Sub-processors
The providers Mergelay engages to process personal data on a customer’s behalf, and separately the third parties that receive data because you told Mergelay to send it there. This list is referenced by the Data Processing Agreement, which gives a general authorisation for these sub-processors and a right to object within 30 days of a change.
Version 1 —Sub-processors
These providers process personal data on Mergelay’s instructions, under art. 28 contracts, and are bound by obligations equivalent to those in the DPA.
| Provider | Legal entity | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|---|
| Vercel | Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA | Hosting for the website, the authentication UI and the web application. | All web requests: sign-in submissions, session cookies, IP address, user agent, request logs, and the one-time review-link URL. | United States. No European region is pinned today. | EU–U.S. Data Privacy Framework (Vercel Inc. is certified), plus SCCs in its DPA. |
| Railway — API and file store | Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA | Runs the API and the scheduler, and hosts the persistent volume holding the workspace file store. | All workspace content: repository and pull-request metadata, analyses, drafts, approvals, imported contacts, delivery records with recipient addresses, audit trail, uploaded brand assets, encrypted destination credentials. API request logs with client IP. | United States. No European region is pinned today. | Standard contractual clauses (EU 2021/914) under Railway’s DPA. No Data Privacy Framework certification is asserted. |
| Railway — PostgreSQL | Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA | Identity database: accounts, sessions, OAuth links, workspaces, memberships, agent tokens. | Email addresses, display names, password hashes, encrypted OAuth tokens, session records with IP address and user agent, verification tokens, workspace names and roles, token hashes. | United States. No European region is pinned today. | Standard contractual clauses (EU 2021/914) under Railway’s DPA. |
| Resend | Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA | Transactional email (verification, password reset, “ready to review”), customer digests, and verification of workspace sending domains. | Recipient email address, subject and rendered body, the one-time review link, and the sending domain name. | United States (delivery over Amazon SES infrastructure). | EU–U.S. Data Privacy Framework (Plus Five Five, Inc. complies), plus SCCs in its DPA. |
| Anthropic | Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland — Anthropic PBC (USA) | Change analysis and draft generation. | Repository metadata and sanitised diffs after redaction of email addresses, credentials and high-entropy tokens; workspace product context; prior draft text. | Irish contracting entity for the EEA, UK and Switzerland; inference infrastructure largely in the United States. | Contracting with the Irish entity, plus standard contractual clauses under Anthropic’s DPA. No Data Privacy Framework certification is asserted. |
| PostHog | PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA — PostHog Cloud EU | Optional product analytics. Engaged only after the visitor explicitly allows analytics. | A pseudonymous “user:<uuid>” identifier and allow-listed event names and low-cardinality properties. No cookie, no local storage, no session replay, no repository or draft content. | European Union — AWS eu-central-1, Frankfurt, Germany. | Data at rest stays in the EU. For US support access, PostHog’s DPA carries the EU–U.S. Data Privacy Framework and standard contractual clauses. |
| GitHub | GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA | The Mergelay GitHub App: reads merged pull requests, releases and repository content for the repositories you connect, and receives signed webhooks. | Repository, pull-request and release metadata and content; installation identifiers; webhook payloads. | United States. | GitHub maintains its own EU–U.S. Data Privacy Framework certification, distinct from Microsoft’s, plus SCCs in the GitHub Data Protection Agreement. |
| OpenAI-compatible gateway | Whatever provider an operator configures. None is configured in production today. | Optional fallback model tier for self-hosted deployments, used only when no Anthropic key is present. | The same redacted payload as the Anthropic path. Nothing is sent while it is unconfigured. | Wherever the configured endpoint runs. | Not applicable — not configured in production today. It would be added to this list, with 30 days’ notice, before any customer data reached it. |
Inter and JetBrains Mono are downloaded and self-hosted at build time, so no visitor’s browser ever contacts a font CDN. Google Fonts is not a runtime sub-processor and is deliberately absent from the table above.
Independent controllers and destinations you choose
These are not Mergelay’s sub-processors. Each decides its own purposes, applies its own terms and notices, and receives data either because you signed in with it or because you configured it as a destination and approved a publication to it.
| Recipient | Legal entity | Why it receives data | Transfer mechanism |
|---|---|---|---|
| Polar (merchant of record) | Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA | Sells the subscription and the X credit packs, issues the invoice, collects and remits taxes. It collects the buyer’s name, email and payment instrument on its own checkout; Mergelay sends it only the workspace identifier and plan metadata. | No Data Privacy Framework certification is asserted. Standard contractual clauses, or art. 49(1)(b) GDPR for a payment you initiate. |
| Google sign-in | Google Ireland Limited (EEA) — Google LLC (USA) | Authenticates you when you choose “Sign in with Google”. | Google LLC is certified to the EU–U.S. Data Privacy Framework, plus SCCs. |
| GitHub sign-in | GitHub, Inc. (USA) — GitHub B.V. (Netherlands) | Authenticates you when you choose “Sign in with GitHub”. A separate OAuth app from the GitHub App above. | GitHub’s own EU–U.S. Data Privacy Framework certification, plus SCCs. |
| Microsoft sign-in and Microsoft Teams | Microsoft Ireland Operations Limited (EEA) — Microsoft Corporation (USA) | Optional “Sign in with Microsoft”, and the Teams workflow endpoint you configure as a destination. | Microsoft’s US entities are certified to the EU–U.S. Data Privacy Framework, plus SCCs. |
| Slack | Slack Technologies Limited (Ireland) — Slack Technologies, LLC (USA), Salesforce group | Receives an approved Update through the incoming webhook you configure. | Salesforce-group EU–U.S. Data Privacy Framework certification, plus SCCs in Slack’s DPA. |
| LinkedIn Ireland Unlimited Company (EEA) — LinkedIn Corporation (USA) | Publishes an approved post to the member profile you connected. | LinkedIn Corporation maintains its own EU–U.S. Data Privacy Framework certification, distinct from Microsoft’s, plus SCCs. | |
| X | X Internet Unlimited Company (Ireland) — X Corp. (USA) | Publishes an approved post to the X account you connected. | No Data Privacy Framework certification is asserted. Standard contractual clauses, or art. 49(1)(b) for a post you publish yourself. |
| Bluesky | Bluesky Social, PBC, 1925 Post Alley, Suite 301, Seattle, WA 98101-1028, USA | Publishes an approved post through the AT Protocol. Posts on that network are public by construction and freely redistributable. | No Data Privacy Framework certification is asserted. Art. 49(1)(b) for a post you publish yourself; standard contractual clauses otherwise. |
| Mastodon instance | The operator of the instance you connect. Mastodon gGmbH publishes the software and runs mastodon.social; it is not the operator of every instance. | Publishes an approved post to your account on that instance. | Determined by the instance operator you chose. Check its own notice. |
| Your automation endpoint | Whatever n8n, Make, Zapier or self-hosted endpoint you configure. | Receives the “published” and “ready for review” events you asked for. The one-time review link is deliberately never included. | You determine it. |
How changes are announced
Before a new sub-processor starts processing customer personal data, this page is updated and its version number incremented, and workspace owners are emailed at least 30 days in advance. Objections on reasonable data-protection grounds go to hello@mergelay.com; the process is set out in clause 7 of the DPA.
Version history
- Version 1 — 31 August 2026. First published list, issued together with the legal notice, the rewritten privacy notice, the Terms of service and the DPA.