Mergelay Back to Mergelay
MERGELAY SUB-PROCESSORS

Sub-processors

The providers Mergelay engages to process personal data on a customer’s behalf, and separately the third parties that receive data because you told Mergelay to send it there. This list is referenced by the Data Processing Agreement, which gives a general authorisation for these sub-processors and a right to object within 30 days of a change.

Version 1 — 31 August 2026

Sub-processors

These providers process personal data on Mergelay’s instructions, under art. 28 contracts, and are bound by obligations equivalent to those in the DPA.

ProviderLegal entityPurposeDataLocationTransfer mechanism
VercelVercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USAHosting for the website, the authentication UI and the web application.All web requests: sign-in submissions, session cookies, IP address, user agent, request logs, and the one-time review-link URL.United States. No European region is pinned today.EU–U.S. Data Privacy Framework (Vercel Inc. is certified), plus SCCs in its DPA.
Railway — API and file storeRailway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USARuns the API and the scheduler, and hosts the persistent volume holding the workspace file store.All workspace content: repository and pull-request metadata, analyses, drafts, approvals, imported contacts, delivery records with recipient addresses, audit trail, uploaded brand assets, encrypted destination credentials. API request logs with client IP.United States. No European region is pinned today.Standard contractual clauses (EU 2021/914) under Railway’s DPA. No Data Privacy Framework certification is asserted.
Railway — PostgreSQLRailway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USAIdentity database: accounts, sessions, OAuth links, workspaces, memberships, agent tokens.Email addresses, display names, password hashes, encrypted OAuth tokens, session records with IP address and user agent, verification tokens, workspace names and roles, token hashes.United States. No European region is pinned today.Standard contractual clauses (EU 2021/914) under Railway’s DPA.
ResendPlus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USATransactional email (verification, password reset, “ready to review”), customer digests, and verification of workspace sending domains.Recipient email address, subject and rendered body, the one-time review link, and the sending domain name.United States (delivery over Amazon SES infrastructure).EU–U.S. Data Privacy Framework (Plus Five Five, Inc. complies), plus SCCs in its DPA.
AnthropicAnthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland — Anthropic PBC (USA)Change analysis and draft generation.Repository metadata and sanitised diffs after redaction of email addresses, credentials and high-entropy tokens; workspace product context; prior draft text.Irish contracting entity for the EEA, UK and Switzerland; inference infrastructure largely in the United States.Contracting with the Irish entity, plus standard contractual clauses under Anthropic’s DPA. No Data Privacy Framework certification is asserted.
PostHogPostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA — PostHog Cloud EUOptional product analytics. Engaged only after the visitor explicitly allows analytics.A pseudonymous “user:<uuid>” identifier and allow-listed event names and low-cardinality properties. No cookie, no local storage, no session replay, no repository or draft content.European Union — AWS eu-central-1, Frankfurt, Germany.Data at rest stays in the EU. For US support access, PostHog’s DPA carries the EU–U.S. Data Privacy Framework and standard contractual clauses.
GitHubGitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USAThe Mergelay GitHub App: reads merged pull requests, releases and repository content for the repositories you connect, and receives signed webhooks.Repository, pull-request and release metadata and content; installation identifiers; webhook payloads.United States.GitHub maintains its own EU–U.S. Data Privacy Framework certification, distinct from Microsoft’s, plus SCCs in the GitHub Data Protection Agreement.
OpenAI-compatible gatewayWhatever provider an operator configures. None is configured in production today.Optional fallback model tier for self-hosted deployments, used only when no Anthropic key is present.The same redacted payload as the Anthropic path. Nothing is sent while it is unconfigured.Wherever the configured endpoint runs.Not applicable — not configured in production today. It would be added to this list, with 30 days’ notice, before any customer data reached it.

Inter and JetBrains Mono are downloaded and self-hosted at build time, so no visitor’s browser ever contacts a font CDN. Google Fonts is not a runtime sub-processor and is deliberately absent from the table above.

Independent controllers and destinations you choose

These are not Mergelay’s sub-processors. Each decides its own purposes, applies its own terms and notices, and receives data either because you signed in with it or because you configured it as a destination and approved a publication to it.

RecipientLegal entityWhy it receives dataTransfer mechanism
Polar (merchant of record)Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USASells the subscription and the X credit packs, issues the invoice, collects and remits taxes. It collects the buyer’s name, email and payment instrument on its own checkout; Mergelay sends it only the workspace identifier and plan metadata.No Data Privacy Framework certification is asserted. Standard contractual clauses, or art. 49(1)(b) GDPR for a payment you initiate.
Google sign-inGoogle Ireland Limited (EEA) — Google LLC (USA)Authenticates you when you choose “Sign in with Google”.Google LLC is certified to the EU–U.S. Data Privacy Framework, plus SCCs.
GitHub sign-inGitHub, Inc. (USA) — GitHub B.V. (Netherlands)Authenticates you when you choose “Sign in with GitHub”. A separate OAuth app from the GitHub App above.GitHub’s own EU–U.S. Data Privacy Framework certification, plus SCCs.
Microsoft sign-in and Microsoft TeamsMicrosoft Ireland Operations Limited (EEA) — Microsoft Corporation (USA)Optional “Sign in with Microsoft”, and the Teams workflow endpoint you configure as a destination.Microsoft’s US entities are certified to the EU–U.S. Data Privacy Framework, plus SCCs.
SlackSlack Technologies Limited (Ireland) — Slack Technologies, LLC (USA), Salesforce groupReceives an approved Update through the incoming webhook you configure.Salesforce-group EU–U.S. Data Privacy Framework certification, plus SCCs in Slack’s DPA.
LinkedInLinkedIn Ireland Unlimited Company (EEA) — LinkedIn Corporation (USA)Publishes an approved post to the member profile you connected.LinkedIn Corporation maintains its own EU–U.S. Data Privacy Framework certification, distinct from Microsoft’s, plus SCCs.
XX Internet Unlimited Company (Ireland) — X Corp. (USA)Publishes an approved post to the X account you connected.No Data Privacy Framework certification is asserted. Standard contractual clauses, or art. 49(1)(b) for a post you publish yourself.
BlueskyBluesky Social, PBC, 1925 Post Alley, Suite 301, Seattle, WA 98101-1028, USAPublishes an approved post through the AT Protocol. Posts on that network are public by construction and freely redistributable.No Data Privacy Framework certification is asserted. Art. 49(1)(b) for a post you publish yourself; standard contractual clauses otherwise.
Mastodon instanceThe operator of the instance you connect. Mastodon gGmbH publishes the software and runs mastodon.social; it is not the operator of every instance.Publishes an approved post to your account on that instance.Determined by the instance operator you chose. Check its own notice.
Your automation endpointWhatever n8n, Make, Zapier or self-hosted endpoint you configure.Receives the “published” and “ready for review” events you asked for. The one-time review link is deliberately never included.You determine it.

How changes are announced

Before a new sub-processor starts processing customer personal data, this page is updated and its version number incremented, and workspace owners are emailed at least 30 days in advance. Objections on reasonable data-protection grounds go to hello@mergelay.com; the process is set out in clause 7 of the DPA.

Version history

  • Version 1 — 31 August 2026. First published list, issued together with the legal notice, the rewritten privacy notice, the Terms of service and the DPA.
© 2026 Mergelay · Alexis Wychowaniak EI · Paris, FranceLegal noticePrivacyTermsDPA