Subprocessors & Service Providers
We use a deliberately small set of infrastructure providers.
Subprocessors
These providers process personal data on our behalf:
| Provider | Service | Data | Location | Safeguards |
|---|---|---|---|---|
| Google LLC (Google Cloud / Firebase) | Hosting, database (Firestore), authentication, key management (Cloud KMS), serverless compute | Account data, item metadata, encrypted OAuth tokens, logs | Primary database region: London (europe-west2), EU. Firebase Authentication processes data exclusively in US data centres. | Google Cloud Data Processing Addendum; SCCs; EU–US Data Privacy Framework; ISO 27001, SOC 2/3. Subprocessor list: firebase.google.com/terms/subprocessors |
| Google LLC (Gemini API — paid tier) | AI inference for priority scoring | Item titles/metadata and transiently read recent email text; AI outputs | United States | Paid-tier terms: prompts/responses not used to improve models; retained up to 55 days solely for abuse monitoring; processor Data Processing Addendum |
Independent controllers we work with
They decide how they process data under their own privacy notices:
| Provider | Role | Notes |
|---|---|---|
| Paddle.com Market Ltd / Paddle.com Inc. | Merchant of Record — checkout, payment, tax, invoicing, refunds | Your purchase is from Paddle; paddle.com/legal/privacy |
| Connected source providers you choose (Google, Microsoft, ClickUp, Monday.com, Slack, Asana) | The services you connect | We access them read-only at your direction under your agreements with them |
Changes: we update this page at least 30 days before adding a subprocessor (except emergency security replacements, notified promptly). Subscribe to changes: email justduedate7@gmail.com with subject "Subprocessor updates".
Justduedate7