Current sub-processors
This list reflects the sub-processors in use as of the date above. It is the authoritative list referenced by our DPA and Privacy Policy.
| Sub-processor | Purpose | Personal data shared |
|---|---|---|
| Clerk | Authentication and session management | Account identity (email, name), profile photo, account metadata, authentication metadata |
| Stripe (incl. Stripe Connect, Express, and Global Payouts) | Subscription billing, conversion and refund webhooks, and affiliate payouts (Stripe Express accounts and Global Payouts bank deposits) | Billing details, payout identity and bank details, affiliate tax forms (held by Stripe on the Express rail), customer and conversion data |
| Paddle | Conversion and refund tracking for brands that connect their own Paddle Billing account | Customer and order identifiers and sale and refund amounts received from the brand’s Paddle account; the brand’s Paddle credentials are stored encrypted at rest |
| Braintree (a PayPal company) | Subscription conversion and chargeback tracking for brands that connect their own Braintree account | Customer and transaction identifiers and recurring sale and dispute amounts received from the brand’s Braintree account; the brand’s Braintree API credentials are stored encrypted at rest |
| Shopify Inc. (Canada) | For merchants who install the Rekomi app for Shopify: order and refund conversion tracking, affiliate discount-code management, and billing for the merchant’s Rekomi subscription and commission fee through Shopify (Shopify is both a sub-processor and the biller of record for those merchants) | Shop domain, order and customer identifiers, and sale and refund amounts received from the merchant’s Shopify store; the store’s offline Admin API access token is stored encrypted at rest. Protected customer data is handled under Shopify’s Protected Customer Data requirements. |
| Wix.com Ltd (Israel / USA) | For brands who install the Rekomi app from the Wix App Market: hosting of the app inside the Wix dashboard, order and refund conversion tracking, affiliate coupon-code management, and billing of the brand’s Rekomi subscription through Wix (Wix is both a sub-processor and the biller of record for those brands) | Site and app-instance identifiers, order and customer identifiers, and sale and refund amounts received from the brand’s Wix store; the site’s Wix app credentials are stored encrypted at rest |
| Xe Corporation (Xe Currency Data API) | Daily mid-market foreign-exchange reference rates for currencies the European Central Bank does not publish (reporting, tax, and payout-conversion valuation; rates only, no personal data leaves Rekomi) | None (Rekomi sends only currency codes and dates) |
| Frankfurter (open-source exchange-rate API, public instance at api.frankfurter.app) | Daily European Central Bank mid-market reference rates for the ECB-published currency set, republished by Frankfurter (reporting, tax, and payout-conversion valuation; rates only, no personal data leaves Rekomi) | None (Rekomi sends only currency codes and dates) |
| Lemon Squeezy (a Stripe company) | Merchant-of-record billing data for brands who connect their own Lemon Squeezy store: order, subscription renewal, and refund conversion tracking | Customer and order identifiers and sale, renewal, and refund amounts received from the brand’s Lemon Squeezy store; the brand’s Lemon Squeezy API key and webhook signing secret are stored encrypted at rest |
| Chargebee | Subscription billing data for brands who connect their own Chargebee site: payment, renewal, and refund conversion tracking | Customer, subscription, and invoice identifiers and payment, renewal, and refund amounts received from the brand’s Chargebee site; the brand’s read-only Chargebee API key and the webhook credential are stored encrypted at rest |
| Polar | Merchant-of-record billing data for brands who connect their own Polar organization: order, subscription renewal, and refund conversion tracking | Customer and order identifiers and sale, renewal, and refund amounts received from the brand’s Polar organization; the brand’s Polar access token and webhook signing secret are stored encrypted at rest |
| Recurly, Inc. | Subscription billing data for brands who connect their own Recurly site: paid invoice, renewal, and refund conversion tracking | Customer, subscription, invoice, and transaction identifiers and payment, renewal, and refund amounts received from the brand’s Recurly site, plus subscription and account custom-field referral values read via the brand’s API key; the brand’s read-only Recurly API key and the webhook credential are stored encrypted at rest |
| Gumroad, Inc. | Merchant-of-record commerce data for brands who connect their own Gumroad seller account: sale, membership renewal, refund, dispute, and membership lifecycle conversion tracking | Buyer email and name, sale, product, and subscription identifiers, and sale, refund, and dispute amounts received from (and read back against) the brand’s Gumroad account; the brand’s Gumroad access token is stored encrypted at rest |
| Armitage Labs OU (Creem) | Merchant-of-record commerce data for brands who connect their own Creem store: sale, subscription renewal, refund, dispute, and subscription lifecycle conversion tracking | Customer email and name, product, order, subscription, and transaction identifiers and amounts received from the brand’s Creem store; the brand’s Creem API key and webhook signing secret are stored encrypted at rest |
| Dodo Payments Inc | Merchant-of-record commerce data for brands who connect their own Dodo Payments account: payment, subscription renewal, refund, dispute, and subscription lifecycle conversion tracking | Customer email and name, business, product, payment, subscription, refund, and dispute identifiers and amounts received from the brand’s Dodo Payments account; the brand’s Dodo Payments API key and webhook signing secret are stored encrypted at rest |
| Mollie B.V. (Amsterdam) | Payment data for brands who connect their own Mollie account: payment, subscription renewal, refund and chargeback conversion tracking | Customer email and name, website profile, payment, subscription, refund and chargeback identifiers and amounts read from the brand’s Mollie organization through a permission-scoped access token; the brand’s Mollie access token and webhook signing secret are stored encrypted at rest |
| PayPal | Affiliate payout rail for countries that neither Stripe Express nor Stripe Global Payouts covers | Affiliate PayPal email and payout amounts |
