Receiz / Legal / Subprocessors
Back home

Trust baseline

Subprocessor List

Public register of subprocessors engaged to support Receiz service delivery.

Effective: March 8, 2026Trust Center
Vendor transparencyDate-tracked updatesNotice controls

Publication Model

Canonical Page

Current list and updates are published at one stable route for procurement and legal review.

Material Notice Target

15 days

Material additions target publication at least 15 days before effective date.

Review Channel

Subprocessor Review

Questions and risk reviews are handled through legal/privacy support intake.

01

Current Subprocessors

ProviderService ScopeData CategoriesPrimary RegionStatus
VercelApplication hosting and edge deliveryService metadata, request logs, deployed contentUnited States / global edgeActive
SupabaseDatabase, object storage, authentication infrastructureAccount records, artifact metadata, storage objectsUnited StatesActive
StripeBilling and payment processingBilling identifiers, transaction metadataUnited StatesActive
ResendTransactional email deliveryEmail address, delivery metadata, message templatesUnited StatesActive
02

Update History

Published DateEffective DateChange TypeDetails
March 8, 2026March 8, 2026Initial publicationCanonical subprocessor register published at /legal/subprocessors.
03

Change Notice Process

Material subprocessor additions are published on this page with provider scope and effective date before activation whenever commercially reasonable.

  • Standard notice target: at least 15 days before effective date for material additions.
  • Emergency security or legal-compliance changes may be implemented on shorter notice when required.
  • Subprocessor inquiries may be submitted to support@receiz.com with subject Subprocessor Review.
04

Subprocessor Due Diligence Controls

  • Written contractual controls including confidentiality and data-protection obligations.
  • Security and operational suitability review prior to production onboarding.
  • Scope-limited processing aligned to documented service purpose and least-privilege principles.
  • Periodic governance review with removal/offboarding when no longer required.