Sub-processors.
The third parties Perch uses to process customer personal data, and where they run.
Perch keeps customer data in the EU. Every sub-processor below runs in an EU region except where noted. We notify the customer organization (the data controller) before adding a new sub-processor, giving a window to object.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Managed Postgres database and authentication | All application data — names, emails, organization membership, bookings, audit log | EU — Frankfurt (eu-central-1) |
| Vercel | Application hosting, serverless compute, and product analytics | Request data for app delivery (essential); page-view and performance data for analytics (consent-gated, only after 'Accept all') | EU — Frankfurt (fra1) |
| Resend | Transactional email — invitations, booking confirmations | Recipient email address and message content | EU |
| Sentry | Error monitoring | Error context, including the acting user id and organization id | EU — Frankfurt (de.sentry.io) |
| Stripe — pending | Payment processing and billing. Becomes active only when live billing begins; processes no customer data until then. | Billing contact and payment metadata. Card details are handled by Stripe and never reach Perch. | US — under Standard Contractual Clauses; EU fallback: Stripe Payments Europe Ltd (Ireland) |
Change notifications
Material changes to this list are communicated to customer organizations before they take effect. A self-service email opt-in for change notifications is planned.
Questions about sub-processors: privacy@perch.app.