Legal
Sub-processors
Last updated: 28 July 2026
BudStacks engages the vendors below to deliver the platform. We update this list when we add or replace a vendor, and notify operators by email at least 30 days before changes take effect, in line with the Data Processing Agreement. Operators may object to a new sub-processor as set out in the DPA.
| Vendor | Purpose | Region | Transfer | DPA |
|---|---|---|---|---|
| Amazon Web Services (AWS S3) | Object storage for tenant assets and backups | EU (eu-west-1) primary; US for cross-region replication | EU SCCs + UK addendum | View → |
| Clerk | Authentication, session management, user identity | United States | EU SCCs + UK addendum | View → |
| Dr. Green API | Product catalogue and order routing for partner storefronts | Portugal / European Union | Within EEA — no SCCs required | — |
| PostgreSQL (managed by Railway) | Primary application database | United States (Railway-managed) | EU SCCs + UK addendum | — |
| Railway | Application hosting, build pipelines, deployment | United States | EU SCCs + UK addendum | View → |
| Redis (managed by Railway) | Cache, session store, background-job queues | United States (Railway-managed) | EU SCCs + UK addendum | — |
| Resend | Transactional email delivery (system notifications) | United States | EU SCCs + UK addendum | View → |
| Sentry | Error monitoring and performance telemetry | United States / EU | EU SCCs + UK addendum | View → |
| Stripe | Payment processing for platform subscription fees | United States / Ireland | EU SCCs + UK addendum; adequacy where applicable | View → |
Operators do not need to subscribe to hear about changes. Every active operator is emailed at least 30 days before a vendor is added or replaced, at the contact address on their account — notice you have to opt into is not notice. Changes are also recorded in the legal changelog. To object to a sub-processor, or to ask anything about this list, contact [email protected].