Subprocessors

Third-party service providers engaged in processing limited customer personal data.

Last Updated: 16 September 2025

Change Management & Notification

We update this list upon engaging or removing a subprocessor. For materially new subprocessors that process personal data, we aim to provide at least 15 days prior notice (via email or dashboard) to customers with a current DPA before activation, enabling objections per the DPA.

Current Subprocessors

NamePurposeData TypesPrimary LocationDPA / TermsStatusLast Review
VercelApplication hosting & edge deliveryRuntime logs, error traces, minimal request metadataUSA / GlobalProvider Standard DPAActive2025-08-01
StripePayment processingBilling email, transaction metadata (no full card data stored by us)USA / EUStripe Services Agreement & DPAActive2025-08-01
Firebase (Google)Authentication & databaseAuth identifiers, user profile metadataGlobal (region selection)Google Cloud Data Processing AddendumActive2025-08-01
Google AnalyticsProduct & usage analyticsAggregated event data, pseudonymous identifiersGlobalGoogle Analytics Data Processing AmendmentActive2025-08-01
Vercel AnalyticsPerformance monitoringPerformance timings, aggregated metricsGlobalVercel DPAActive2025-08-01

All subprocessors are evaluated for security posture, data protection commitments, and need-to-know scope minimization.

Request More Information

For security questionnaires or clarification about any subprocessor, contact alex@zuvohq.com. Include your account identifier and justification for the request.

Disclaimer

This list is provided for transparency and does not itself constitute a contractual commitment. Binding terms are contained in the Client Agreement, Terms of Service, and Data Processing Agreement.