Subprocessors
Last updated: 21 September 2026Effective: 21 September 2026Version 1.0
In plain language
This page names every third party that processes data on our behalf. It is the authoritative list referenced by Annex 3 of the Data Processing Addendum.
Your telemetry and account data are stored on Hetzner Online GmbH infrastructure in Helsinki, Finland (EU). Three subprocessors come into contact with telemetry — the hosting provider, our CDN, and our transactional email provider, because alert and on-call emails carry exception messages and monitor names. The rest handle billing, optional sign-in or website analytics, and never receive telemetry.
We give 30 days’ notice before a new subprocessor starts processing customer data, and you can object.
This summary is for orientation only. The numbered sections below are the binding text.
1.Current subprocessors
As at 21 September 2026. The list is split by the role TracePath plays, because that determines which agreement governs the provider. Rows marked conditional only process data when the feature named is in use; if you never sign in with Google, for example, Google never receives anything about you.
Subprocessors of Customer telemetry — Annex 3 of the DPA
These process Customer Personal Data contained in telemetry, where TracePath acts as processor. They are the providers the change-notice and objection right in section 3 of this page, and section 7 of the DPA, applies to.
| Subprocessor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Hetzner Hetzner Online GmbH (Germany), with Hetzner Finland Oy operating the Helsinki site Privacy notice | Cloud infrastructure: the application servers, PostgreSQL, ClickHouse and object storage that run the Service. | All Service data — account data, billing records and all Customer telemetry. | Helsinki, Finland (EU). Provider established in Germany (EU). | No transfer outside the EEA. |
| Cloudflare Cloudflare, Inc. (US) / Cloudflare Germany GmbH Privacy notice | Authoritative DNS, CDN and reverse proxy in front of the websites and the API, TLS termination at the edge, WAF and DDoS protection, Turnstile bot protection on sign-up, and email routing for the @tracepath.dev mailboxes. | Connection metadata (IP address, user agent, request headers, requested URL), request and response content while in transit, and the envelope and content of email routed to our mailboxes. | Global edge network, including locations outside the EEA. | EU Standard Contractual Clauses (Decision 2021/914) under the Cloudflare Customer DPA; Cloudflare also self-certifies under the EU–US Data Privacy Framework. |
| Resend Resend (Plus Five Five, Inc.), United States Privacy notice | Transactional email delivery: email verification, password reset, team invitations, alert and on-call notifications, and quota warning emails. | Recipient email address and name, message subject and body, and delivery metadata (timestamps, delivery and bounce status). | United States. | EU Standard Contractual Clauses under Resend's DPA; Resend also relies on the EU–US Data Privacy Framework. |
Processors of account, billing and website data — controller-side
These never receive Customer telemetry. They process account, billing, sign-in or marketing-website data, for which TracePath is the controller; they are covered by section 7 of the Privacy Policy rather than by the DPA.
| Processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Stripe Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (US) Privacy notice | Payment processing, subscription management, invoicing and the self-service billing portal. | Billing contact name and email, company name, VAT identification number, billing country and address, subscription and invoice records, and payment instrument data. Payment card details are entered directly into Stripe Checkout and are never received or stored by TracePath. | Ireland (EU) and the United States. | Stripe's own DPA with EU Standard Contractual Clauses; Stripe self-certifies under the EU–US Data Privacy Framework and its UK Extension. |
| Google (OAuth sign-in) Google Ireland Limited / Google LLC Privacy notice Conditional: Only when a user chooses to sign in with Google. | Optional “Sign in with Google” for user authentication. | Google account identifier, email address, display name and avatar URL, received from Google when a user chooses this sign-in method. | European Union and the United States. | EU Standard Contractual Clauses; Google LLC self-certifies under the EU–US Data Privacy Framework. |
| GitHub (OAuth sign-in) GitHub, Inc. (a Microsoft company), United States Privacy notice Conditional: Only when a user chooses to sign in with GitHub. | Optional “Sign in with GitHub” for user authentication. | GitHub account identifier, email address, display name and avatar URL, received from GitHub when a user chooses this sign-in method. | United States. | EU Standard Contractual Clauses under the Microsoft/GitHub data protection terms; Microsoft self-certifies under the EU–US Data Privacy Framework. |
| Google Analytics 4 Google Ireland Limited / Google LLC Privacy notice Conditional: Only loads on tracepath.dev after the visitor accepts analytics in the consent banner, and only if analytics is configured for the deployment. Never runs on app.tracepath.dev. | Aggregate website usage statistics for tracepath.dev. | Pseudonymous usage data: pages viewed, referrer, approximate location derived from a truncated IP address, device and browser type, and a randomly generated analytics identifier stored in cookies. | European Union and the United States. | EU Standard Contractual Clauses; Google LLC self-certifies under the EU–US Data Privacy Framework. |
| Plausible Analytics Plausible Insights OÜ, Estonia Privacy notice Conditional: Only loads on tracepath.dev after the visitor accepts analytics in the consent banner, and only if analytics is configured for the deployment. | Cookieless, aggregate website usage statistics for tracepath.dev — the privacy-preserving alternative to Google Analytics. | Aggregated page views, referrer and device class. No cookies and no cross-site identifiers. | European Union. | No transfer outside the EEA. |
Note
2.Where your data lives
All production systems — the application, the API, the telemetry endpoint, PostgreSQL, ClickHouse and object storage — run on infrastructure provided by Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) in Helsinki, Finland (EU).
That is inside the European Union. Storing customer telemetry there means no cross-border transfer is involved in the storage itself, which materially simplifies the transfer analysis for EU customers. The provider maintains an ISO/IEC 27001 certified information security management system covering the Helsinki site, and we have a data processing agreement with it under Article 28 GDPR.
We do not currently offer a data residency option outside the EU. If you need one, talk to [email protected] before you commit to a plan rather than after.
3.Notice of changes and your right to object
- We publish intended additions and replacements here, and email the owners of every affected organisation, at least 30 days before the new subprocessor starts processing customer data.
- To receive these notices at a specific address — a security or procurement mailbox rather than the account owner — write to [email protected] and we will add it.
- You may object on reasonable data-protection grounds within the notice period. We will discuss it with you in good faith and look for an alternative.
- If we cannot provide the service without that subprocessor and cannot offer a commercially reasonable alternative, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees. The full mechanism is in section 7 of the DPA.
- Where a change is required to keep the service running or secure — for example an emergency migration away from a failing provider — we may act on shorter notice and will explain why at the time.
4.How we choose a subprocessor
Before a provider goes on this list we check that:
- it is genuinely necessary — we would rather run one fewer service than add one more party to the chain;
- it will receive the minimum data needed for its function, and no telemetry unless its function requires it;
- there is a written agreement containing the Article 28(3) GDPR terms, and a documented transfer mechanism where it processes outside the EEA;
- it publishes its own subprocessor list and security documentation, so the chain stays inspectable;
- an EU-based or EU-hosted option was considered first.
5.What is not on this list
We do not use advertising networks, data brokers, lead-enrichment services, customer data platforms or third-party session recording on our own properties, so none appears here. We do not send customer telemetry to any AI or machine-learning provider.
Our accountant and, when engaged, external legal advisers may see billing records in the course of their professional work. They act under statutory professional confidentiality rather than as subprocessors of customer telemetry, and they never have access to the Service.
6.Contact
Questions, objections, requests for a provider’s transfer documentation, or a request to be added to the change-notice list: [email protected].
More legal documents: Legal & trust centre.