← ShareMyPage

Subprocessors

ShareMyPage uses a small number of third-party subprocessors to deliver the service. Each is bound by a data processing agreement and holds recognized security certifications (SOC 2 Type II and/or ISO 27001). This list is kept current; material changes are communicated to customers with an active DPA. Last updated: June 2026.

Primary data region: page content (Blob), the database (Postgres), and serverless compute run in the European Union (Frankfurt); transactional email (Brevo, France) and product analytics (PostHog, Frankfurt) are processed in the EU. Only auth (Clerk) and payments (Stripe) process limited data in the US, covered by the EU Standard Contractual Clauses.

SubprocessorPurposeData processedLocation
VercelApplication hosting, serverless compute, content (Blob) storage, and cookieless web analyticsPage HTML, application requestsEuropean Union (fra1, Frankfurt) — Blob storage + serverless compute; global CDN edge
NeonManaged Postgres databasePage metadata, versions, folders, comments, tokens, audit logEuropean Union (AWS eu-central-1, Frankfurt)
ClerkAuthentication and identity (Google/Microsoft OAuth, organizations)Name, email, workspace membershipUnited States
UpstashRate limiting (Redis)Transient request counters (no content)Global edge · transient counters only
StripeSubscription billing and paymentsBilling contact and payment metadataUnited States / EU
BrevoTransactional email (welcome, comment notifications, invitations)Recipient email, names, and email contentEuropean Union (France)
PostHogProduct analytics and session replay (cookieless)Pageviews, UI interaction events, approximate location from IP; never page contentEuropean Union (Frankfurt)

Identity providers (Google, Microsoft) process authentication on your behalf when your users sign in; they are not subprocessors of your page content.

Related: Security overview · Data Processing Agreement · Privacy Policy