Sub-processors.

The third parties Perch uses to process customer personal data, and where they run.

Perch keeps customer data in the EU. Every sub-processor below runs in an EU region except where noted. We notify the customer organization (the data controller) before adding a new sub-processor, giving a window to object.

Sub-processorPurposeDataRegion
SupabaseManaged Postgres database and authenticationAll application data — names, emails, organization membership, bookings, audit logEU — Frankfurt (eu-central-1)
VercelApplication hosting, serverless compute, and product analyticsRequest data for app delivery (essential); page-view and performance data for analytics (consent-gated, only after 'Accept all')EU — Frankfurt (fra1)
ResendTransactional email — invitations, booking confirmationsRecipient email address and message contentEU
SentryError monitoringError context, including the acting user id and organization idEU — Frankfurt (de.sentry.io)
Stripe — pendingPayment processing and billing. Becomes active only when live billing begins; processes no customer data until then.Billing contact and payment metadata. Card details are handled by Stripe and never reach Perch.US — under Standard Contractual Clauses; EU fallback: Stripe Payments Europe Ltd (Ireland)

Change notifications

Material changes to this list are communicated to customer organizations before they take effect. A self-service email opt-in for change notifications is planned.

Questions about sub-processors: privacy@perch.app.