Service Provider Register

Last updated 28 February 2026

This concise, non-exhaustive register identifies material service providers we publicly name for data-protection diligence. It is not an architecture inventory and does not imply that no other subprocessors are used.

Payment processors and user-selected authentication providers may act as independent controllers under their own terms and are not listed here merely because customers interact with them. Public source platforms are also independent from Social Fetch.

Changes and objections

We intend to give customers at least 30 days’ advance notice of a new subprocessor that will process customer personal data where practicable. We may make an urgent change sooner where reasonably necessary for security, service continuity, or legal compliance, and will give notice without undue delay. Customers may raise a reasonable, documented data-protection objection at support@socialfetch.dev during the notice period.

To subscribe to notices, request additional diligence information, or object on documented data-protection grounds, email support@socialfetch.dev. Additional information is provided where legally permitted and subject to applicable confidentiality and contractual restrictions. The authorisation, notice, objection, and remedy terms are set out in the Data Processing Addendum.

Current register

  • Vercel

    Location: United States

    Purpose: Cloud hosting and delivery

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Neon

    Location: United States

    Purpose: Managed database services

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Railway

    Location: United States

    Purpose: Cloud compute and hosting

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Cloudflare

    Location: Global

    Purpose: Security, content delivery, and object storage

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Upstash

    Location: United States

    Purpose: Caching, messaging, and search infrastructure

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Twilio SendGrid

    Location: United States and global

    Purpose: Transactional email delivery

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • PostHog

    Location: United States

    Purpose: Product analytics

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • Sentry

    Location: United States

    Purpose: Error monitoring and performance diagnostics

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

  • OpenRouter

    Location: United States and global; service configuration may vary

    Purpose: AI processing for AI-enabled features

    Safeguards: Contractual data-protection safeguards; an applicable lawful transfer mechanism is used where required.

International transfers

Where a restricted transfer applies, Social Fetch uses an appropriate lawful mechanism and supplementary measures where required. The applicable mechanism depends on the processing, destination, provider, and contract.

Related documents

Data Processing Addendum · Privacy Policy · Security