Subprocessor List

Current as of the Privacy Policy version date. We notify users of material changes at least 14 days in advance.

Each processor is bound by a Data Processing Agreement and, where applicable, the EU–US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).

SubprocessorPurposeData ProcessedLocationTransfer Mechanism
SupabaseDatabase, auth, storage, edge functionsAccount data, brand assets, usage dataUS (or EU region if configured)DPF (verify) + SCCs
VercelHosting, CDN, serverless runtime, cronRequest logs, IP (ephemeral)USDPF + SCCs
SentryError trackingAnonymised stack traces, user IDUSDPF + SCCs
MixpanelProduct analytics — funnels, cohorts (opt-in only). Optional Session Replay (separate, granular opt-in) for UX debugging.Usage events, $device_id, user_id, tenant_id, role, email, name. Session Replay (when enabled): masked DOM events of in-app interactions; payment, integration, admin, and brand-KB routes are excluded entirely.EU (Frankfurt)EU residency for primary storage; SCCs for any incidental US support access
Google (Analytics 4)Audience and acquisition analytics (opt-in only)Pseudonymous client_id, page URL, referrer, user_id once authenticatedUS (with EU regional collection per GA4 default)DPF + SCCs
Google (Ads / Conversion Tracking)Measure ad campaign conversions and build remarketing audiences (separate opt-in). Without consent, runs in Consent Mode v2: anonymous, cookieless conversion pings only.Pseudonymous click ID (gclid), conversion event, page URL. With advertising opt-in: cookie-based audience identifiers for remarketing.USDPF + SCCs
Paddle (Merchant of Record)Payment processing, billing, subscription management, and sales-tax/VAT/GST calculation and remittance. Acts as the seller of record and an independent controller for payment and tax data.Name, email, billing address, payment card details (held by Paddle, not us), transaction and tax recordsUK / USUK adequacy + SCCs
ResendTransactional emailEmail address, name, message bodyUSDPF + SCCs
OpenAIAI content generationPrompts + brand contextUSDPF
AnthropicAI content generationPrompts + brand contextUSSCCs
Google (Gemini)AI fact-checkingPrompts + brand contextUS / EUDPF
OpenAI gpt-image-2AI image generation (hero, social, instagram)Image promptsUSDPF
Customer-connected integrations (WordPress, Buffer, WooCommerce, Google Ads, Meta Ads, Brevo)Publishing + analyticsAPI keys, publishing payloads, analyticsVaries per vendorCustomer-configured

To subscribe to change notifications or ask questions about this list, email admin@coolest.agency.

We use essential cookies to run Coolest.Agency and, with your permission, analytics and advertising cookies to improve it and measure our campaigns. Learn more.

Subprocessors | Coolest.Agency