Subprocessors
Last updated: June 8, 2026
To provide the HTMLvault service (“Service”), we engage a small set of trusted third-party companies that process data on our behalf (“subprocessors”). This page lists those subprocessors, what they do, and where to find their data-protection terms. It is referenced by our Privacy Policy and supports the data-protection commitments described there. We require each subprocessor to handle data under contractual terms at least as protective as our own, and we remain responsible for their processing of data we entrust to them.
How to stay informed of changes
We may add or replace subprocessors as the Service evolves. When we make a material change to this list, we will update the “Last updated” date above. Customers with a Data Processing Agreement who would like advance notice of subprocessor changes can request it at [email protected].
Infrastructure subprocessors
| Subprocessor | Purpose | Data processed | Location | Reference |
|---|---|---|---|---|
| Vercel Inc. | Application hosting, edge delivery, serverless compute | Account data, published content, request and usage logs | United States | Terms |
| Supabase, Inc. | Primary database (Postgres), storage | Account data, published content, link analytics | United States | Terms |
| Cloudflare, Inc. | DNS, CDN, TLS, and edge proxy | Request metadata, IP addresses, traffic routing | Global edge network | Terms |
Platform subprocessors
| Subprocessor | Purpose | Data processed | Location | Reference |
|---|---|---|---|---|
| WorkOS, Inc. | Authentication and identity (Magic Auth, Passkeys, SSO/SAML) | Email address, authentication events | United States | Terms |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact, plan/subscription status, payment details (handled by Stripe) | United States | Terms |
| Twilio (SendGrid) | Transactional email delivery (account, link, and password notifications) | Recipient email addresses, message content | United States | Terms |
| Zoho Corporation | Business email inboxes (support and account correspondence) | Email correspondence you send to us | United States / Global | Terms |
Security and safety subprocessors
| Subprocessor | Purpose | Data processed | Location | Reference |
|---|---|---|---|---|
| Google LLC (Safe Browsing) | Malicious-URL and phishing checks on links at upload and creation | Link URLs submitted for scanning | United States | Terms |
Customer-directed subprocessors (bring your own key)
If you enable AI-powered PII scanning on a paid plan, content is transmitted to the AI provider you select, under your account and key, and subject to that provider’s terms. These are not subprocessors we engage on your behalf — you direct the connection and the relationship is between you and your chosen provider. Depending on your configuration this may include providers such as Anthropic, OpenAI, or Google. Our default regex-based PII scanning runs within the Service and does not transmit your content to any external AI provider.
Analytics on our own marketing site
We use Google Analytics (GA4) and Vercel Analytics on the HTMLvault marketing site to understand how the site is used. These do not run on the links you publish or on white-labeled customer domains.
Contact
HTMLvault, 704 13th St East, Suite 600, Whitefish, MT 59937. [email protected]