Sub-processors
The third parties we use to run StackSpend, and exactly what each one receives.
Last updated: 24 August 2026
How we notify you of changes
Under clause 6.3 of our Data Processing Addendum, we notify your organisation's administrative contact by email at least 30 days before a new sub-processor begins processing your data, and update this page at the same time. You can object on reasonable data-protection grounds within 15 days, and if we cannot resolve the objection you may terminate the affected part of the service without penalty and receive a pro-rata refund.
Current sub-processors
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Supabase | Database and authentication | Account data, cost and usage data, audit logs | United States |
| Railway | Application hosting (API and background workers) | Customer Personal Data in transit and in process memory | United States |
| Vercel | Application hosting (web frontend) | Standard web request data | United States |
| Stripe | Payment processing and subscription management | Billing contact email, subscription details | United States / Ireland |
| Twilio SendGrid | Transactional email delivery | Recipient email address, report and alert content | United States |
| OpenAI | Model inference for automated classification and cost-intelligence chat | Provider service and SKU names; where source-control correlation is enabled, change-request titles, descriptions, labels, changed file paths and diff content; cost-intelligence chat messages | United States |
Location is each sub-processor's country of establishment. International transfers are covered by the Standard Contractual Clauses and the UK Addendum, as set out in section 11 of the DPA.
Optional integrations you control
These receive data only if you switch them on, and only what you direct them to receive. They are not sub-processors — your relationship with them is your own.
| Destination | Purpose | Data sent |
|---|---|---|
| Slack | Notifications | Cost summaries, alert content |
| Microsoft Teams | Notifications | Cost summaries, alert content |
Providers you connect are not sub-processors
When you connect a cloud or AI provider — AWS, GCP, Azure, OpenAI, Anthropic, Cursor or any other — we read billing data from that provider using the read-only credentials you supply. We disclose nothing to them. OpenAI appears in the table above for a separate reason: we use it for model inference. The two roles are unrelated, and the data flows in opposite directions.
Questions
Email privacy@stackspend.app. See also our Privacy Policy, Security overview, and Data Processing Addendum.