Subprocessors

Last updated: September 23, 2026

Checkout Page uses the companies below to process personal data on behalf of our customers. Each one is bound by a written agreement with data protection obligations that are no less protective than our Data Processing Addendum.

"End customers + admins" means the subprocessor can process data about the people who buy from your store. "Admins only" means it only processes data about you and your team.

SubprocessorPurposeLocationScopeData
MongoDB AtlasPrimary databaseUnited StatesEnd customers + adminsAll application data: store accounts, customer details, payments, subscriptions, products, pages
Stripe, Inc.Payment processing (Stripe Connect)United States, EUEnd customers + adminsPayment and transaction identifiers, payment status, amounts, customer name and email, billing address, card brand, last four digits and country
Amazon Web ServicesFile storage and content deliveryUnited StatesEnd customers + adminsUploaded files, product images, store configuration, data exports
RenderBackend API and background job hosting, and the key value store behind themUnited StatesEnd customers + adminsApplication runtime data, request logs, IP addresses, session data and queued jobs
VercelWebsite and checkout page hostingUnited StatesEnd customers + adminsDomain configuration, web traffic data, IP addresses in access logs
CloudflareDNS, firewall and MCP server hostingUnited StatesEnd customers + adminsWeb traffic, IP addresses, DNS queries, MCP requests
Postmark (ActiveCampaign)Transactional email deliveryUnited StatesEnd customers + adminsCustomer names and email addresses, order details, email content
Google reCAPTCHABot and fraud protectionUnited StatesEnd customers + adminsIP addresses, browser and interaction data
SentryError monitoringUnited StatesEnd customers + adminsError reports from checkout pages and the dashboard, including IP address, browser and request details
OpenAIAI features in the dashboard, and AI assistance in customer supportUnited StatesEnd customers + adminsPrompts and content you submit to AI features, and support conversation content
AnthropicAI assistance in customer support, engineering and debuggingUnited StatesEnd customers + adminsSupport conversation content, and the logs and records our engineers work with while fixing a problem
MixpanelProduct analyticsEUAdmins onlyAccount email, plan, feature usage events
PostHogProduct analyticsUnited StatesAdmins onlyDashboard and marketing site page views and usage events, and session replay with inputs masked, and all text masked in the dashboard. Never used on checkout pages
Google AnalyticsWebsite analyticsUnited StatesAdmins onlyIP addresses, page views, user agent, referral data
LoopsAccount and product emails to store ownersUnited StatesAdmins onlyAccount owner name and email, plan, account events
Google WorkspaceOur email, calendars and documentsGlobalEnd customers + adminsEmail we exchange with you, and the customer or order details in those messages and in the documents we keep about them
SlackInternal team messagingUnited StatesEnd customers + adminsInternal messages about support cases and product work, and the order or account details discussed in them
GitHubCode hosting and issue trackingUnited StatesEnd customers + adminsOur code and the bug reports we write about a problem, including the order or account details needed to reproduce it
NotionInternal documents and issue trackingUnited StatesEnd customers + adminsNotes and tickets about support cases and product work, and the order or account details recorded in them
CrispCustomer support chatEUEnd customers + adminsName, email and messages you send to our support team, including any customer details in those messages

Support and engineering

We use AI tools to help answer support conversations and to build and debug the product, so support content and the logs an engineer works with can reach the AI providers above. We keep customer details out of that work wherever we can, and access stays limited to the people and cases that need it.

Changes to this list

Before we add or replace a subprocessor, we update this page and email the owner of every Checkout Page account at least 30 days in advance. If you object to a change on reasonable data protection grounds, email us at security@checkoutpage.com within 14 days of the notice. The objection process is described in section 6 of the Data Processing Addendum.