Last updated: 2026-07-19
CodeQR engages the following subprocessors to deliver the service. Changes to this list are announced on this page.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel | Hosting, CDN and edge network | All service data in transit | United States (global edge) |
| PlanetScale | Primary database | Account, workspace, links/QR metadata, leads | United States (AWS us-east-1) |
| Tinybird | Event analytics processing | Click/scan event data (pseudonymized) | European Union |
| Upstash | Cache and message queue | Link/QR lookup data, job payloads | United States |
| Cloudinary | Image storage and processing | QR images, uploaded media | United States |
| Stripe | Payment processing | Billing and payment data | United States |
| Resend | Transactional email | Name, email address | United States |
| Anthropic | AI features | Content submitted to AI features | United States |
| Google (Analytics/Tag Manager) | Marketing-site analytics (consent-gated) | Marketing-site usage data | United States |
| Meta (Pixel) | Marketing-site advertising measurement (consent-gated) | Marketing-site usage data | United States |
| AdOpt | Consent management platform | Consent records | Brazil |
| Statsig | Feature flags and experimentation | Feature usage data | United States |
Integrations that customers enable themselves (such as Kiwify, HubSpot, Kommo, RD Station, Slack, and Meta) receive data only when the customer activates them. In that role they are not subprocessors of CodeQR — the customer instructs the sending of the data.