| Resend | Transactional and lifecycle email delivery | Recipient email address and message content |
| Cloudflare | DNS, CDN, edge tracking, bot detection, Turnstile human verification on lead forms and portal login, and custom tracking and portal hostnames | Request metadata, IP address, user agent, bot score, Turnstile challenge result |
| Vercel | Hosting of the rekomi.com website and the web application front end, and registration of the custom hostnames brands point at their portals | Request metadata, IP address, user agent, custom hostnames a brand registers |
| IPQualityScore (IPQS) | Fraud and invalid-traffic detection: IP reputation, proxy, VPN, data-center, and bot detection, and device fingerprinting on tracking clicks and on signup, lead, and proposal forms; malicious-URL scanning of landing-page and proposal links; email address reputation for brand account, affiliate, and payout mailboxes; risk scoring of a brand's subscription billing details during trust review; and reporting of identifiers tied to confirmed fraud. Used only for fraud risk scoring, never for advertising | IP address, user agent, device characteristics, email addresses, the landing-page and proposal URLs submitted for scanning, and for brand trust review the billing name, billing email, country and postal code, the last four digits and expiry of the subscription card and the outcome of the card checks (never a full card number, BIN, or bank account number) |
| DigitalOcean | Application hosting and private object storage (Spaces) for uploaded files such as affiliate tax forms | Uploaded documents (for example W-8 tax forms) and application data in transit through hosting |
| Anthropic | Language model API behind two features: ranking a brand’s existing customers as affiliate candidates (Invite affiliates, From customers) and writing the plain-language summary shown to Rekomi staff during brand verification review | For candidate ranking, pseudonymous customer handles (a hash, never the email) with purchase totals and dates; for verification review, the brand’s business name, website domain, a short extract of its public website text and the risk signals that fired. No affiliate or customer names, emails, card or bank details are sent, and the provider does not use API inputs to train its models |
| DigitalOcean (managed PostgreSQL and Redis, New York) | Primary application database and cache, with daily backups and 7-day point-in-time recovery | All application data, including account, affiliate, conversion, and payout records |
| Sentry | Error and performance monitoring, including a masked session replay captured when an error occurs | Diagnostic data scrubbed of personal data before transmission where feasible; user agent; IP addresses are scrubbed; session replays have text and inputs masked |
| PostHog (opt-in) | Product analytics, enabled only with analytics-cookie consent | Usage events and device or session identifiers |
| Google Analytics 4 | Aggregate traffic and marketing attribution. The tag loads on every visit with storage denied (Consent Mode) and sends only cookieless pings until you accept analytics cookies; full measurement runs after you accept | Cookieless page-view pings before consent; aggregate usage and traffic data after consent; IP addresses are anonymized by Google before storage |
| Intercom (opt-in) | Support chat, loaded only with marketing-cookie consent | Support conversation content; signed-in users are identified to Intercom by user id, name, email, and signup date |
| Anthropic | AI features (Claude) that a user invokes, and the automated review of new brand accounts for fraud | For AI features, the content you submit: prompts can include the recipient names and emails you put into outreach and creator profile text, and performance stats are sent in aggregate. For the automated brand review, the brand dossier our reviewers see: business name, website and website text, the owner and cardholder names, the owner and billing email addresses, the sign-up IP address and device id, the last four digits, expiry, billing postcode and country and check results of the card on the subscription, campaign settings, the names, email addresses and sign-up IP addresses of the brand’s affiliates, funding account holder names, and the text the brand typed into its description and verification replies, so the model can write a plain-English risk summary. Not used to train models |
| Zapier | Embedded Zapier page in the brand dashboard for building automations | The signed-in brand user’s name and email, passed to the embed so Zapier can identify the account. Data sent to a brand’s own Zaps is covered under Services you connect below |
| Gravatar (Automattic) | Avatar images for referred customers shown in the brand dashboard | An MD5 hash of each referred customer’s email, fetched from the viewer’s browser, so Gravatar also sees the viewer’s IP address and user agent |
| Google Fonts (Google) | Fonts served at page load on brand portal signup pages and creator about pages | Visitor IP address and user agent, as with any font request served by Google |
| Calendly | Demo booking widget embedded on rekomi.com/demo | Whatever you enter in the booking form (name, email, and any notes) plus the visitor’s IP address and user agent |
Services you connect
Some services receive personal data because a Brand connects them, not because Rekomi chose them: the CRMs and email platforms a Brand syncs affiliates and customers to, the webhook endpoints and Zapier Zaps a Brand subscribes to events (which receive affiliate names and emails for those events), the tracking pixels a Brand places on its signup pages, and the social platforms a creator or Brand connects to their profile. These are the Brand’s (or creator’s) own processors, chosen and controlled by them, not Rekomi sub-processors, and their handling of the data is governed by that party’s agreement with the service.
Data residency
Our default processing region is the United States. Sub-processors may operate globally; where personal data is transferred out of the EEA or UK, our DPA relies on Standard Contractual Clauses and the UK International Data Transfer Addendum.
Changes
We post additions to this page with the Updated date and email organization owners at least 30 days before a new sub-processor processes Customer personal data, except where a change is needed urgently for security or continuity, in which case we notify as soon as practicable. The “Updated” date above reflects the current list. To raise a concern about a sub-processor, contact support@rekomi.com.