Sub-processors

LAST UPDATED · MAY 2026 · MMXXVI

This page lists the third-party services Finisit uses to process user data. We disclose them per GDPR Article 28(2) (sub-processor transparency) and as part of our customer due-diligence promise.

We notify users of new sub-processors via the canonical changelog at our public commit history and via this page's Last Updated stamp. Material changes (new processor categories, new regions) trigger a Privacy Policy update notification.

Active sub-processors

VendorServiceData sharedPurposeRegion
VercelHosting + edge networkAll app data in transitWeb hosting + serverless functionsUS (primary)
NeonManaged PostgresApplication data at restPrimary databaseUS-East
StripePayment processingName, email, billing address, last4Subscription + one-off paymentsUS, EU
PrintfulPrint-on-demandShipping name + addressPhysical merch fulfillmentUS, EU
ResendTransactional emailRecipient email + message bodyWelcome / verify / drip / receiptsUS
SentryError trackingStack traces, request IDs, user IDs (no PII payloads)ObservabilityUS, EU
Plausible AnalyticsWeb analyticsPage URL, referrer, anonymized IPPrivacy-friendly traffic analyticsEU

Conditional sub-processors

Activated only when the corresponding feature is enabled in your account or globally:

VendorActivationData shared
OneSignal / Firebase Cloud MessagingWhen push notifications enabledDevice push tokens
Cloudflare or Bunny CDNWhen IMAGE_CDN_PROVIDER is setPublic product image URLs
Twitch / YouTubeLive streaming pagesEmbedded video; no user data shared with these platforms by us

Data residency

Application data is stored in the US (Neon US-East). Payments are processed via Stripe's global network with EU-region selectable for European customers. Email is delivered via Resend (US) — for EU residents, contact privacy@finisit.app if you require EU-only email routing.

Standard contractual clauses

For EU/UK data subjects, transfers to US-based sub-processors rely on Standard Contractual Clauses (SCCs) per the EU Commission's 2021 model clauses. Each vendor above either operates EU regions (Sentry, Plausible) or has executed SCCs with us.

Notification of changes

We commit to:

Contact

Questions about this list, our DPA, or our sub-processor practices → privacy@finisit.app.

See also: Privacy Policy · Terms of Service · Security · security.txt