| Vendor | Category | Location | Scope of processing | Legal basis |
|---|---|---|---|---|
| Vercel | Application hosting & domains | Global | App hosting, custom-domain routing, TLS, CDN, and request logs | Vercel DPA + SCCs where applicable |
| Supabase | Database & storage | Configured project region | Account, link, domain, consent, and analytics data | Supabase DPA + SCCs where applicable |
| Clerk | Authentication | As described in Clerk's DPA | Sign-in, user accounts, sessions, and team membership | Clerk DPA + SCCs where applicable |
| Stripe | Billing | Global | Payment processing, subscriptions, and invoicing | Stripe DPA + SCCs where applicable |
| PostHog Cloud US | Product analytics | United States | Dashboard usage and server-side product events | PostHog DPA + SCCs where applicable |
| Google Analytics | Website analytics (optional) | Global | Marketing-site analytics after the visitor consents | Google data processing terms + SCCs where applicable |
| Cloudflare | Edge security & AI generation | Global edge network | Bot checks, free-tool prompts, and generated tool responses when a visitor uses live AI | Cloudflare DPA + SCCs where applicable |
| Apify | Public social-data collection | Provider-controlled cloud regions | Public account identifiers and bounded public-post collection for enabled social analytics features | Apify DPA + SCCs where applicable |
Current provider list
We record providers here with the service category, processing scope, location description, and contractual basis available to us.
Questions or objections
Contact info@getapproute.com if you have a question or objection about a provider or processing activity listed here.
Processing locations
Hosting and edge processing may be global. Database location is determined by the configured Supabase project region; each vendor's current terms govern its processing locations.