TracePath
Platform
LogsTracesMetricsSession ReplayExceptions / Stack TracesMonitorsOn-CallFleet Overview
Specialized
Agent SkillsMCP ServerAI TracingDashboards as CodePerformanceFlutter Session ReplaySymbolicator
Featured
Agent Skills

Your coding agent sets up TracePath and debugs production for you.

Built on OpenTelemetry

Standard OTLP in, every signal on one screen. Free plan, no credit card.

See pricing
PricingBlogDocs
Sign inStart for free
Legal

Subprocessors

Last updated: 21 September 2026Effective: 21 September 2026Version 1.0

In plain language

This page names every third party that processes data on our behalf. It is the authoritative list referenced by Annex 3 of the Data Processing Addendum.

Your telemetry and account data are stored on Hetzner Online GmbH infrastructure in Helsinki, Finland (EU). Three subprocessors come into contact with telemetry — the hosting provider, our CDN, and our transactional email provider, because alert and on-call emails carry exception messages and monitor names. The rest handle billing, optional sign-in or website analytics, and never receive telemetry.

We give 30 days’ notice before a new subprocessor starts processing customer data, and you can object.

This summary is for orientation only. The numbered sections below are the binding text.

On this page

  1. 01Current subprocessors
  2. 02Where your data lives
  3. 03Notice of changes and your right to object
  4. 04How we choose a subprocessor
  5. 05What is not on this list
  6. 06Contact

1.Current subprocessors

As at 21 September 2026. The list is split by the role TracePath plays, because that determines which agreement governs the provider. Rows marked conditional only process data when the feature named is in use; if you never sign in with Google, for example, Google never receives anything about you.

Subprocessors of Customer telemetry — Annex 3 of the DPA

These process Customer Personal Data contained in telemetry, where TracePath acts as processor. They are the providers the change-notice and objection right in section 3 of this page, and section 7 of the DPA, applies to.

Third parties that process Customer telemetry on behalf of TracePath.
SubprocessorPurposeData processedLocationTransfer mechanism
Hetzner
Hetzner Online GmbH (Germany), with Hetzner Finland Oy operating the Helsinki site
Privacy notice
Cloud infrastructure: the application servers, PostgreSQL, ClickHouse and object storage that run the Service.All Service data — account data, billing records and all Customer telemetry.Helsinki, Finland (EU). Provider established in Germany (EU).No transfer outside the EEA.
Cloudflare
Cloudflare, Inc. (US) / Cloudflare Germany GmbH
Privacy notice
Authoritative DNS, CDN and reverse proxy in front of the websites and the API, TLS termination at the edge, WAF and DDoS protection, Turnstile bot protection on sign-up, and email routing for the @tracepath.dev mailboxes.Connection metadata (IP address, user agent, request headers, requested URL), request and response content while in transit, and the envelope and content of email routed to our mailboxes.Global edge network, including locations outside the EEA.EU Standard Contractual Clauses (Decision 2021/914) under the Cloudflare Customer DPA; Cloudflare also self-certifies under the EU–US Data Privacy Framework.
Resend
Resend (Plus Five Five, Inc.), United States
Privacy notice
Transactional email delivery: email verification, password reset, team invitations, alert and on-call notifications, and quota warning emails.Recipient email address and name, message subject and body, and delivery metadata (timestamps, delivery and bounce status).United States.EU Standard Contractual Clauses under Resend's DPA; Resend also relies on the EU–US Data Privacy Framework.

Processors of account, billing and website data — controller-side

These never receive Customer telemetry. They process account, billing, sign-in or marketing-website data, for which TracePath is the controller; they are covered by section 7 of the Privacy Policy rather than by the DPA.

