Legal

Subprocessors

What this page lists

PeerPath uses the third-party services below to run the platform. Each subprocessor handles a specific function and is bound by its own contract with us. We do not allow any subprocessor to use peer-group content for marketing, advertising, or AI-model training.

Current subprocessors

SubprocessorRoleLocation
SupabaseManaged Postgres database, authentication, file storage, scheduled jobs (pg_cron).United States (AWS us-east-1).
VercelApplication hosting (Next.js), routing middleware, scheduled functions, runtime logs.United States (multi-region edge; serverless functions pinned to a US region).
BrevoTransactional email delivery (sign-in codes, invitations, goal reminders, account notifications), inbound bounce/complaint webhooks.European Union (operator); messages are routed to recipient mail servers globally.
CloudflareTurnstile bot mitigation on the public contact form only. Confirms a visitor is a person before their message is sent; it receives the challenge interaction and the submitting IP address, and no peer-group content, account data, or tracking cookie.Global anycast network.

Notice before we add new subprocessors

When we add a new subprocessor that will process customer data, we update this page and post a notice at least 10 days before the new subprocessor begins processing. Existing customers may object during that window by writing to support@getpeerpath.com.

Where a change is required urgently — to address a security risk, to comply with a legal obligation, or to keep the service running if a subprocessor becomes unavailable — we may make the change immediately and give notice at the same time or as soon as we reasonably can. The right to object still applies.

Internal infrastructure (not subprocessors)

The following internal services do not receive peer-group content and are listed for transparency only:

  • GitHub (source code, CI logs that contain redacted operational metadata; never customer data).
  • Sentry (error tracking) and PostHog (product analytics) are not used in v1. If either is added in a future release, this page and the Privacy Policy will be updated and a notice will be posted at least 10 days before they go live, on the same terms as the notice section above.

Change history

Every change to this page is recorded here, newest first, so the notice commitment above can be checked against what actually happened.

  • 2026-08-15 — contact address corrected to support@getpeerpath.com; subprocessor notice period restated as 10 days with an urgent-change carve-out.
  • 2026-08-08 — Cloudflare added as a subprocessor.
  • 2026-06-07 — first published.

Contact

Questions about subprocessors? Email support@getpeerpath.com.