Sub-processors

Everyone who touches your data.

A sub-processor is a company we rely on to run PayGlue that may process personal data on your behalf. This is the complete list, kept current.

We announce changes here at least 30 days in advance.That commitment is written into section 8 of our Data Processing Agreement. If you object to a new sub-processor on reasonable data-protection grounds, tell us and we will work it out with you. If we cannot, you may terminate the affected part of the service.

The DPA itself is available in your dashboard under Settings, Documents. Not a customer yet and need it for review?Ask usand we will send it over.

Current sub-processors

Sub-processorWhat it doesLocationTransfer mechanism
RailwayApplication hosting and databaseEU regionNot applicable (EU-based)
SupabaseAuthentication for the PayGlue dashboard: account email, sign-in method, and session tokensEU regionStandard Contractual Clauses (Supabase Inc., US HQ)
CloudflareEdge network and API proxy. No personal data is cached at the edgeGlobal edge network, company HQ in the USStandard Contractual Clauses
ResendTransactional email for PayGlue itself, sent to your own account contacts. Emails to your Ghost members are sent by your Ghost instance, not by usUS-headquarteredStandard Contractual Clauses
HetznerEncrypted database backups on a 7-day rolling window, and internal tooling (booking, wiki, git, status page). Backups are read only for disaster recovery. Live from 1 August 2026GermanyNot applicable (EU-based)
UserbackPowers our in-app feedback widget and the contact form on our website. May process your name, email address, account information, the message and any attachments you send, and the history of that conversation. Loaded on every page, because the contact form depends on itAustralia-headquartered (Userback Pty Ltd)Standard Contractual Clauses
PostHogProduct analytics and error monitoring on our public website and dashboard: pages viewed, device and browser, approximate location, interactions such as starting a checkout or completing a signup, and the message and stack trace of browser errors so we can fix them. Only ever loaded after you opt in to analytics cookies, which are off by defaultEU region (eu.posthog.com)Standard Contractual Clauses (PostHog Inc., US HQ)

The application and database run in EU data centers. Where a sub-processor is headquartered outside the EU or EEA, transfers rely on the EU Standard Contractual Clauses.

What is deliberately not on this list

Three things people expect to see here, and why they are not sub-processors.

Your payment providers

Polar, Lemon Squeezy, PayPal, Gumroad, Paddle, Ko-fi, Patreon, Creem and any other provider you connect are not our sub-processors. You engage each of them directly and independently. PayGlue only receives a signed webhook notification after that provider has already processed the transaction.

Brevo

Used only for our own newsletter. We publish at payglue.io/blog, and the subscriber list is held in the Ghost site at blog.payglue.io, which also runs as our live demo. Those subscribers are ours, not yours: it never touches your data or your Ghost members.

Mailgun

Delivers our own newsletter from the Ghost site at blog.payglue.io. Those subscribers are ours, not yours: it never sees your data or your Ghost members.

Change history

Every addition, replacement, and removal, with the date it was announced.

  1. 20 July 2026Hetzner becomes a sub-processor, Mailgun listed as out of scope

    From 1 August 2026, encrypted database backups are stored at Hetzner (Germany) on a 7-day rolling window, read only for disaster recovery. Hetzner previously appeared here only as internal tooling that touched no customer data; holding backups changes that, so it moves into the sub-processor list proper and is listed above ahead of the switch-on date. On the 30-day notice period in section 8 of the DPA: at the date of this announcement PayGlue has no customers, so there is no controller whose objection right is shortened. Every future customer sees this entry from their first day. Mailgun is added to the out-of-scope list: it delivers the newsletter for our own marketing blog and never touches customer or Ghost member data.

  2. 19 July 2026Initial publication

    First published version of this list, matching Annex 2 of the Data Processing Agreement v1.0. No changes to the sub-processors themselves.

Want the fuller picture?

The Security Manifest spells out exactly which fields we receive, which ones are structurally impossible for us to see, and how long anything is kept.

Read the Security Manifest