TRUST & COMPLIANCE
Subprocessors
To support delivery of our services, Costframe engages third-party infrastructure, identity, billing, email, analytics, and observability providers. Below is the transparent list of authorized providers and the region posture we can currently disclose.
Scope Notice:We list services active in production or configured for production telemetry. Customers’ own AWS, Azure, and GCP cloud environments are client-owned and are not subprocessors. We choose EU regions where available and appropriate, but vendor subprocessors may process data in other locations under their own data-processing terms and transfer safeguards.
| Subprocessor | Purpose | Data Category | Configured Region | Notes | Status |
|---|---|---|---|---|---|
| Supabase | Database & storage | Workspace data, encrypted credentials, cost snapshots, metadata | Configured project region; EU preferred where provisioned | Supabase DPA and subprocessors apply. | Active |
| Clerk | Authentication & identity | User profiles, emails, sessions | Global / vendor subprocessor locations | Account Portal, sessions, organizations, and identity flows. | Active |
| Stripe | Billing & subscriptions | Customer, subscription, invoice, tax, and payment metadata | Global, including US and EU infrastructure | Stripe stores and processes payment data under its DPA and service-provider terms. | Active |
| Resend | Transactional email | Recipient emails, message metadata, notification content | US / vendor subprocessor locations | Used for system email and customer notifications. | Active |
| PostHog | Product analytics | Usage events (no credentials) | EU Cloud where configured; otherwise selected PostHog region | Use the EU Cloud host for EU-hosted product analytics where configured. | Active |
| Vercel | Web hosting, analytics, and speed insights | Website telemetry, deployment logs, edge request metadata | Global edge / vendor subprocessor locations | Vercel Analytics is designed without third-party cookies. | Active |
| Railway | API and worker hosting | Application logs, runtime metadata, API processing | EU compute region where configured; vendor subprocessors may vary | Use EU compute regions for API and worker services where configured. | Active |
| Sentry | Error monitoring and performance telemetry | Error events, stack traces, release and browser metadata | Selected Sentry data location | Avoid sending secrets or customer cloud payloads in error context. | Active |
| Google Analytics | Website analytics | Page views, device/browser data, approximate location, events | Google global processing locations | Used for website measurement; governed by Google Analytics data-processing terms. | Active |
| Ahrefs Analytics | Website analytics | Page-view and referrer analytics | Vendor processing locations | Ahrefs states its web analytics uses no cookies and collects no personal data by default. | Active |