Subprocessors
Last updated: Reviewed 2026-08-18
Every vendor that processes TryTokka data or visitor requests, including disaster-recovery backups that were easy to miss inside the Privacy Policy.
This is the same list as Privacy Policy §4. If they ever disagree, this page is wrong — both read one source file.
Badge hosts receive a visitor IP when the footer image loads. They do not receive account data or provider keys.
| Service | Purpose | Data shared | Where |
|---|---|---|---|
| Supabase | Database, Auth, and Row-Level Security | Email, hashed passwords, encrypted provider credentials, usage snapshots, audit rows | Supabase-hosted Postgres and Auth. Region is fixed at project creation; not selectable per customer. |
| Vercel | Application hosting, cron, environment secrets, cookieless Analytics on the public site | Server logs, request metadata, ENCRYPTION_KEY and other env secrets. Analytics is aggregate page views, not account rows. | Current production serverless functions run in iad1 (Washington, D.C. area, United States). Region is not customer-selectable. |
| Stripe | Payments (international card checkout) | Email, payment details handled by Stripe (TryTokka does not store card numbers) | Stripe’s infrastructure under Stripe’s DPA |
| Razorpay | Payments (India) | Email, payment details handled by Razorpay (TryTokka does not store card numbers) | Razorpay’s infrastructure |
| Dodo Payments | Payments (international, Merchant of Record) | Email, payment info, billing address | Dodo Payments as Merchant of Record |
| Resend | Transactional email (alerts, auth, billing mail) | Email address, alert and transactional content | Resend’s infrastructure |
| Sentry | Error monitoring (when enabled) | Anonymous user id, stack traces, request path (no API keys; PII scrubbed) | Sentry’s infrastructure |
| Cloudflare | Off-site disaster-recovery snapshots of the database (Workers KV) | Daily encrypted-database dump (includes emails and credential ciphertext). 90-day TTL per snapshot. | Cloudflare Workers KV |
| GitHub | Disaster-recovery database dumps as Actions artifacts (when that workflow runs) | Database dump artifacts, 90-day expiry | GitHub Actions artifact storage |
| Peerlist | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Peerlist’s image host |
| Product Hunt | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Product Hunt’s image host |
| Post Your Startup | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Post Your Startup’s image host |
Hosting and region detail lives on the Security page. There is no customer-selectable or EU-only region today.