Reservly Sub-Processor List
Last updated: July 12, 2026
What is a sub-processor?
A sub-processor is a third-party service that Reservly uses to operate the platform. Where those services store, transmit, or otherwise process personal data on Reservly's behalf, the GDPR and similar laws classify them as sub-processors. The businesses that use Reservly are controllers of their customers' personal data; Reservly is a processor acting on each business's behalf; the services listed below are sub-processors engaged by Reservly.
This page lists every sub-processor we currently use, plus services we expect to activate in the near term. We keep the list current because the businesses we serve often need it to satisfy their own compliance programs.
Current sub-processors
Core platform infrastructure
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Supabase (Supabase, Inc.) | Primary application database (Postgres) and authentication | Account data, booking data, usage logs, customer-provided booking form fields, encrypted OAuth tokens (Supabase Vault) | European Union — eu-central-1 (Frankfurt, Germany) | supabase.com/privacy |
| Vercel (Vercel, Inc.) | Application hosting — serverless functions, edge network, static asset delivery | Server-side request and rendering data, access logs | United States — iad1 (Northern Virginia) | vercel.com/legal/privacy-policy |
| Cloudflare R2 (Cloudflare, Inc.) | Object storage for business-uploaded images, served through our custom domain images.reservly.io | Uploaded images (logos, gallery photos, floor plans), image metadata | European Union (EU) jurisdiction — reservly-images-eu bucket | cloudflare.com/privacypolicy |
| Upstash (Upstash, Inc.) | Rate-limiting state (fixed-window counters) and short-term counters | API keys (hashed), per-key request counters, IP-address-derived counters | European Union — Frankfurt, Germany | upstash.com/trust/privacy.pdf |
‡ For UK personal data transferred to US-based sub-processors (Vercel): the applicable transfer mechanism is the ICO-approved IDTA or UK Addendum to EU SCCs. Where a US-based sub-processor is certified under the UK-US Data Bridge, Reservly may rely on that certification in lieu of the IDTA for that specific transfer. Certification status will be verified per vendor before UK customer onboarding.
Communication and monitoring
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Resend (Resend, Inc.) | Outbound transactional email (booking confirmations, reminders, account email) | Recipient email address, email subject and body, delivery events | United States | resend.com/legal/privacy-policy |
| Sentry (Functional Software, Inc. / Sentry) | Application error and performance monitoring | Error stack traces, request metadata, breadcrumbs (PII scrubbed before ingest) | European Union — ingest.de.sentry.io (Frankfurt) | sentry.io/privacy |
Push notification delivery
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Google Firebase Cloud Messaging (Google LLC) | Delivers browser/OS push notifications to Chrome, Edge, and other Chromium/Android-based devices | Push-subscription endpoint URL, encrypted subscription keys (p256dh, auth), encrypted notification payload (booking type, customer name, service, time) | Global (Google-operated infrastructure) | policies.google.com/privacy |
| Mozilla Push Service (Mozilla Corporation) | Delivers browser push notifications to Firefox | Push-subscription endpoint URL, encrypted subscription keys, encrypted notification payload | Global (Mozilla-operated infrastructure) | mozilla.org/privacy |
| Apple Push Notification service (Apple Inc.) | Delivers browser/OS push notifications to Safari and iOS/macOS devices | Push-subscription endpoint URL, encrypted subscription keys, encrypted notification payload | Global (Apple-operated infrastructure) | apple.com/legal/privacy |
Reservly does not choose which of these three services is used for a given device — the recipient's browser makes that determination when the device subscribes to push notifications. This feature is used to notify business staff/owners of new bookings on their own devices; it is not used to send push notifications to end-user customers.
