Skip to main content

Reservly Sub-Processor List

Last updated: July 12, 2026

What is a sub-processor?

A sub-processor is a third-party service that Reservly uses to operate the platform. Where those services store, transmit, or otherwise process personal data on Reservly's behalf, the GDPR and similar laws classify them as sub-processors. The businesses that use Reservly are controllers of their customers' personal data; Reservly is a processor acting on each business's behalf; the services listed below are sub-processors engaged by Reservly.

This page lists every sub-processor we currently use, plus services we expect to activate in the near term. We keep the list current because the businesses we serve often need it to satisfy their own compliance programs.

Current sub-processors

Core platform infrastructure

Sub-processorPurposeData categories processedRegionProvider privacy page
Supabase (Supabase, Inc.)Primary application database (Postgres) and authenticationAccount data, booking data, usage logs, customer-provided booking form fields, encrypted OAuth tokens (Supabase Vault)European Union — eu-central-1 (Frankfurt, Germany)supabase.com/privacy
Vercel (Vercel, Inc.)Application hosting — serverless functions, edge network, static asset deliveryServer-side request and rendering data, access logsUnited States — iad1 (Northern Virginia)vercel.com/legal/privacy-policy
Cloudflare R2 (Cloudflare, Inc.)Object storage for business-uploaded images, served through our custom domain images.reservly.ioUploaded images (logos, gallery photos, floor plans), image metadataEuropean Union (EU) jurisdiction — reservly-images-eu bucketcloudflare.com/privacypolicy
Upstash (Upstash, Inc.)Rate-limiting state (fixed-window counters) and short-term countersAPI keys (hashed), per-key request counters, IP-address-derived countersEuropean Union — Frankfurt, Germanyupstash.com/trust/privacy.pdf

‡ For UK personal data transferred to US-based sub-processors (Vercel): the applicable transfer mechanism is the ICO-approved IDTA or UK Addendum to EU SCCs. Where a US-based sub-processor is certified under the UK-US Data Bridge, Reservly may rely on that certification in lieu of the IDTA for that specific transfer. Certification status will be verified per vendor before UK customer onboarding.

Communication and monitoring

Sub-processorPurposeData categories processedRegionProvider privacy page
Resend (Resend, Inc.)Outbound transactional email (booking confirmations, reminders, account email)Recipient email address, email subject and body, delivery eventsUnited Statesresend.com/legal/privacy-policy
Sentry (Functional Software, Inc. / Sentry)Application error and performance monitoringError stack traces, request metadata, breadcrumbs (PII scrubbed before ingest)European Union — ingest.de.sentry.io (Frankfurt)sentry.io/privacy

Push notification delivery

Sub-processorPurposeData categories processedRegionProvider privacy page
Google Firebase Cloud Messaging (Google LLC)Delivers browser/OS push notifications to Chrome, Edge, and other Chromium/Android-based devicesPush-subscription endpoint URL, encrypted subscription keys (p256dh, auth), encrypted notification payload (booking type, customer name, service, time)Global (Google-operated infrastructure)policies.google.com/privacy
Mozilla Push Service (Mozilla Corporation)Delivers browser push notifications to FirefoxPush-subscription endpoint URL, encrypted subscription keys, encrypted notification payloadGlobal (Mozilla-operated infrastructure)mozilla.org/privacy
Apple Push Notification service (Apple Inc.)Delivers browser/OS push notifications to Safari and iOS/macOS devicesPush-subscription endpoint URL, encrypted subscription keys, encrypted notification payloadGlobal (Apple-operated infrastructure)apple.com/legal/privacy

Reservly does not choose which of these three services is used for a given device — the recipient's browser makes that determination when the device subscribes to push notifications. This feature is used to notify business staff/owners of new bookings on their own devices; it is not used to send push notifications to end-user customers.

