Sub-processors

Effective date: April 20, 2026 Last updated: April 20, 2026

Plain English, first

SignRoad runs on a small, fixed set of service providers. We only share data with them when it is necessary to run the service, and every provider is contractually bound to use your data only for that purpose.

We email active users at least 30 days before we add or replace a sub-processor that processes personal data. If you are a business customer, you can object on reasonable data-protection grounds.

Current sub-processors

Provider Purpose Location Data we share
Supabase Database, authentication, and storage US / EU region (depending on project) Account data, practice data, content you create
Dodo Payments Web payment processing Global (Dodo-controlled) Subscription status, last four digits of card
RevenueCat Mobile subscription management (iOS/Android) US Subscription status, platform transaction identifiers
Sentry Error reporting with PII stripped US / EU Stack traces, device context (no letter, goal, or reflection bodies)
Cloudflare DNS, DDoS protection, and edge delivery Global edge Request metadata for security and performance
Apple Push Notification service Push notifications (opt-in) Global Device push token
Firebase Cloud Messaging Push notifications on Android (opt-in) Global Device push token
Resend Transactional and optional product emails US Email address for operational and product emails (not your practice content)

What we do not share

Changes to this list

If we add a new sub-processor, we will:

  1. Update this page.
  2. Email the address on your account at least 30 days before the change takes effect.
  3. For B2B customers, give you 14 days to object on reasonable data-protection grounds.

Contact

Questions about this list: privacy@signroad.com.