Distinct-app

Legal hub

Subprocessors

Last updated: 10 September 2026

The table below lists the service providers we use to run the platform: what each one does, what categories of data it can access, where it processes or stores that data, and the data processing terms that govern it.

ProviderPurposeData categoriesData processing / hosting locationDPA status
SupabaseDatabase, authentication, file storage for most appsAccount data, business data, bookings, fileseu-north-1 (AWS Stockholm, Sweden)Supabase Data Processing Addendum (standard terms)
VercelApplication hosting for most appsAll data transiting the hosted appus-east-1 (Washington, D.C., USA)Vercel Data Processing Addendum (standard terms)
CloudflareDNS, object storage (R2), hosting for some apps, inbound email routing, and AI inference (Workers AI) as a fallback provider for the in-app AI assistantUploaded files/photos; DNS traffic metadata; inbound email metadata; AI prompt text and the app data retrieved to answer itGlobal network; the shared R2 storage bucket is located in Western EuropeCloudflare Data Processing Addendum (standard terms)
Anthropic, PBCAI inference for the in-app AI assistant (primary provider), where the assistant is enabledThe user's question text and the business/account data retrieved to answer it. Sent via Anthropic's API, which is not used to train models by default.United StatesAnthropic Commercial Terms / Data Processing Addendum (standard terms)
Google LLC"Sign in with Google" authentication (via Supabase Auth), and AI inference (Gemini API) for the in-app AI assistant and for content generation in Flyer Buddy / Logo Maker Genie, where enabledFor sign-in: name, email address, profile picture. For AI: prompt text and the business/account data retrieved to answer it. Paid Gemini API usage is not used to train models.United States and other locations where Google operatesGoogle Cloud / Workspace Data Processing terms (standard terms)
GitHub, Inc. (Microsoft)Source-code hosting and CI/CD (GitHub Actions), including automated security and quality scans of our own code and deploymentsApplication source code, deployment logs, and CI configuration. No customer personal information is intentionally sent; end-user data is not stored in the repositories.United StatesGitHub Data Protection Agreement (standard terms)
Paystack South Africa (Pty) LtdPayment processing, transaction management and related payment services for Distinct-app subscriptions and for Paystack-enabled in-app transactionsCustomer identification/contact information, transaction information, and payment data necessary to process the transaction. Distinct-app does not receive or store full card details where those details are collected directly by Paystack.South Africa and other jurisdictions used in Paystack's payment infrastructureApplicable Paystack merchant agreement and data-processing provisions
ResendOutbound transactional email, where configuredRecipient email address, message contentUnited States, per Resend's Privacy PolicyResend Data Processing Addendum (standard terms)
sms1.smsmessenger.co.zaLive SMS delivery (Marketing app)Recipient phone number, message contentSouth AfricaGoverned by the provider's standard service terms
Black Forest Labs (FLUX)AI image generation (Flyer Forge, Logo Maker Genie, Marketing)Prompt text only, no personal information intentionally sent by us, though a user could enter personal information in a promptNot publicly disclosed by the provider; requests are made via its hosted APIGoverned by Black Forest Labs' standard API terms

Not every app uses every provider above. This list is reviewed alongside the platform governance documentation and updated when a new provider is integrated.

We also use software for security scanning, automated testing, and performance and code analysis. These tools run inside our own build pipeline against our own source code and our own running services — they do not receive customer personal information — so they are not listed as subprocessors. The platform that hosts that pipeline (GitHub) is listed above.