LEGAL Subprocessors
Subprocessors
The third parties that may process customer data, and what each one does.
Template — not yet reviewed by a solicitor
This document is scaffolding written to match how the platform actually
handles data. It is not legal advice and must be reviewed and amended
before the site goes live. Remove this notice by setting
'reviewed' => true
in config/policies.php.
Other documents
Current subprocessors
Each entry below is engaged under a written contract with data protection terms at least as protective as our own. Complete this table with your actual providers before publishing.
- Hosting and infrastructure — application servers, database and object storage. Region: United Kingdom.
- Transactional email — account emails, alerts and scheduled reports. Region: European Economic Area.
- Error monitoring — application diagnostics, with personal data scrubbed before transmission.
- Payment processing — subscription billing. Card details are held by the processor, never by us.
Onward destinations you control
These are not our subprocessors. They receive data only when a company connects them and enables an export, acting on that company's instruction:
- Meta Platforms — hashed identifiers and conversion events sent through the Conversions API.
- Google — hashed identifiers and offline conversion uploads sent to Google Ads.
- Any CRM or commerce platform the company connects.
Notice of changes
We give at least 30 days' notice before adding or replacing a subprocessor. To receive those notices, subscribe on this page or write to privacy@tracepointer.com.
Questions about this document? Write to privacy@tracepointer.com.