Subprocessors

Last updated: February 12, 2026

PrivaBase uses the following third-party service providers (subprocessors) to deliver our platform. Each subprocessor has been vetted for security and compliance. Under GDPR Article 28, we maintain Data Processing Agreements (DPAs) with all subprocessors that handle personal data.

Vercel Inc.

United States

Application hosting, CDN, and serverless compute

Data processed:

Application requests, static assets, serverless function execution

Certifications:

SOC 2 Type II, GDPR DPA

Privacy Policy →

Supabase Inc.

United States (US-East)

Database hosting, authentication infrastructure

Data processed:

Account data, compliance records, application data

Certifications:

SOC 2 Type II, HIPAA

Privacy Policy →

Stripe Inc.

United States

Payment processing and billing

Data processed:

Billing information, payment methods, subscription data

Certifications:

PCI DSS Level 1, SOC 2 Type II

Privacy Policy →

Resend Inc.

United States

Transactional email delivery

Data processed:

Email addresses, email content (verification, password reset, issue reports)

Certifications:

SOC 2 Type II

Privacy Policy →

Kit (ConvertKit) Inc.

United States

Email marketing and subscriber management

Data processed:

Email addresses, signup tags, sequence engagement data

Certifications:

GDPR DPA available

Privacy Policy →

Google LLC

United States

Website analytics (Google Analytics 4)

Data processed:

Anonymized IP, page views, session data (only with user consent)

Certifications:

ISO 27001, SOC 2, GDPR DPA

Privacy Policy →

Namecheap Inc.

United States

Domain registration and DNS management

Data processed:

DNS records only — no customer data processed

Certifications:

ICANN accredited

Privacy Policy →

Change Notifications

We will notify customers at least 30 days before adding a new subprocessor or making material changes to existing subprocessor relationships. Enterprise customers on the Business plan and above receive email notifications of any subprocessor changes.

If you object to a new subprocessor, contact us at privacy@privabase.com within 30 days of notification.