SMS delivery (business-connected "bring your own" Twilio)
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Twilio (Twilio Inc.) | SMS delivery via business-connected "bring your own" Twilio accounts — the business supplies its own Twilio Account SID and Auth Token; Reservly routes SMS through that business's account | Twilio Account SID and Auth Token (encrypted at rest in Supabase Vault), sending phone number, SMS send-event log (timestamp, delivery status, template type, masked recipient number + one-way hash), STOP/START opt-out records | Global (business-selected Twilio numbering region) | twilio.com/legal/privacy |
Billing (Reservly's own subscriptions)
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Paddle (Paddle.com Market Ltd.) | Merchant of record for Reservly subscriptions — collects payment, handles global sales tax (VAT/GST), issues invoices and receipts, processes subscription cancellations and refunds. Note: Paddle is incorporated in the United Kingdom; no international transfer mechanism is required for UK personal data transferred to Paddle. | Business billing contact, payment method (handled by Paddle; Reservly does not see card numbers), transaction amounts, tax determinations | Global, with EU primary (Paddle is UK-incorporated) | paddle.com/legal/privacy |
Customer-to-business payments (Reservly is software-only)
Reservly is software-only. Reservly does not hold customer funds, does not maintain a master merchant account, and is not a Payment Facilitator, Payment Services Provider, Money Transmitter, or Merchant of Record under any regulatory definition (including PSD2, the UK Payment Services Regulations, FinCEN, US state money-transmitter laws, or the Mastercard / Visa Payment Facilitator registries). When a business using Reservly accepts payments from its customers through Stripe, Stripe processes payment data on the business's instruction — not Reservly's instruction. This means Stripe is not Reservly's sub-processor in this flow; it is an independent data processor engaged directly by the business through the business's own Stripe Connect Standard account. The business, as the merchant of record, has its own contractual relationship with Stripe and is responsible for Stripe's data-processing practices in the customer-facing payment flow.
Reservly lists this provider here for transparency, because the OAuth connect flow passes through Reservly's infrastructure and Reservly stores minimal payment-adjacent reference data (transaction IDs, as described in the Privacy Policy). The customer personal data processed during payment itself — card details, billing address, bank account information — is governed solely by the business's agreement with Stripe, not by Reservly's DPA.
The following table describes this relationship for transparency. Stripe is not Reservly's sub-processor; it is listed because Reservly stores OAuth tokens that link a business's account to Stripe.
| Sub-processor | Purpose | Data categories processed | Region | Provider privacy page |
|---|---|---|---|---|
| Stripe (Stripe, Inc.) | Customer-to-business payment processing via business's own Stripe Connect Standard account — Stripe processes on the business's instruction, not Reservly's | OAuth tokens linking a business to its Stripe account (encrypted at rest in Supabase Vault); payment intent reference IDs. Card details and billing data are processed solely by Stripe under the business's agreement with Stripe. | Global | stripe.com/privacy |
Planned sub-processors
These services are contracted or under evaluation and will appear in the "Current" tables above on the date they begin processing live data. We will announce each activation through the notice process described below at least 30 days in advance.
| Sub-processor | Purpose | Planned activation | Region |
|---|---|---|---|
| Mistral AI (Mistral AI SARL) | AI-powered translation of business-authored content (service names, descriptions, policies) via the R4.2 translation feature. Data processed in the EU; no third-country transfer; paid API excludes data from model training; 30-day data retention limit. DPA available at legal.mistral.ai. | On R4.2 translation feature launch | France / European Union — eu-central-1 (Frankfurt) |
| Telnyx (Telnyx LLC) | SMS delivery for bookings in North America (USA, Canada, Mexico) | On SMS feature launch | United States |
| Infobip (Infobip Ltd.) | SMS delivery for bookings in the European Union, United Kingdom, and adjacent markets | On SMS feature launch | European Union |
How we manage sub-processor changes
We maintain a Data Processing Agreement or equivalent contract with every sub-processor that processes personal data on our behalf, and we rely on Standard Contractual Clauses or an equivalent transfer mechanism for international transfers where required.
