Legal

Sub-processors

Last updated: 28 July 2026

BudStacks engages the vendors below to deliver the platform. We update this list when we add or replace a vendor, and notify operators by email at least 30 days before changes take effect, in line with the Data Processing Agreement. Operators may object to a new sub-processor as set out in the DPA.

VendorPurposeRegionTransferDPA
Amazon Web Services (AWS S3)Object storage for tenant assets and backupsEU (eu-west-1) primary; US for cross-region replicationEU SCCs + UK addendumView →
ClerkAuthentication, session management, user identityUnited StatesEU SCCs + UK addendumView →
Dr. Green APIProduct catalogue and order routing for partner storefrontsPortugal / European UnionWithin EEA — no SCCs required—
PostgreSQL (managed by Railway)Primary application databaseUnited States (Railway-managed)EU SCCs + UK addendum—
RailwayApplication hosting, build pipelines, deploymentUnited StatesEU SCCs + UK addendumView →
Redis (managed by Railway)Cache, session store, background-job queuesUnited States (Railway-managed)EU SCCs + UK addendum—
ResendTransactional email delivery (system notifications)United StatesEU SCCs + UK addendumView →
SentryError monitoring and performance telemetryUnited States / EUEU SCCs + UK addendumView →
StripePayment processing for platform subscription feesUnited States / IrelandEU SCCs + UK addendum; adequacy where applicableView →

Operators do not need to subscribe to hear about changes. Every active operator is emailed at least 30 days before a vendor is added or replaced, at the contact address on their account — notice you have to opt into is not notice. Changes are also recorded in the legal changelog. To object to a sub-processor, or to ask anything about this list, contact [email protected].