Legal
Subprocessors
What this page lists
PeerPath uses the third-party services below to run the platform. Each subprocessor handles a specific function and is bound by its own contract with us. We do not allow any subprocessor to use peer-group content for marketing, advertising, or AI-model training.
Current subprocessors
| Subprocessor | Role | Location |
|---|---|---|
| Supabase | Managed Postgres database, authentication, file storage, scheduled jobs (pg_cron). | United States (AWS us-east-1). |
| Vercel | Application hosting (Next.js), routing middleware, scheduled functions, runtime logs. | United States (multi-region edge; serverless functions pinned to a US region). |
| Brevo | Transactional email delivery (sign-in codes, invitations, goal reminders, account notifications), inbound bounce/complaint webhooks. | European Union (operator); messages are routed to recipient mail servers globally. |
| Cloudflare | Turnstile bot mitigation on the public contact form only. Confirms a visitor is a person before their message is sent; it receives the challenge interaction and the submitting IP address, and no peer-group content, account data, or tracking cookie. | Global anycast network. |
Notice before we add new subprocessors
When we add a new subprocessor that will process customer data, we update this page and post a notice at least 10 days before the new subprocessor begins processing. Existing customers may object during that window by writing to support@getpeerpath.com.
Where a change is required urgently — to address a security risk, to comply with a legal obligation, or to keep the service running if a subprocessor becomes unavailable — we may make the change immediately and give notice at the same time or as soon as we reasonably can. The right to object still applies.
Internal infrastructure (not subprocessors)
The following internal services do not receive peer-group content and are listed for transparency only:
- GitHub (source code, CI logs that contain redacted operational metadata; never customer data).
- Sentry (error tracking) and PostHog (product analytics) are not used in v1. If either is added in a future release, this page and the Privacy Policy will be updated and a notice will be posted at least 10 days before they go live, on the same terms as the notice section above.
Change history
Every change to this page is recorded here, newest first, so the notice commitment above can be checked against what actually happened.
- 2026-08-15 — contact address corrected to support@getpeerpath.com; subprocessor notice period restated as 10 days with an urgent-change carve-out.
- 2026-08-08 — Cloudflare added as a subprocessor.
- 2026-06-07 — first published.
Contact
Questions about subprocessors? Email support@getpeerpath.com.