β single aggregated entry (one legal entity, one DPA, one transfer mechanism) Data: customer account, design uploads, review media (photos + video posters + transcoded MP4), logs, visitor IP + Turnstile challenge tokens (bot detection) | US (multi-region; EU jurisdictional restriction on `reviews/` prefix per ADR-0062 Β§13 β pre-EU-launch gate) | EU SCCs (controller-to-processor, 2021 modules) | Link |
| Resend Labs, Inc. | Transactional email delivery (orders, account, support, review solicitation Stage 1/fallback/reminder + statement-of-reasons) Data: customer email, order metadata, review excerpts (in statement-of-reasons emails) | US | EU SCCs | Link |
| Modal Labs, Inc. | AI inference (mockups, masks) + ADR-0062 video transcoding for reviewer-uploaded MP4/MOV (first non-AI Modal entry per ADR-0048 phase A) Data: design uploads, review video (MP4/MOV transcoded to web-friendly MP4 + poster frame) | US | EU SCCs | Link |
| Runware | AI image generation (avatar pool per backend CLAUDE.md, design assets, FLUX-family inference) Data: AI prompt text, reference images supplied by the user, generated outputs | EU + US (multi-region inference) | EU SCCs | Link |
| fal.ai | AI image / video / mask generation pipeline (printables generation, ADR-0048 mask R&D) Data: AI prompt text, reference images, generated outputs | US | EU SCCs | Link |
| Google Cloud (Vertex AI / Gemini) | AI inference for ADR-0056 Phase 2.5 vision moderation + (where applicable) Gemini-family generation Data: composition snapshots at moderation time, AI prompt text | US (snowcone-488623 GCP project; not the Encore-managed prod project) | EU SCCs | Link |
| Stripe, Inc. + Stripe Payments Europe Ltd. | Payment processing, subscription billing, Stripe Tax, Connect payouts Data: billing identity, payment card metadata (no PAN), tax address | US + Ireland (EEA customers route to Stripe Payments Europe) | Adequacy (EEA-internal) + EU SCCs (US flows) | Link |
| Encore Cloud (Encore Software AB) | Backend hosting, database, Pub/Sub, secrets Data: all customer data processed by the backend | US (configurable; EU region available) | EU SCCs | Link |
| Inngest, Inc. | Workflow orchestration for fulfillment routing (ADR-0033) Data: order metadata, fulfillment events | US | EU SCCs | Link |
| Ship24 | Cross-carrier tracking aggregation Data: recipient name, shipping address, tracking number | Estonia (EU) | Adequacy (EEA-internal) | Link |
| SanMar Corporation | Decorator order routing (PromoStandards) β blank apparel sourcing Data: recipient name, shipping address, order line items | US | EU SCCs | Link |
| FM Expressions | Decorator (DTF printing) β fulfillment partner Data: recipient name, shipping address, order line items, design files | US | EU SCCs | Link |
| OrderDesk, Inc. | Order-routing integration with decorator partners that use OrderDesk as their order-management system Data: recipient name, shipping address, order line items, design files | US | EU SCCs | Link |
| Anthropic, PBC | AI inference for product/design metadata generation, AI-assisted catalog translation pipeline, and the in-product chat assistant (Claude) Data: AI prompt text, design metadata, user-supplied chat content | US | EU SCCs | Link |
| Dash0 / Sentry | Error monitoring + tracing (per ADR-0012) Data: error stack traces, request metadata, session ID (no PII by default) | US | EU SCCs | Link |
| Tinybird (Y Combinator GmbH) | Usage analytics + materialized aggregates (per ADR-0002 + ADR-0004) Data: usage events, request metadata | EU (Frankfurt) + US | EU SCCs (US replication) | Link |
| MeiliSearch (Meili SAS) | Product / design catalog search (per ADR-0014) Data: public catalog metadata, search query logs | France (EU) | Adequacy (EEA-internal) | Link |
| Google LLC (Workspace) | Customer-support inbox hosting (Gmail) for support@snowcone.app β receipt, threading and retention of inbound support correspondence, incl. the detractor-feedback intake relayed via Resend (apps/backend/reviews/feedback-api.ts) Data: customer email, customer name, order ID + tracking number (support intake), support correspondence body, attachments uploaded by users | US (Google Workspace EU data region available; not currently pinned) | EU SCCs (Google Workspace Data Processing Amendment) | Link |
Last updated . Previous versions available on request.
Read the Privacy Policy β
