Subprocessors

Last updated 25 July 2026
In plain language
Three other companies handle RenewalOps customer data. Cloudflare runs the app and stores your database and your documents. Stripe takes the payments, and card details go straight to Stripe without passing through us. Resend delivers reminder emails, and only when a sending address has been configured. Nobody else is involved, and the second half of this page lists the kinds of vendor a product like this usually has and we do not.
Needs a lawyer's review. This list is accurate about the integrations in the software. Before publication, confirm each company's exact legal entity name, its place of incorporation, and the current link to its own data processing terms, then add those here. A procurement reviewer will ask for all three.

1. Who processes your data

Each entry below says what the company does for us and exactly what data reaches it. The list is maintained against the code rather than written once: these three are the only external services the application talks to.

Cloudflare
Hosting, database and document storage
United States

The whole application runs on Cloudflare Workers. Records live in Cloudflare D1 and uploaded files live in a private Cloudflare R2 bucket. Cloudflare also terminates TLS for the site.

What reaches them
  • All of it. Account details, every compliance record, every uploaded document, the reminder history and the audit trail.
  • The production database was created in Cloudflare's Western North America region. Our configuration does not pin the document bucket to a region, and we do not offer a residency guarantee.
  • Encryption in transit and at rest on this data is provided by Cloudflare's platform. It is their control, not one we configured.
Stripe
Payments
United States

Subscriptions are created on a checkout page Stripe hosts, and plan changes and cancellations happen in Stripe's billing portal. Stripe tells us about the result through a signed webhook.

What reaches them
  • Card details and billing address, collected by Stripe on their own page. Those never pass through our servers and we never store them.
  • The email address of the person starting the checkout, so Stripe can send the receipt.
  • Our internal organization number and the plan name, attached to the Stripe session so the payment can be matched back to the right account.
  • No compliance records and no documents. Stripe has no access to what you track.
Resend
Transactional email
United States

Reminder and escalation emails are sent through Resend's API. Resend is used only when the deployment has both an API key and a sending address configured. Without them, no email leaves the system and the reminder is recorded as undelivered rather than sent.

What reaches them
  • The recipient's email address.
  • The subject and body of the reminder. A reminder names the person and the record it is about, so the content typically includes an employee or vendor name, what is expiring, and the date.
  • A per-reminder idempotency key derived from our record number, so a network retry cannot become a second email.
  • No documents are attached, and no record other than the one being reminded about.

2. What we do not use

A list of vendors tells you less than it looks like, because the risk is usually in the ones nobody mentions. These are the categories we have no vendor in at all.

  • No analytics or product telemetry. No Google Analytics, no product analytics, no session recording, no heatmaps. The app sets one cookie, and it holds a session token.
  • No advertising or marketing trackers. No pixels, no ad network, no retargeting.
  • No error or performance monitoring service. Logs stay in Cloudflare's own observability for the Worker. Nothing is shipped to a third-party monitoring vendor.
  • No AI or model provider. Uploads are not sent anywhere to be read. The app guesses a document type from the file name, inside our own Worker.
  • No SMS provider. SMS exists in the code as an interface with no implementation, so nothing is sent and no phone number is passed to a carrier or gateway.
  • No support chat widget or CRM script. There is no third-party JavaScript in the pages at all, and web fonts are served from our own domain rather than a font CDN.

3. Changes to this list

If we take on a new subprocessor, we will update this page before it starts handling customer data, and email the account owner. To be told about changes in writing, or to ask about one, write to TODO: privacy contact email.

How the processor relationship works, including what we commit to as your processor, is in the data processing section of the privacy policy.

Back to renewalops.com
TermsPrivacySubprocessors