Subprocessors
Last updated: 2026-04-17
Podley engages the following third-party subprocessors to provide the Service. Each processes user data only as necessary to perform the service described here, bound by terms that prohibit any other use. This list mirrors Privacy Policy §4. Material changes are announced in-app and by email with at least 30 days’ notice before taking effect.
Supabase
ExecutedPostgreSQL database hosting, authentication, realtime, and encrypted file storage (customer-uploads bucket).
Data handled: All operational data - encrypted OAuth tokens, case records, customer photos, user accounts. Row-Level Security scopes every read.
United States (AWS us-east-1)
Vercel
ExecutedApplication hosting and edge functions for the Next.js frontend and API routes.
Data handled: In-memory during request handling only. Serves API routes that process Gmail content; nothing persisted at the Vercel layer.
United States + global edge
Anthropic
Standard commercial termsClaude large-language-model inference for email classification, draft generation, photo analysis, and voice profile synthesis.
Data handled: Per-request only: parsed customer email body, case context, voice profile. Subject to truncation in audit logs. Anthropic may retain standard API requests for up to 30 days for abuse monitoring; never used to train models or shared with other customers.
United States
Stripe
ExecutedPayment processing, subscription management, and billing portal.
Data handled: Merchant-account billing: Stripe customer ID, subscription status. Payment instruments stored by Stripe directly - Podley never touches card numbers.
United States
Sentry
ExecutedServer-side and client-side error monitoring, including session replay for debugging UI errors.
Data handled: Error events with content-scrubbed context (see SECURITY.md § Error Monitoring). Gmail body fields are never sent - enforced by beforeSend scrubber.
United States
PostHog
Standard commercial termsProduct analytics and feature-flag evaluation.
Data handled: Feature-usage events (e.g., case_created, case_resolved) with aggregated counts. No Gmail content; no case-level PII.
United States
Resend
ExecutedTransactional email delivery for notifications sent BY Podley TO merchants (not customer-facing mail).
Data handled: Merchant's own email address + notification content (summaries of case activity, billing alerts, account notices).
United States
Upstash (Redis)
Standard commercial termsDistributed rate-limiting counter store.
Data handled: IP-address hashes + endpoint identifiers for rate-limit buckets only. No user content.
United States + global edge
Google (Gmail API, Pub/Sub, OAuth)
Standard commercial termsSource of truth for the Gmail integration. Merchants grant OAuth access; Pub/Sub delivers real-time change notifications; OAuth verifies tokens.
Data handled: Gmail messages read via API; outbound messages sent via API. Google is upstream - data originates with the merchant + their customers.
Global (Google infrastructure)
Shopify (Admin API, Webhooks)
Standard commercial termsReads order + customer data per case to contextualize replies. Receives mandatory GDPR webhooks for data deletion requests.
Data handled: Per-case read: order, customer name/email, fulfillment status, tracking, line items. Write access is scoped to the support actions you configure (refunds, cancellations, address edits, discounts).
Global (Shopify infrastructure)
Print-on-Demand providers (Printify, Printful, Gooten, Gelato)
Standard commercial termsMerchant-provided API keys to fetch fulfillment status and tracking. Needed to answer "where is my order" style cases.
Data handled: Order fulfillment status, tracking numbers, print quality claim data.
Varies by provider
Requesting a formal DPA
Enterprise and compliance-focused merchants may request a Data Processing Agreement (DPA) covering Podley’s obligations as a data processor under GDPR/CCPA. Contact privacy@podley.app.
See also: Privacy Policy · Terms of Service · Trust overview