This page lists every third-party sub-processor PixelProof engages to deliver the service, required for Enterprise customers' GDPR Article 28(3)(d) due diligence and for anyone evaluating PixelProof under an existing Data Processing Agreement (DPA). If you are an Enterprise customer, our DPA references this page directly rather than embedding a static vendor list that goes stale.
1. Current sub-processors
Every processor below is US-based and US-region for data residency. We do not use any sub-processor outside the United States as of the last-updated date above.
| Sub-processor | Country | Purpose / data processed | Data residency | DPA |
|---|---|---|---|---|
| Supabase, Inc. | United States | Primary database — stores scan results, store domains, findings, email captures, waitlist signups, and account/subscription records. | US region (AWS us-east-1) | DPA |
| Stripe, Inc. | United States | Billing — processes and stores payment card details, subscription status, and invoices for paid plans. We never see or store raw card numbers. | US region (Stripe global infrastructure, PCI DSS Level 1) | DPA |
| Resend, Inc. | United States | Transactional email — delivers scan reports, receipts, coupon codes, and account notifications. No marketing/cold email sent through this processor. | US region | DPA |
| Vercel Inc. | United States | Hosting + edge network — serves the application, runs serverless/edge functions, and terminates HTTPS. Vercel edge logs contain IP addresses and request metadata for a limited retention window. | US region (primary), global edge network for static/cached assets | DPA |
| PostHog Inc. | United States | Product analytics + masked session replay (all text/input fields masked). Only loads after cookie consent is granted — see /meta-monitor/cookies. | US region (us.i.posthog.com) | DPA |
| Functional Software, Inc. (Sentry) | United States | Client + server error tracking, so we can find and fix bugs. Client-side Sentry only loads after cookie consent is granted — see /meta-monitor/cookies. | US region | DPA |
| Apollo.io (Apollo Technologies, Inc.) | United States | Business-contact prospecting for outbound cold email to potential customers, run via Instantly (see /meta-monitor/cookies for the outbound-email disclosure). Apollo does not process any data submitted by users of the product itself. | US region | DPA |
| OpenAI / Anthropic (LLM providers) | United States | Not used at runtime. We do NOT use OpenAI, Anthropic, or any other large language model provider to process customer data at runtime. No store URL, HTS code, scan finding, email address, or other customer-submitted data is sent to an LLM API as part of any live product feature. (Internal engineering tooling — e.g. Claude Code sessions used by our team to write and audit application code — is a separate, non-customer-data context and out of scope for this disclosure.) | ||
2. What "country" and "data residency" mean here
"Country" is the sub-processor's primary legal jurisdiction of incorporation. "Data residency" is where the specific data PixelProof sends to that sub-processor is physically stored and processed. All seven vendors above store and process PixelProof data exclusively in US-region infrastructure as of August 13, 2026; none of your data is transferred to a third country outside the US under this disclosure.
3. Notification of new sub-processors
We will notify Enterprise customers 30 days in advance of adding a new sub-processor, giving you the opportunity to object per your Data Processing Agreement. Free and self-serve customers can check this page any time — the "Last updated" date above changes whenever the vendor list changes, and every change is logged in our internal publish log with the date it took effect.
4. Subscribe to sub-processor changes
Enterprise and Business customers can request proactive email notification of sub-processor changes (in addition to the 30-day DPA notice above) by emailing hello@citationsafe.com with the subject line "Subscribe to sub-processor updates" from the email address on your account. We confirm the subscription by reply within 2 business days.
5. Objecting to a new sub-processor
If you are an Enterprise customer with a signed DPA and you object to a newly announced sub-processor, contact hello@citationsafe.com within the 30-day notice window. We will work with you on a mitigation (e.g., excluding the new sub-processor from your account's data flow where technically feasible) or, if no mitigation is possible, you may terminate the affected service without penalty per your DPA's termination-for-cause clause.
8. How we vet a sub-processor before adding one
We don't add a new vendor lightly. Before any sub-processor is added to PixelProof's stack, we check: does it have a published DPA (every vendor above does); does it publish SOC 2 Type II or equivalent (Supabase, Stripe, Vercel, Sentry, and PostHog all do as of August 13, 2026); and does it actually need the data we'd send it, or can the same thing be done with a vendor we already disclose. That last question is why PixelProof runs on seven sub-processors, not seventeen.
9. How data actually flows
In plain terms: your browser talks to Vercel's edge network, which runs our application code. That code reads and writes to Supabase (the database) and, where relevant, calls Stripe (billing), Resend (transactional email), PostHog (analytics, only post-consent), or Sentry (error reports, only post-consent). None of those calls fan out further -- Supabase doesn't forward your data to Stripe, PostHog doesn't see your database rows, and nothing here trains a model or gets resold. Apollo sits entirely outside this loop; it never receives a byte of data any PixelProof user submits through the product itself.
12. Frequently asked
Do you use a payment processor other than Stripe? No — Stripe is the only payment processor in the PixelProof stack. Can I request my sub-processor list in a different format for procurement? Yes — email hello@citationsafe.com and we will send a signed PDF version of this table on request, useful for vendor-risk-assessment questionnaires that require a static document rather than a live page.
12. Related pages
- Privacy Policy — the full data-handling policy this disclosure supports.
- Cookie Policy — what cookies each of the above vendors sets in your browser.
- Terms of Service.
- About Digital Empire — who operates PixelProof and how to reach us.
13. Contact
Questions about this disclosure or a DPA request: hello@citationsafe.com (fallback: hello@citationsafe.com).
Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan WY 82801