Third parties that process controller-side data on behalf of TracePath.
ProcessorPurposeData processedLocationTransfer mechanism
Stripe
Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (US)
Privacy notice
Payment processing, subscription management, invoicing and the self-service billing portal.Billing contact name and email, company name, VAT identification number, billing country and address, subscription and invoice records, and payment instrument data. Payment card details are entered directly into Stripe Checkout and are never received or stored by TracePath.Ireland (EU) and the United States.Stripe's own DPA with EU Standard Contractual Clauses; Stripe self-certifies under the EU–US Data Privacy Framework and its UK Extension.
Google (OAuth sign-in)
Google Ireland Limited / Google LLC
Privacy notice
Conditional: Only when a user chooses to sign in with Google.
Optional “Sign in with Google” for user authentication.Google account identifier, email address, display name and avatar URL, received from Google when a user chooses this sign-in method.European Union and the United States.EU Standard Contractual Clauses; Google LLC self-certifies under the EU–US Data Privacy Framework.
GitHub (OAuth sign-in)
GitHub, Inc. (a Microsoft company), United States
Privacy notice
Conditional: Only when a user chooses to sign in with GitHub.
Optional “Sign in with GitHub” for user authentication.GitHub account identifier, email address, display name and avatar URL, received from GitHub when a user chooses this sign-in method.United States.EU Standard Contractual Clauses under the Microsoft/GitHub data protection terms; Microsoft self-certifies under the EU–US Data Privacy Framework.
Google Analytics 4
Google Ireland Limited / Google LLC
Privacy notice
Conditional: Only loads on tracepath.dev after the visitor accepts analytics in the consent banner, and only if analytics is configured for the deployment. Never runs on app.tracepath.dev.
Aggregate website usage statistics for tracepath.dev.Pseudonymous usage data: pages viewed, referrer, approximate location derived from a truncated IP address, device and browser type, and a randomly generated analytics identifier stored in cookies.European Union and the United States.EU Standard Contractual Clauses; Google LLC self-certifies under the EU–US Data Privacy Framework.
Plausible Analytics
Plausible Insights OÜ, Estonia
Privacy notice
Conditional: Only loads on tracepath.dev after the visitor accepts analytics in the consent banner, and only if analytics is configured for the deployment.
Cookieless, aggregate website usage statistics for tracepath.dev — the privacy-preserving alternative to Google Analytics.Aggregated page views, referrer and device class. No cookies and no cross-site identifiers.European Union.No transfer outside the EEA.

Note

Hetzner operates the servers and storage that hold telemetry, Cloudflare proxies the connections that carry it, and Resend delivers alert, check-down and on-call emails, whose subject and body carry exception messages and monitor names. Stripe, the OAuth providers and the analytics tools never receive telemetry.

2.Where your data lives

All production systems — the application, the API, the telemetry endpoint, PostgreSQL, ClickHouse and object storage — run on infrastructure provided by Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) in Helsinki, Finland (EU).

That is inside the European Union. Storing customer telemetry there means no cross-border transfer is involved in the storage itself, which materially simplifies the transfer analysis for EU customers. The provider maintains an ISO/IEC 27001 certified information security management system covering the Helsinki site, and we have a data processing agreement with it under Article 28 GDPR.

We do not currently offer a data residency option outside the EU. If you need one, talk to [email protected] before you commit to a plan rather than after.

3.Notice of changes and your right to object

  1. We publish intended additions and replacements here, and email the owners of every affected organisation, at least 30 days before the new subprocessor starts processing customer data.
  2. To receive these notices at a specific address — a security or procurement mailbox rather than the account owner — write to [email protected] and we will add it.
  3. You may object on reasonable data-protection grounds within the notice period. We will discuss it with you in good faith and look for an alternative.
  4. If we cannot provide the service without that subprocessor and cannot offer a commercially reasonable alternative, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees. The full mechanism is in section 7 of the DPA.
  5. Where a change is required to keep the service running or secure — for example an emergency migration away from a failing provider — we may act on shorter notice and will explain why at the time.

4.How we choose a subprocessor

Before a provider goes on this list we check that:

  • it is genuinely necessary — we would rather run one fewer service than add one more party to the chain;
  • it will receive the minimum data needed for its function, and no telemetry unless its function requires it;
  • there is a written agreement containing the Article 28(3) GDPR terms, and a documented transfer mechanism where it processes outside the EEA;
  • it publishes its own subprocessor list and security documentation, so the chain stays inspectable;
  • an EU-based or EU-hosted option was considered first.

5.What is not on this list

We do not use advertising networks, data brokers, lead-enrichment services, customer data platforms or third-party session recording on our own properties, so none appears here. We do not send customer telemetry to any AI or machine-learning provider.

Our accountant and, when engaged, external legal advisers may see billing records in the course of their professional work. They act under statutory professional confidentiality rather than as subprocessors of customer telemetry, and they never have access to the Service.

6.Contact

Questions, objections, requests for a provider’s transfer documentation, or a request to be added to the change-notice list: [email protected].


More legal documents: Legal & trust centre.

TracePath

Observability that tells you what to fix first. One OpenTelemetry-native backend for logs, traces, metrics, replay and exceptions.

[email protected]

Pillars
  • Logs
  • Traces
  • Metrics
  • Session Replay
  • Exceptions / Stack Traces
  • Monitors
  • On-Call
  • Fleet Overview
Specialized
  • Agent Skills
  • MCP Server
  • AI Tracing
  • Dashboards as Code
  • Performance
  • Flutter Session Replay
  • Symbolicator
Resources
  • Pricing
  • Compare
  • Framework guides
  • Docs
  • Blog
  • Changelog
  • Security
  • Contact
  • Support
Legal
  • Privacy Policy
  • Terms of Use
  • Data Processing Addendum
  • Subprocessors
  • Cookies
  • Acceptable Use
  • Licenses
  • Imprint

© 2026 TracePath — AtlasAPX Kamil Krawczyk · NIP 8291758710

Built on OpenTelemetry · ClickHouse · Go