A sub-processor is a third party we engage to process personal data on behalf of our customers. This page lists every one, what it does, and what it receives. It is referenced by Section 7 of our Data Processing Addendum and by Section 7 of our Privacy Policy.
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, storage, backups, and outbound email delivery | All Customer Personal Data held in the Service | United States (us-east-1 primary, us-west-2 backup replication) |
| Stripe, Inc. | Subscription billing and payment processing | Your billing contact details and payment method. No Customer Personal Data — no creator record ever reaches Stripe. | United States |
| Anthropic, PBC | Four features: suggesting how spreadsheet columns map to fields during an import; classifying a creator into a content category; drafting campaign brief copy; and generating draft landing-page copy from a campaign brief |
Import mapping: column headings and target field names only — for example
“Instagram Handle”, “Fee Paid”. The rows beneath those headings are
never transmitted.
Creator classification: a creator’s public social handle, public display name, public follower count, and the text of up to twelve of their recent public post captions. These are sent so the model can return a content category (for example “fitness”) and brand-safety flags. No email address, contact detail, private message, or figure a brand recorded privately — such as a fee — is ever sent. The model returns labels only and is never asked to produce a metric. Copy drafting: the campaign brief a brand writes — its goal, audience description and offer — together with the named creator’s public social handle and platform name, so the draft can address the right audience and name the right creator. No follower count, post content, email address or contact detail is sent. |
United States |
| Google LLC | Business email, for support and service correspondence | Your email address and the content of messages you send us | United States |
Some third parties receive data because you tell the Service to exchange data with them. They act as independent controllers under their own terms rather than on our instructions, so they are not sub-processors and are not covered by the notice commitment above. They are listed here because the distinction is easy to lose.
| Service | When it receives anything | Acting as |
|---|---|---|
| Google, Facebook (sign-in) | Only if you choose to sign in with that provider | Independent controller |
| Instagram / Facebook Graph, YouTube | Only for an integration you connect, within the scope you authorise | Independent controller |
| Commerce platforms you connect | Only for a store you connect, to read orders and discount codes | Independent controller |
This section lists integrations the software supports but which are switched off in production. It exists so that an absence is a deliberate, checkable statement rather than something inferred from silence — and so that enabling one means editing this section rather than remembering that a row is missing.
OpenAI, L.L.C. is integrated in the code, for finding similar past imports, but not engaged: since 11 September 2026 the component that would call it is not given a key, so the Service sends it no data. It was listed in the table above until that date. Anthropic was listed in this section until 7 September 2026; it has since moved into the table above, where it is the provider behind the four AI features listed there.
To ask about a sub-processor, request a signed copy of the DPA, or object to a proposed change: privacy@tejdux.com.