草稿,待律师审阅。[方括号] 内是法律实体占位。
Subprocessors
Status: draft pending counsel review.
Last updated: [LAST_UPDATED]
[LEGAL_ENTITY_NAME] uses the following third parties to operate Bruchim. Regions are typical defaults and must be confirmed in each provider dashboard before this list is treated as production.
This table is based on the product’s internal subprocessors document. Update both places when a service is added or removed.
| Service | Purpose | Data involved | Typical region |
|---|---|---|---|
| Clerk | Authentication, organizations, sessions | Workspace user identity, email, MFA factors | US (Clerk cloud) |
| Neon | Primary database | App data including visitor personal information | Canada or US (project choice) |
| Vercel | App and marketing hosting, serverless compute | Request logs, environment configuration | Often US |
| Vercel Blob | Object storage | Visitor photos, branding assets | Per Blob store |
| Stripe | Billing | Owner contact and subscription metadata (not visitor records) | US |
| SendGrid | Transactional email | Host and visitor notification content | US |
| Cloudflare | DNS and edge | DNS and possibly proxied request metadata | Global |
| PrintNode | Cloud print relay | Badge job payloads (may include visitor name) | Confirm in account |
| Sentry | Error monitoring | Stack traces; may include request context (PII should be scrubbed) | US or EU per org setting |
| Upstash | Rate limits; delayed jobs | IP or route keys; job identifiers | Per database / QStash region |
Marketing site only
bruchim.io uses Vercel and Cloudflare. It does not send visitor check-in data. If we add cookieless analytics later, that vendor will be added here.
Changes
We will update this page when processors change. Workspace owners who need a formal notice process should say so in a future DPA.
Contact
[PRIVACY_EMAIL]