Legal
Sub-processors
Last updated October 6, 2026
To deliver the hosted service we rely on the vetted third parties below. Each is engaged under written terms that impose data-protection obligations consistent with our Data Processing Addendum. This list is the authoritative register referenced by the DPA. Self-hosted deployments do not use our sub-processors.
Infrastructure sub-processors
| Sub-processor | Purpose | Data processed | Location | Applies to |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and compute, managed PostgreSQL database, object storage and encrypted backups, and certificate/registry tooling. | All hosted Service data at rest and in transit (account, configuration, domain/DNS, logs). | United States (primary region), with AWS global infrastructure. | All customers |
| Cloudflare, Inc. | DNS, CDN, WAF, and reverse proxy for our own domains, plus origin protection for the control plane. | Request metadata and traffic to our public endpoints; limited network-layer data. | United States / global edge network. | All customers |
| Let's Encrypt (Internet Security Research Group) | Automated issuance and renewal of TLS/SSL certificates (ACME) for connected custom domains. | Domain names for which certificates are requested. | United States | Customers using automatic SSL |
| Grafana Labs, Inc. | Hosted observability backend (Grafana Cloud Mimir metrics, Loki logs, and Tempo traces) for operating and monitoring the hosted Service. | Operational telemetry from the hosted Service: metrics, structured logs that exclude secrets and payloads, and request traces. Not intended to include message content. | United States / global. | All customers |
| Functional Software, Inc. dba Sentry | Application error and exception monitoring for the hosted Service. | Error events and diagnostic context (stack traces, request metadata, and environment/release identifiers), configured to avoid capturing secrets or request payloads. | United States | All customers |
| PostHog, Inc. | Product analytics, session recording and feature-flag delivery for the console. | Product-usage events and pseudonymous product/end-user identifiers, plus interaction metadata. For console visitors who have not turned analytics off, the IP address and the approximate location derived from it, and recordings of how they use the public pages and, once signed in, the console (clicks, scrolling and page views, kept 30 days). Typed text other than a domain name, secrets, sign-in, billing and agent access pages are never recorded. Anonymous connect widget funnel events (step, outcome, provider, error code; no domain and no end user IP address). | United States | All customers |
Business and optional sub-processors
| Sub-processor | Purpose | Data processed | Location | Applies to |
|---|---|---|---|---|
| Resend, Inc. | Delivery of the Service's own email: verification and password messages, team invitations, welcome messages, and the DNS setup instructions you or a teammate ask us to send. | Recipient email address, name where the message uses it, and the content of the message, such as a verification link or the DNS records to add. | United States | All customers |
| EverJust Company (the everjust.app platform) | Runs our marketing website, customer relationship records and the mailbox we use to answer you and, where you agreed, to send product news. It is operated by the company behind CustomDomain™ on AWS in the United States. | Name, email address, company and the messages you send us; for newsletter recipients, whether a message was delivered, opened or clicked. | United States | Visitors who contact us or subscribe, and customers we correspond with |
| Stripe, Inc. | Payment processing and subscription/usage billing. | Billing contact, plan and usage data, and payment details entered directly with Stripe (we do not receive full card numbers). | United States / global. | Paid customers |
| Name.com (registrar partner) | Backend registrar for the optional domain-search and domain-purchase feature. | Registrant contact details required by the registry to register a domain. | United States | Customers using the registrar feature |
| Google LLC | Optional single sign-on (OAuth) for the console. | Google account identifier, name, and email, only if you choose Google sign-in. | United States / global. | Customers who use Google sign-in |
Customer-directed DNS providers and registries
When you or your end-users connect a domain, the Service interacts with the DNS provider and registry you choose (for example, your registrar or managed-DNS host). Those providers act on your instruction and are independent controllers of the data you send them; they are not our sub-processors. Where automatic DNS changes are authorized, provider access tokens are used once and discarded rather than stored.
Changes and how to subscribe
We may add or replace sub-processors as the Service evolves. When we do, we will update this page and, for customers who have subscribed, provide advance notice so you can review the change. Under the DPA, you may object to a new sub-processor on reasonable data-protection grounds within the notice window described there.
To be notified of changes to this list, email [email protected] with the subject "Subscribe: sub-processor updates." This list was last updated on October 6, 2026.