Skip to content
Start free
Menu

Subprocessors

Last updated 2026-09-25

These are the third parties that process data on TraceLog's behalf. Notice is given before one is added, so a customer can object.

The list

EU hosting describes where TraceLog stores data, and that storage does not move: every event, daily aggregate and account record stays in eu-central-1. Three optional operations send information outside the region: answering a question, signing in with Google, and paying for a subscription through Stripe. If a customer does not ask a question, sign in with Google, or choose a paid plan, none of those providers receives their information. Creating an account with email and password is the one that is not optional: Cloudflare checks the person signing up from its global network, and receives no account data. Signing up with Google skips that check. One other request leaves the region but carries no data: once an hour a background process sends a signal to the uptime monitor described below.

One resource sits outside the EU and holds no data: the TLS certificate this site is served with, which the content delivery network reads only from its own North Virginia region. A certificate is a public key and a domain name. Every origin it points at is in Frankfurt.

SubprocessorWhat it doesData it seesRegion
ResendDelivers transactional email: the alert, the diagnostic, and account mail such as address verification and password resetThe recipient's email address and the content of the messageEU
GoogleAuthenticates an account when the person chooses Google Sign-InThe Google account identifier, verified email address, name, profile image, and OAuth security metadata — never measurement dataGlobal
AnthropicReads questions asked in the product's conversation and chooses which governed read answers them; TraceLog states the answer, and no text the model writes reaches the readerThe question as typed, the project's declared conversion path, and what TraceLog's governed reads return — aggregate numbers, recorded findings and, when the question needs them, the customer's own notes on actions and changes — never raw events, sessions, identifiers or payloadsUnited States
StripeTakes the subscription payment, hosts the checkout and the invoice portal, and is where card details are entered and heldThe account owner's email address, the plan chosen, and the payment details entered on Stripe's own pages — never any conversion-record dataUnited States
CloudflareChecks that whoever creates an account with email and password is a person (Turnstile)The IP address and browser signals of the person signing up, during that check — never the email address, the password or any measurement dataGlobal
Amazon Web ServicesRuns the application, the API, the background processes and the database, and serves this site and the capture runtime from immutable per-version pathsEverything the product stores, and the network requests that reach itEU (eu-central-1, Frankfurt)

Not subprocessors

Geolocation is a local lookup. TraceLog reads a MaxMind GeoLite2 Country database file on its own machines to turn an IP address into a two-letter country code; no address leaves the service, and none is stored.

An external uptime monitor receives only a signal that TraceLog is running. Once an hour a background process sends one request to a fixed address, with no content and no parameters — no personal data, no customer information, and no list of customers. This lets an external service detect if that process stops.

A customer's own platform — their store, CMS, or server — belongs to the customer and is not TraceLog's subprocessor. Integrations run inside that platform under the customer's control.

Changes

Additions are announced to account owners by email before they take effect, and this page carries the date of its last change. Objections go to info@tracelog.io.

If you have questions about this page, email info@tracelog.io. A person from TraceLog will reply.