Legal
Subprocessors
Subprocessors
Last updated: July 31, 2026
We use the following subprocessors to run the porthatch products. A new subprocessor is published on this page at least 30 days before it takes effect, and the notice also goes by email to the address on every active account — so the reliable way to track changes is this page plus your inbox, and it's worth checking here before a renewal.
Infrastructure
| Subprocessor | Purpose | Data location | Privacy policy |
|---|---|---|---|
| Cloudflare | Workers runtime, edge routing, KV cache, Queues, Workflows, R2 (Placet uploads, Sluice CSVs) | Requests are served from the edge location nearest the visitor. The R2 buckets holding uploaded media and Sluice CSVs carry Cloudflare's EU jurisdictional restriction: those objects are stored only in the European Union, and that is a guarantee rather than a placement. KV (caches, no customer content) is replicated across Cloudflare's network by design, and Queues hold messages only while they are being delivered — for those two we rely on Cloudflare's SCCs. Cloudflare remains a US-parented company whatever the storage region. | cloudflare.com/privacy |
| Neon | Managed Postgres for account, workspace, audit, and product metadata | EU — Frankfurt (aws-eu-central-1) |
neon.tech/privacy |
| GitHub | Storage for the nightly encrypted database backup, kept as a build artifact for 30 days. The dump covers the whole database — every account, every product schema — and is the only copy outside Neon. | US | github.com/privacy |
Billing
| Subprocessor | Purpose | Data location | Privacy policy |
|---|---|---|---|
| Paddle | Merchant of Record: checkout, card processing, sales-tax/VAT, subscription and credit-pack billing, and the customer portal. We do not see card numbers — they go directly to Paddle. | UK / EU + US | paddle.com/legal/privacy |
Communications
| Subprocessor | Purpose | Data location | Privacy policy |
|---|---|---|---|
| Resend | Transactional email delivery: magic-link sign-in, payment-failure notices, and subscription notifications | US | resend.com/legal/privacy |
Observability
| Subprocessor | Purpose | Data location | Privacy policy |
|---|---|---|---|
| Sentry | Application error tracking. Stack traces, request context. We never attach a user identity to an event, and email addresses are stripped from the event payload — message, exception values, URLs and breadcrumbs — before it leaves the Worker. | EU — Germany (organisation is on Sentry's EU region) | sentry.io/privacy |
| Axiom | Structured logs and metrics. Request ids, route, status, latency. No PII. | EU — Frankfurt (eu-central-1 ingest edge) |
axiom.co/privacy |
Product-specific (only relevant if you use that product)
| Subprocessor | Used by | Purpose | Data location | Privacy policy |
|---|---|---|---|---|
| Notion | Cordon | Database proxy — your Notion content stays in Notion; we hold only an integration token and a proxy audit | US (vendor). We store no Notion content — the token and audit rows live in Neon (EU) | notion.so/notion/Privacy-Policy |
| Airtable | Veneer | Base proxy — your Airtable content stays in Airtable; we hold only a Personal Access Token (encrypted at rest) and a proxy audit | US (vendor). We store no Airtable content — the token and audit rows live in Neon (EU) | airtable.com/privacy |
| Stripe | Duehatch | Source of the invoices you chase. You connect your own Stripe account with a read-only restricted key; unlike Notion and Airtable we do copy content — open invoices and the customer records attached to them (name, email, amount, due date) sync into our database so the chase sequence can run. | US (vendor). The synced copy lives in Neon (EU); the restricted key is stored encrypted. | stripe.com/privacy |
| EmailListVerify | Sluice "deep" tier | Third-party SMTP probe for email validation. Activated only on the deep tier; standard tier doesn't reach an external vendor. Receives the email addresses being verified — third-party personal data supplied by the customer. | Netherlands (hosted by WorldStream B.V.) for customers established in the EEA/UK. Which regime applies to Porthatch's own account is being confirmed with the vendor — see the note below | emaillistverify.com/privacy · DPA |
EmailListVerify carries the most sensitive data in the portfolio. Three products hold personal data belonging to people who never signed up for Porthatch: Placet keeps a reviewer's email with their approval decision, Duehatch stores the name, email and outstanding amount of your customers, and Sluice takes whole lists of addresses. What makes Sluice Deep different is not that the data is third-party — it's that this is the only place where that third-party data is forwarded to an external vendor rather than staying inside our own EU infrastructure. For all three you are the controller and we are the processor, and the warranties you give us about lawful basis and Article 13–14 notice are in Terms §4.
Their published position is that EEA/UK-established customers are served from EU servers under their DPA. Porthatch is not EEA-established, so we have asked the vendor to confirm in writing which servers process our account's requests, and this row will state the answer rather than the inference. Until then, treat the location as unconfirmed. Standard-tier verification never leaves our own infrastructure.
How we vet new subprocessors
Before adding a new subprocessor we check:
- Public privacy policy + DPA terms compatible with our customers' GDPR posture
- Compliance certifications (SOC2 Type II, ISO 27001) where applicable
- Encryption-in-transit + encryption-at-rest defaults
- Sub-processor list (so we don't add a subprocessor that fans out to another we haven't vetted)
Publishing the change is part of connecting the vendor, not an afterthought: this page is updated and the notice emailed to every active account before the vendor is wired into production, with the 30-day clock started from that publication.
How to object
If a new subprocessor is incompatible with your compliance posture, email privacy@porthatch.app within 30 days of the notice. You can exit the service with a pro-rated refund of the remaining billing period; you can download any completed results before you go.