logo

Subprocessors

Last updated: 2026-07-25

CodeQR engages the following subprocessors to deliver the service. Changes to this list are announced on this page.

SubprocessorPurposeData processedLocation
VercelHosting, CDN and edge networkAll service data in transitUnited States (global edge)
PlanetScalePrimary databaseAccount, workspace, links/QR metadata, leadsUnited States (AWS us-east-1)
TinybirdEvent analytics processingClick/scan event data (pseudonymized)European Union
UpstashCache and message queueLink/QR lookup data, job payloadsUnited States
CloudinaryImage storage and processingQR images, uploaded mediaUnited States
StripePayment processingBilling and payment dataUnited States
ResendTransactional emailName, email addressUnited States
AxiomApplication logging and observabilityRequest metadata and application logs, including IP addressUnited States
Better StackUptime monitoring, status page and incident recordsUptime probe results; incident notesEuropean Union
AnthropicAI featuresContent submitted to AI featuresUnited States
Google (Analytics/Tag Manager)Marketing-site analytics (consent-gated)Marketing-site usage dataUnited States
Meta (Pixel)Marketing-site advertising measurement (consent-gated)Marketing-site usage dataUnited States
AdOptConsent management platformConsent recordsBrazil
StatsigFeature flags and experimentationFeature usage dataUnited States

International transfers

Where a subprocessor processes personal data outside the European Economic Area, the transfer relies on the EU Standard Contractual Clauses incorporated into our Data Processing Agreement, together with the subprocessor's own transfer safeguards.

Logging and retention

Application logs include the IP address of the requesting client. They are retained for 30 days and are used to investigate security incidents, abuse, and service faults. This processing rests on our legitimate interest in keeping the service secure and available.

Customer-enabled integrations

Integrations that customers enable themselves (such as Kiwify, HubSpot, Kommo, RD Station, Slack, and Meta) receive data only when the customer activates them. In that role they are not subprocessors of CodeQR — the customer instructs the sending of the data.