Sub-processors

The third parties we use to run StackSpend, and exactly what each one receives.

Last updated: 24 August 2026

How we notify you of changes

Under clause 6.3 of our Data Processing Addendum, we notify your organisation's administrative contact by email at least 30 days before a new sub-processor begins processing your data, and update this page at the same time. You can object on reasonable data-protection grounds within 15 days, and if we cannot resolve the objection you may terminate the affected part of the service without penalty and receive a pro-rata refund.

Current sub-processors

Sub-processorPurposeData receivedLocation
SupabaseDatabase and authenticationAccount data, cost and usage data, audit logsUnited States
RailwayApplication hosting (API and background workers)Customer Personal Data in transit and in process memoryUnited States
VercelApplication hosting (web frontend)Standard web request dataUnited States
StripePayment processing and subscription managementBilling contact email, subscription detailsUnited States / Ireland
Twilio SendGridTransactional email deliveryRecipient email address, report and alert contentUnited States
OpenAIModel inference for automated classification and cost-intelligence chatProvider service and SKU names; where source-control correlation is enabled, change-request titles, descriptions, labels, changed file paths and diff content; cost-intelligence chat messagesUnited States

Location is each sub-processor's country of establishment. International transfers are covered by the Standard Contractual Clauses and the UK Addendum, as set out in section 11 of the DPA.

Optional integrations you control

These receive data only if you switch them on, and only what you direct them to receive. They are not sub-processors — your relationship with them is your own.

DestinationPurposeData sent
SlackNotificationsCost summaries, alert content
Microsoft TeamsNotificationsCost summaries, alert content

Providers you connect are not sub-processors

When you connect a cloud or AI provider — AWS, GCP, Azure, OpenAI, Anthropic, Cursor or any other — we read billing data from that provider using the read-only credentials you supply. We disclose nothing to them. OpenAI appears in the table above for a separate reason: we use it for model inference. The two roles are unrelated, and the data flows in opposite directions.

Questions

Email privacy@stackspend.app. See also our Privacy Policy, Security overview, and Data Processing Addendum.

Sub-processors — StackSpend