Subprocessors
Providers that may process personal data while delivering ReviveDB.
- Cloudflare R2
- Encrypted managed backup objects and object metadataBackup objects stay in Cloudflare R2's EU jurisdiction with no non-EU storage option. Cloudflare's data processing addendum and EU Standard Contractual Clauses cover authorised access from outside the EEA.
- Railway
- Application hosting, operational logs, app database and verification databaseRailway hosts ReviveDB's API, workers, application database, verification databases and operational logs. Railway is US-based; a signed data processing addendum and EU Standard Contractual Clauses cover applicable transfers.
- Resend
- Sign-in and operational email deliveryEmail for revivedb.dev is dispatched from Resend's Ireland region. Resend stores account data, email metadata, logs and API records in the United States; its data processing addendum includes EU Standard Contractual Clauses and the EU-US Data Privacy Framework for applicable transfers.
- Vercel
- Frontend hosting and cookieless analytics on public pages; query strings are removed before analytics events are sentVercel is US-based and its primary processing takes place in the United States: its data processing addendum applies automatically, with EU standard contractual clauses covering the transfer.
- PostHog
- Cookieless, pseudonymous server-side lifecycle events and a browser survey that loads only when you open FeedbackEU Cloud hosting (Frankfurt). Provider is US-based: EU standard contractual clauses and Data Privacy Framework apply.
- Stripe
- Billing identity, subscription state and payment method; Stripe holds card data and ReviveDB does not store itStripe determines processing location. Its data processing addendum incorporates EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. ReviveDB never stores card data.
- Optional Google sign-in and verified account emailGoogle processes optional sign-in under its published privacy and transfer terms. No customer backup contents or project credentials are sent to Google.
- Sanity
- Public website and blog content deliverySanity serves public website and blog content only. No customer account data, project credentials or backup contents are sent to Sanity.
- Better Stack
- External uptime monitoring of the public health endpoints; the monitored responses contain component status only, no account, project or backup dataOnly component status from public health endpoints is monitored; no account, project, credential or backup data is included. Better Stack's DPA uses the Data Privacy Framework and Standard Contractual Clauses for applicable transfers.
We provide advance notice of material subprocessor changes. Questions or objections can be submitted through our contact page.