We review each sub-processor's data-processing practices, DPA status, and region at least annually. The Last updated date at the top of this page reflects the most recent review cycle. Individual sub-processor rows do not show per-row review dates; all rows were verified as of the most recent Last updated date unless otherwise noted.
When we propose to add a new sub-processor or materially change an existing one, we will post the change on this page and send notice to the primary contact email on every active subscription at least 30 days before the change takes effect, unless a shorter period is required by law or by a security-critical incident. During that window, a business may object to the change by emailing support@reservly.io. If we cannot accommodate the objection, the business may terminate its subscription and receive a pro-rated refund of any prepaid fees for the remaining service period.
Subscribe to change notifications
Businesses with active subscriptions receive sub-processor change notices automatically at the primary contact email.
Other parties (prospective customers, auditors, procurement teams) may subscribe to change notifications by emailing support@reservly.io with the subject line "Sub-processor list subscribe" and we will add the address to the notice list. You may unsubscribe at any time with the subject line "Sub-processor list unsubscribe."
We plan to add an RSS feed for this page in a future update; when available, it will be linked here.
Changelog
This section records every material change to the list above, in reverse chronological order.
| Date | Change |
|---|---|
| 2026-07-12 | Moved Twilio from "Planned" to "Current" sub-processors (new "SMS delivery" section) — BYO Twilio SMS has been live since PRs #118/#120/#124, roughly seven weeks before this page's prior "Last updated" date. Telnyx and Infobip remain Planned; no code integration exists for either yet. Also corrected the Upstash region to European Union — Frankfurt (provisioned 2026-07-11), removed "object storage" from Supabase's listed purpose (100% of object storage runs through Cloudflare R2), and removed the fabricated "last four digits of payment methods" storage claim from the Stripe row and surrounding prose (Reservly never sees or stores card data). |
| 2026-07-05 | Removed PayPal Commerce Platform from the customer-to-business payments section. Reservly launches Stripe-only; PayPal is no longer an available payment provider. Stripe's row and its independent-processor posture are unchanged. |
| 2026-06-20 | Corrected the Supabase region to eu-central-1 (Frankfurt, Germany) following the 2026-05-02 EU migration (the former US-region project was permanently deleted). Stated Cloudflare R2 image-storage jurisdiction as the European Union (EU). Removed the "Integrations activated at the business's option" section (Google / Microsoft / Zoom / Dropbox calendar, meeting, and backup integrations) — these were withdrawn from the product; calendar is now subscribable ICS feeds plus .ics email attachments, with no third-party calendar, meeting, or backup sub-processor. Reconciled the backup-resilience claim to match production: daily encrypted backups are retained for 7 days (Supabase Pro). |
| 2026-04-26 | Reclassified Stripe and PayPal from "sub-processors" to "independent processors engaged by the business" in the customer-to-business payment section. Expanded Google and Microsoft integration rows with explicit data-flow direction (bidirectional calendar, write-only backup/meetings). Added UK Addendum/IDTA and UK-US Data Bridge footnote for UK transfers. Added last-reviewed disclosure to sub-processor management section. Added Mistral AI SARL to planned sub-processors (R4.2 AI translation feature). Confirmed DeepSeek is not and will not be integrated — excluded from this list per A6 compliance review (GDPR unlawful transfer risk, active Italian/German DPA actions). |
| 2026-04-26 | Open item — RA-47: Upstash DPA acceptance pending Steve's verification. Upstash processes IP-address-derived rate-limiting counters, which constitute personal data under GDPR Recital 30. Steve must log in at upstash.com/trust and confirm the Data Processing Agreement has been signed or accepted for the Reservly account. This entry will be updated once confirmed — see RA-47. |
| 2026-04-16 | Initial publication. |
Contact
Questions about any sub-processor, a specific transfer, or our sub-processor program generally: support@reservly.io.
Formal data-protection inquiries (data subject requests, regulator correspondence): support@reservly.io with subject line "Privacy Officer" — routed to Reservly's designated Privacy Officer role.