Third-Party Services & Sub-processors
Every vendor that handles data on our behalf, and what each one does.
This page forms part of our Privacy Policy and our Data Processing Addendum. Under GDPR Article 28, customers are entitled to know who processes their data on our behalf.
1. How to read this
- Sub-processors (section 2) are vendors we engage. Their use is not optional — using the Service means these are involved.
- Optional integrations (section 3) are services you choose to switch on for your site. They are off by default.
2. Sub-processors
2.1 Payments — Razorpay
| Field | Detail |
|---|---|
| Purpose | Payment processing, subscription billing, card tokenisation, refunds |
| Data processed | Billing name, email address, transaction amounts and history, payment method details, and — where you save a card — a tokenised reference and non-sensitive card descriptors |
| Location | India |
| Privacy policy | razorpay.com/privacy |
Card numbers, CVV and PIN are entered directly into the provider’s secure interface and do not reach Postlyo’s systems. The provider is a PCI-DSS-compliant payment processor and acts as an independent controller for its own compliance and fraud-prevention purposes.
2.2 Transactional email — Brevo (Sendinblue SAS)
| Field | Detail |
|---|---|
| Purpose | Delivery of transactional email — account verification, password reset, billing notices, service alerts |
| Data processed | Recipient name and email address, message content, delivery metadata |
| Location | European Union (France) |
| Privacy policy | brevo.com/legal/privacypolicy |
2.3 Hosting, content delivery and storage — Cloudflare, Inc.
| Field | Detail |
|---|---|
| Purpose | Application hosting and edge delivery, content delivery network, DNS, TLS certificate provisioning (including for custom domains), object storage for uploaded media, network security |
| Data processed | All data transiting or stored in the Service, including account data, content, uploaded media, and technical data such as IP addresses |
| Location | Global edge network; storage region as configured |
| Privacy policy | cloudflare.com/privacypolicy |
2.4 Application hosting (backend)
| Field | Detail |
|---|---|
| Provider | To be confirmed and completed by the website owner. |
| Purpose | Hosting of the application backend |
| Data processed | Data transiting the application in the course of request handling |
| Location | To be completed by the website owner. |
2.5 Database and caching
| Field | Detail |
|---|---|
| Provider | To be completed by the website owner — name the managed PostgreSQL and Redis providers. |
| Purpose | Primary data storage; caching and rate-limiting state |
| Data processed | Account data, content, billing metadata, session and rate-limiting state |
| Location | To be completed by the website owner. |
2.6 Internal operational alerting — Discord Inc.
| Field | Detail |
|---|---|
| Purpose | Delivery of internal operational and error alerts to the engineering team |
| Data processed | Operational event data. May incidentally include identifiers such as an account or transaction reference where these appear in an alert. |
| Location | United States |
| Privacy policy | discord.com/privacy |
2.7 Web fonts and marketing assets
| Provider | Purpose | Affects |
|---|---|---|
| Google Fonts | Typeface delivery | Marketing site presentation |
| Unsplash | Imagery on marketing pages | Marketing site only |
| Product Hunt | Badge embed on the landing page | Marketing site only |
These affect the marketing website, not customer sites or the dashboard.
3. Optional integrations — enabled by you
These are off by default. Nothing below runs on your site unless you turn it on.
| Integration | Enabled by | Purpose | Access |
|---|---|---|---|
| Google Analytics (GA4) | Entering a measurement ID in your site settings | Traffic and audience measurement for your site | Collects your visitors' data |
| Google AdSense | Enabling advertising and supplying a publisher ID | Serving advertising on your site | Collects your visitors' data; may personalise ads |
| Google Search Console | Connecting your Google account | Retrieving your site's search performance data | Read-only |
| AdSense reporting | Connecting your Google account | Retrieving your advertising performance data | Read-only |
| Content import | Starting an import from an existing site | Transferring your existing content in | Credentials you supply, stored encrypted, used only for the import |
3.1 Your obligations when you enable these
Switching on an integration makes you responsible for:
- Obtaining consent from your visitors where required — before any non-essential cookie is set or tracking request fires. See our Cookie Policy.
- Disclosing the integration in your own privacy and cookie notices.
- Complying with the provider’s own terms, including Google’s EU User Consent Policy, which contractually requires a compliant consent management platform with Consent Mode for EEA and UK traffic.
- Handling your visitors’ rights requests in relation to that data.
- Not enabling behavioural advertising on sites directed at children.
Postlyo does not obtain this consent for you and does not receive the data these integrations collect.
4. International transfers
Several sub-processors are located outside the EEA and the UK. Where personal data is transferred, we rely on Standard Contractual Clauses (with the UK Addendum where applicable), an adequacy decision, or another lawful mechanism. Copies of the relevant safeguards are available from privacy@postlyo.com.
5. Changes to sub-processors
We may add or replace sub-processors as the Service evolves. We will:
- Update this page;
- Give customers at least 30 days’ notice before a new sub-processor begins processing personal data; and
- Allow a customer who reasonably objects on data-protection grounds to raise it under our Data Processing Addendum and — if we cannot resolve it — to terminate the affected part of the Service without penalty.
To receive notice of changes, email privacy@postlyo.com and ask to be added to the sub-processor notification list.
6. Contact
Questions about sub-processors, or requests for copies of transfer safeguards: privacy@postlyo.com.
This document is provided in English. If we publish a translation and there is a conflict, the English version governs unless local law requires otherwise.