SubTru LLC Subprocessors
Last updated: August 20, 2026
This page identifies third parties SubTru LLC ("SubTru") engages to process Customer Personal Data when providing the SubTru service. Capitalized terms not defined here have the meanings given in the SubTru Data Processing Addendum ("DPA").
Current Subprocessors
| Subprocessor | Service and processing purpose | Data involved | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Supabase Pte. Ltd. | Authentication and hosted database services | Account identifiers, organization and project data, provider configuration, subscriber identifiers, subscription state, and event records | United States (customer project hosted in AWS us-east-1); other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
| Fly.io, Inc. | API, website, and dashboard hosting, networking, and log transport | API requests and responses, account and request metadata, subscriber identifiers, subscription events and state, operational metadata, and Customer Personal Data submitted through or displayed in the dashboard | United States (service regions include Virginia and Chicago); other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
| Cloudflare, Inc. | Content delivery, traffic security, and country-level request geolocation | IP addresses, request metadata, and Customer Personal Data transmitted through the website and dashboard | Cloudflare's global network and other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
| Raintank Inc. dba Grafana Labs | Application monitoring, logs, metrics, traces, and alerting | Operational and request metadata and the identifiers permitted by SubTru's logging policy; raw credentials and webhook payloads are excluded | United States (AWS us-east-1; Grafana Cloud prod-us-east-3); other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
| PostHog, Inc. | Product analytics and masked session replay | Account identifiers, product events, and masked website interactions; customer-specific text and form inputs are configured to be masked | United States (PostHog Cloud US, Virginia); other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
| Plus Five Five, Inc. dba Resend | Transactional email delivery for authentication and organization invitations | Sender and recipient email addresses, message content, authentication and invitation links, and delivery metadata | United States and other locations where the provider and its subprocessors operate | Provider DPA, including applicable cross-border transfer safeguards |
Customer-directed providers
Customer-directed payment and app-store providers are not SubTru Subprocessors when a customer directs SubTru to interoperate with those services. The customer's agreement with the applicable provider governs that provider's processing. Providers that process account and payment information for SubTru's own billing are described by category in the SubTru Privacy Policy; that controller-side processing is not processing of Customer Personal Data under the DPA.
Changes
SubTru will provide reasonable advance notice to the primary email associated with a customer's account or through the Service before a new Subprocessor begins processing Customer Personal Data. The objection process in Section 6 of the DPA applies.
Contact
Questions about Subprocessors may be sent to [email protected].