SMS delivery (business-connected "bring your own" Twilio)

Sub-processorPurposeData categories processedRegionProvider privacy page
Twilio (Twilio Inc.)SMS delivery via business-connected "bring your own" Twilio accounts — the business supplies its own Twilio Account SID and Auth Token; Reservly routes SMS through that business's accountTwilio Account SID and Auth Token (encrypted at rest in Supabase Vault), sending phone number, SMS send-event log (timestamp, delivery status, template type, masked recipient number + one-way hash), STOP/START opt-out recordsGlobal (business-selected Twilio numbering region)twilio.com/legal/privacy

Billing (Reservly's own subscriptions)

Sub-processorPurposeData categories processedRegionProvider privacy page
Paddle (Paddle.com Market Ltd.)Merchant of record for Reservly subscriptions — collects payment, handles global sales tax (VAT/GST), issues invoices and receipts, processes subscription cancellations and refunds. Note: Paddle is incorporated in the United Kingdom; no international transfer mechanism is required for UK personal data transferred to Paddle.Business billing contact, payment method (handled by Paddle; Reservly does not see card numbers), transaction amounts, tax determinationsGlobal, with EU primary (Paddle is UK-incorporated)paddle.com/legal/privacy

Customer-to-business payments (Reservly is software-only)

Reservly is software-only. Reservly does not hold customer funds, does not maintain a master merchant account, and is not a Payment Facilitator, Payment Services Provider, Money Transmitter, or Merchant of Record under any regulatory definition (including PSD2, the UK Payment Services Regulations, FinCEN, US state money-transmitter laws, or the Mastercard / Visa Payment Facilitator registries). When a business using Reservly accepts payments from its customers through Stripe, Stripe processes payment data on the business's instruction — not Reservly's instruction. This means Stripe is not Reservly's sub-processor in this flow; it is an independent data processor engaged directly by the business through the business's own Stripe Connect Standard account. The business, as the merchant of record, has its own contractual relationship with Stripe and is responsible for Stripe's data-processing practices in the customer-facing payment flow.

Reservly lists this provider here for transparency, because the OAuth connect flow passes through Reservly's infrastructure and Reservly stores minimal payment-adjacent reference data (transaction IDs, as described in the Privacy Policy). The customer personal data processed during payment itself — card details, billing address, bank account information — is governed solely by the business's agreement with Stripe, not by Reservly's DPA.

The following table describes this relationship for transparency. Stripe is not Reservly's sub-processor; it is listed because Reservly stores OAuth tokens that link a business's account to Stripe.

Sub-processorPurposeData categories processedRegionProvider privacy page
Stripe (Stripe, Inc.)Customer-to-business payment processing via business's own Stripe Connect Standard account — Stripe processes on the business's instruction, not Reservly'sOAuth tokens linking a business to its Stripe account (encrypted at rest in Supabase Vault); payment intent reference IDs. Card details and billing data are processed solely by Stripe under the business's agreement with Stripe.Globalstripe.com/privacy

Planned sub-processors

These services are contracted or under evaluation and will appear in the "Current" tables above on the date they begin processing live data. We will announce each activation through the notice process described below at least 30 days in advance.

Sub-processorPurposePlanned activationRegion
Mistral AI (Mistral AI SARL)AI-powered translation of business-authored content (service names, descriptions, policies) via the R4.2 translation feature. Data processed in the EU; no third-country transfer; paid API excludes data from model training; 30-day data retention limit. DPA available at legal.mistral.ai.On R4.2 translation feature launchFrance / European Union — eu-central-1 (Frankfurt)
Telnyx (Telnyx LLC)SMS delivery for bookings in North America (USA, Canada, Mexico)On SMS feature launchUnited States
Infobip (Infobip Ltd.)SMS delivery for bookings in the European Union, United Kingdom, and adjacent marketsOn SMS feature launchEuropean Union

How we manage sub-processor changes

We maintain a Data Processing Agreement or equivalent contract with every sub-processor that processes personal data on our behalf, and we rely on Standard Contractual Clauses or an equivalent transfer mechanism for international transfers where required.

