Active sub-processors
Neon, Inc.
- Purpose
- Primary PostgreSQL database — stores all app-user, payer, and chart employee data
- Data categories
- All PII categories: identity/contact (email, name, avatar), auth tokens, account/role, consent records + checkout attribution + analytics join-key sources, billing identifiers, org-chart employee data (names, titles, departments, reporting lines). The consent-gated behavioral event stream is delivered to OpenPanel once the cutover completes.
- Region
- AWS us-east-1 (United States)
- Transfer basis
- EU-US Data Privacy Framework (DPF) + EU SCCs 2021/914 + UK IDTA/Addendum
- Privacy policy
- https://neon.tech/privacy-policy
- Notes
- Primary data store; CLOUD Act reach persists regardless of region.
Vercel, Inc.
- Purpose
- Application hosting, edge delivery, serverless functions — all PII transits Vercel
- Data categories
- All PII categories in transit: request/response bodies including export buffers, auth tokens in headers, analytics payloads
- Region
- US (default iad1; region not currently pinned — see D5)
- Transfer basis
- EU-US DPF + EU SCCs 2021/914 + UK IDTA/Addendum
- Privacy policy
- https://vercel.com/legal/privacy-policy
- Notes
- Region pinning to fra1 is planned (D5) for EU accounts.
Stytch (Twilio, Inc.)
- Purpose
- User authentication, magic-link delivery, OAuth (Google), session management
- Data categories
- Identity/contact: email, name, OAuth profile data; auth: session tokens, provider IDs
- Region
- United States
- Transfer basis
- EU-US DPF (Twilio, Inc. participant #5394)
- Privacy policy
- https://stytch.com/legal/privacy
- Notes
- DPF basis confirmed for Twilio/Stytch. SCC fallback DPA execution pending confirmation.
Stripe, Inc.
- Purpose
- Payment processing for export passes — card checkout AND programmatic (x402) USDC settlement, which runs entirely through Stripe (deposit-mode crypto payments; no external facilitator)
- Data categories
- Billing identifiers (Stripe customer ID, subscription ID); Stripe holds payment card data on its own servers — OCS does not receive or store card numbers. For x402 USDC payments, Stripe mints a per-payment crypto deposit address and detects the on-chain deposit; the payer's public wallet address may be surfaced to Stripe on the charge (pseudonymous, not stored by OCS). OCS stores checkout metadata (session ID, amount, currency, UTM attribution) in its own database.
- Region
- United States
- Transfer basis
- EU-US DPF + EU SCCs 2021/914
- Privacy policy
- https://stripe.com/privacy
OpenPanel (OpenPanel AB)
- Purpose
- Consent-gated product analytics and, under a separate consent purpose, session replay across the site and chart studio
- Data categories
- Product events: opaque user/account/anonymous/session identifiers, event names, URL paths without query strings, browser/user-agent information, and PII-scrubbed usage/attribution properties. No names, email addresses, raw query strings, stored IP addresses, or org-chart employee data are sent in the event payload. OpenPanel never stores raw IP addresses: an IP is used transiently to derive coarse location and a daily-rotating anonymous identifier, then discarded. Replay: DOM changes and interactions across the site excluding sign-in/verification, OAuth, and checkout routes; text and inputs masked by default; chart-node employee text (names, titles, custom fields) replaced with neutral placeholder text in-browser before transmission; employee-data surfaces (people list, export previews, import comparisons) and iframes blocked; opaque first-party actor id only.
- Retention
- Analytics events are retained while our OpenPanel account is active and deleted within 30 days of account termination; session replay is configured but currently paused and records nothing, and when it is enabled, replays are permanently deleted after 30 days
- Region
- EU only: primary analytics and session-replay storage on Hetzner in Germany, behind Cloudflare's EU edge, with backups in Cloudflare R2 in the EU. No US region.
- Transfer basis
- OpenPanel pre-signed Art. 28 Data Processing Agreement (incorporated into its terms of service) + EU Standard Contractual Clauses for its US sub-processors
- Privacy policy
- https://openpanel.dev/privacy
- Notes
- OpenPanel's DPA is at https://openpanel.dev/dpa and is pre-signed, so no countersignature round-trip is required. Its own sub-processors are Hetzner (Germany), Cloudflare and Cloudflare R2 (EU edge and EU backups), OpenAI (US; only when its opt-in AI features are invoked) and Resend (US; transactional email). Polar is OpenPanel's Merchant of Record for OpenPanel's own billing and is an independent controller, not a sub-processor. Public analytics, URL-parameter tracking, and automatic pageviews/navigation/autocapture are disabled for the Org Chart Studio property; only the consented product-event stream is enabled — session replay is configured behind its own consent purpose but is currently paused and records nothing — and raw IP addresses are never stored.
Google LLC (Google Analytics + Google Tag Manager)
- Purpose
- Google Analytics provides consent-gated web analytics and traffic measurement after analytics consent. Google Tag Manager additionally coordinates optional advertising conversion tags and loads only after both analytics and marketing-measurement consent.
- Data categories
- Online identifiers: IP address (anonymized per GA4 configuration), Google Analytics client ID, GA session ID, device/browser identifiers, behavioral telemetry (pages visited, events), referrer
- Region
- United States (Google LLC US entity processes EU data)
- Transfer basis
- EU-US DPF (Google LLC participant #5780) + EU SCCs
- Privacy policy
- https://policies.google.com/privacy
- Notes
- Disclosed in privacy policy §4.6 and §8. Google Analytics is not loaded until analytics consent is accepted; Google Tag Manager also requires marketing-measurement consent. Collection was paused from 2026-07-17 during an analytics migration and subsequently reinstated.
Legacy processors during migration
These providers receive no new analytics or replay data after the OpenPanel production cutover, but remain processors while historical data is retained for migration validation, rollback, or expiry.
LogRocket, Inc.
- Purpose
- Legacy consented session-replay history; no new recordings are collected
- Data categories
- Historical replay, interaction, and identified-user data collected under the prior masking configuration
- Region
- United States
- Transfer basis
- EU-US DPF + EU SCCs
- Privacy policy
- https://logrocket.com/privacy/
- Notes
- Remove from this list after the retained replay data and account are deleted.
Planned sub-processors (not yet active)
The following sub-processors are planned but not yet receiving personal data. This list will be updated and the active table above will be amended before any data flows to these services.
SendGrid (Twilio) and/or Email Octopus
- Purpose
- Transactional and marketing email (F12 — not yet procured)
- Region
- TBD at procurement
- Notes
- DPA/SCC review required at procurement. Sub-processor list will be updated before first send.
Questions and requests
If you have questions about our sub-processors or wish to object to the engagement of a new sub-processor (under your DPA rights), please contact us at hello@orgchartstudio.com.