Subprocessors
Last updated: September 23, 2026
Checkout Page uses the companies below to process personal data on behalf of our customers. Each one is bound by a written agreement with data protection obligations that are no less protective than our Data Processing Addendum.
"End customers + admins" means the subprocessor can process data about the people who buy from your store. "Admins only" means it only processes data about you and your team.
| Subprocessor | Purpose | Location | Scope | Data |
|---|---|---|---|---|
| MongoDB Atlas | Primary database | United States | End customers + admins | All application data: store accounts, customer details, payments, subscriptions, products, pages |
| Stripe, Inc. | Payment processing (Stripe Connect) | United States, EU | End customers + admins | Payment and transaction identifiers, payment status, amounts, customer name and email, billing address, card brand, last four digits and country |
| Amazon Web Services | File storage and content delivery | United States | End customers + admins | Uploaded files, product images, store configuration, data exports |
| Render | Backend API and background job hosting, and the key value store behind them | United States | End customers + admins | Application runtime data, request logs, IP addresses, session data and queued jobs |
| Vercel | Website and checkout page hosting | United States | End customers + admins | Domain configuration, web traffic data, IP addresses in access logs |
| Cloudflare | DNS, firewall and MCP server hosting | United States | End customers + admins | Web traffic, IP addresses, DNS queries, MCP requests |
| Postmark (ActiveCampaign) | Transactional email delivery | United States | End customers + admins | Customer names and email addresses, order details, email content |
| Google reCAPTCHA | Bot and fraud protection | United States | End customers + admins | IP addresses, browser and interaction data |
| Sentry | Error monitoring | United States | End customers + admins | Error reports from checkout pages and the dashboard, including IP address, browser and request details |
| OpenAI | AI features in the dashboard, and AI assistance in customer support | United States | End customers + admins | Prompts and content you submit to AI features, and support conversation content |
| Anthropic | AI assistance in customer support, engineering and debugging | United States | End customers + admins | Support conversation content, and the logs and records our engineers work with while fixing a problem |
| Mixpanel | Product analytics | EU | Admins only | Account email, plan, feature usage events |
| PostHog | Product analytics | United States | Admins only | Dashboard and marketing site page views and usage events, and session replay with inputs masked, and all text masked in the dashboard. Never used on checkout pages |
| Google Analytics | Website analytics | United States | Admins only | IP addresses, page views, user agent, referral data |
| Loops | Account and product emails to store owners | United States | Admins only | Account owner name and email, plan, account events |
| Google Workspace | Our email, calendars and documents | Global | End customers + admins | Email we exchange with you, and the customer or order details in those messages and in the documents we keep about them |
| Slack | Internal team messaging | United States | End customers + admins | Internal messages about support cases and product work, and the order or account details discussed in them |
| GitHub | Code hosting and issue tracking | United States | End customers + admins | Our code and the bug reports we write about a problem, including the order or account details needed to reproduce it |
| Notion | Internal documents and issue tracking | United States | End customers + admins | Notes and tickets about support cases and product work, and the order or account details recorded in them |
| Crisp | Customer support chat | EU | End customers + admins | Name, email and messages you send to our support team, including any customer details in those messages |
Support and engineering
We use AI tools to help answer support conversations and to build and debug the product, so support content and the logs an engineer works with can reach the AI providers above. We keep customer details out of that work wherever we can, and access stays limited to the people and cases that need it.
Changes to this list
Before we add or replace a subprocessor, we update this page and email the owner of every Checkout Page account at least 30 days in advance. If you object to a change on reasonable data protection grounds, email us at security@checkoutpage.com within 14 days of the notice. The objection process is described in section 6 of the Data Processing Addendum.