We review each sub-processor's data-processing practices, DPA status, and region at least annually. The Last updated date at the top of this page reflects the most recent review cycle. Individual sub-processor rows do not show per-row review dates; all rows were verified as of the most recent Last updated date unless otherwise noted.

When we propose to add a new sub-processor or materially change an existing one, we will post the change on this page and send notice to the primary contact email on every active subscription at least 30 days before the change takes effect, unless a shorter period is required by law or by a security-critical incident. During that window, a business may object to the change by emailing support@reservly.io. If we cannot accommodate the objection, the business may terminate its subscription and receive a pro-rated refund of any prepaid fees for the remaining service period.

Subscribe to change notifications

Businesses with active subscriptions receive sub-processor change notices automatically at the primary contact email.

Other parties (prospective customers, auditors, procurement teams) may subscribe to change notifications by emailing support@reservly.io with the subject line "Sub-processor list subscribe" and we will add the address to the notice list. You may unsubscribe at any time with the subject line "Sub-processor list unsubscribe."

We plan to add an RSS feed for this page in a future update; when available, it will be linked here.

Changelog

This section records every material change to the list above, in reverse chronological order.

DateChange
2026-07-12Moved Twilio from "Planned" to "Current" sub-processors (new "SMS delivery" section) — BYO Twilio SMS has been live since PRs #118/#120/#124, roughly seven weeks before this page's prior "Last updated" date. Telnyx and Infobip remain Planned; no code integration exists for either yet. Also corrected the Upstash region to European Union — Frankfurt (provisioned 2026-07-11), removed "object storage" from Supabase's listed purpose (100% of object storage runs through Cloudflare R2), and removed the fabricated "last four digits of payment methods" storage claim from the Stripe row and surrounding prose (Reservly never sees or stores card data).
2026-07-05Removed PayPal Commerce Platform from the customer-to-business payments section. Reservly launches Stripe-only; PayPal is no longer an available payment provider. Stripe's row and its independent-processor posture are unchanged.
2026-06-20Corrected the Supabase region to eu-central-1 (Frankfurt, Germany) following the 2026-05-02 EU migration (the former US-region project was permanently deleted). Stated Cloudflare R2 image-storage jurisdiction as the European Union (EU). Removed the "Integrations activated at the business's option" section (Google / Microsoft / Zoom / Dropbox calendar, meeting, and backup integrations) — these were withdrawn from the product; calendar is now subscribable ICS feeds plus .ics email attachments, with no third-party calendar, meeting, or backup sub-processor. Reconciled the backup-resilience claim to match production: daily encrypted backups are retained for 7 days (Supabase Pro).
2026-04-26Reclassified Stripe and PayPal from "sub-processors" to "independent processors engaged by the business" in the customer-to-business payment section. Expanded Google and Microsoft integration rows with explicit data-flow direction (bidirectional calendar, write-only backup/meetings). Added UK Addendum/IDTA and UK-US Data Bridge footnote for UK transfers. Added last-reviewed disclosure to sub-processor management section. Added Mistral AI SARL to planned sub-processors (R4.2 AI translation feature). Confirmed DeepSeek is not and will not be integrated — excluded from this list per A6 compliance review (GDPR unlawful transfer risk, active Italian/German DPA actions).
2026-04-26Open item — RA-47: Upstash DPA acceptance pending Steve's verification. Upstash processes IP-address-derived rate-limiting counters, which constitute personal data under GDPR Recital 30. Steve must log in at upstash.com/trust and confirm the Data Processing Agreement has been signed or accepted for the Reservly account. This entry will be updated once confirmed — see RA-47.
2026-04-16Initial publication.

Contact

Questions about any sub-processor, a specific transfer, or our sub-processor program generally: support@reservly.io.

Formal data-protection inquiries (data subject requests, regulator correspondence): support@reservly.io with subject line "Privacy Officer" — routed to Reservly's designated Privacy Officer role.