Legal
Subprocessors
Last updated September 1, 2026 · version 2026-09-01
The service providers Sitterz relies on to run the platform, what each one receives, and how we give notice before adding another.
1. What this page is
To run Sitterz we use a small number of other companies — a database, a host, a payment processor, an email service. Where they handle personal information on our behalf they are our subprocessors, and this page names every one of them.
This list is incorporated into our Data Processing Addendum, which is how a business authorises us to use them.
2. Our subprocessors
| Provider | What it does for us | What it receives | Where |
|---|---|---|---|
| Supabase | Primary database and file storage | All workspace data, and the bytes of every uploaded photograph and document | United States |
| Vercel | Application hosting, edge delivery, scheduled jobs | Request traffic in the course of serving the application. Its domain API receives hostnames only, never personal information. | United States |
| Stripe | Payment processing for a business's own charges, and our own subscription billing | Payer name and email address, amounts, and reference identifiers. Card details go to Stripe directly from the browser and never reach our servers. | United States |
| Resend | Transactional email delivery | Recipient email address, sender identity, subject, and the full message body — which for a daily summary includes a child's first name and that day's log entries | United States |
| SendGrid (Twilio) | Inbound email replies only. Resend sends our mail; it does not receive, so a reply to one of our messages is delivered through SendGrid. | The sender's email address and the full text of the reply they wrote | United States |
| Twilio | Text messaging — not in use. No text-messaging credentials are configured for this deployment, so nothing is sent to Twilio. | If enabled: recipient phone number and message body. Nothing today. | United States |
| Sentry | Error tracking — server-side only | Error type, message, stack trace, the area of the application, and the workspace identifier. It receives whatever a stack trace or an error message happens to carry, which is why we keep personal information out of error context. No browser SDK, so nothing is collected from a visitor's device. | United States |
| Optional sign-in with a Google account | The standard sign-in exchange, which returns a Google account identifier, email address, name, and profile picture | United States | |
| Browser push services (Google, Mozilla, or Apple, whichever the visitor's browser chose) | Delivering a web push notification to a device that asked for one | A payload encrypted so the push service cannot read it, and a signed request identifying us as the sender | Varies by browser |
The only information that reaches the model provider is the four inputs above — no record about any person is ever sent. See the AI Features Schedule for the full scope of that one feature, including what we require of the provider.
3. Not subprocessors: things a business chooses for itself
Two categories look similar and are not ours. We list them so nobody has to guess.
Analytics and advertising tags on a business's own website
A business can add its own Google Tag Manager, Google Analytics, Meta, Microsoft Clarity, LinkedIn, or TikTok tag to the website it publishes through Sitterz. Those tags load on that business's site, send data to that business's accounts, and load only after a visitor accepts them through the consent banner. They are the business's vendors and its responsibility, and they never run on sitterz.com or on any signed-in page of the Service.
Systems a business connects on its own
A business can configure the Service to send event notifications to a web address of its choosing. Where it does, it has chosen that recipient and is responsible for it.
4. Changes to this list
Before we add a subprocessor that will handle personal information, we will give at least 30 days' notice by email to account owners and by updating this page.
A business may object on reasonable data-protection grounds within that period. If we cannot resolve the objection, the business may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees. That is the remedy — a single customer cannot veto infrastructure the platform runs on, and we would rather say so than pretend otherwise.
Every subprocessor is bound by written terms at least as protective as those in our Data Processing Addendum, including the prohibition on using anything we send for its own purposes.
To be notified of changes, email support@sitterz.com and ask to be added to the subprocessor notice list.
Questions about this document? Email support@sitterz.com.