Trust

Sub-processors

Last updated 28 September 2026

RecruitAffiliates.ai, our sister product, has its own list at recruitaffiliates.ai/subprocessors.

In plain English

These are the companies that touch data on our behalf, what each one does, and where it happens. Most of them process in the United States. The live chat is the exception and processes inside the EU. When we add one, we tell you before it starts, so you have time to object.

Why this page exists

When you run an affiliate program on AffiliateRail, your affiliates and your referred customers are your data. You decide why it is held and we hold it for you, which makes you the controller and us the processor. UK GDPR says we may not pass that data to anyone else without your authorisation.

Publishing the list is how that authorisation works in practice. Accepting our terms, which include the data processing agreement, is your general authorisation for the companies below.

Telling you about changes

We give 30 days' notice before a new sub-processor starts processing your data. The notice goes to the email on your account and this page is updated on the same day. If you object during those 30 days, tell us and we will either find another way or, if we cannot, you may end your subscription and we refund the unused part of what you have paid.

To be told about changes, email support@affiliaterail.com with "sub-processor notices" in the subject. That is a list of addresses and nothing else goes to it.

We did not manage it for Crisp. The live chat went into the dashboard on 9 September 2026 and this page was updated on 10 September, so you got a day's notice instead of thirty. That is our mistake and it is written here rather than quietly fixed. If the live chat is the one you would have objected to, tell us and we will turn it off for your account.

The list

Checked against what the software actually calls, not against a document. Last checked on 28 September 2026 against the code and each provider's published terms. Where we could not confirm something, this page says so rather than filling the gap.

WhoWhat they do for usWhereTransfer mechanism
Neon (Neon, LLC, part of Databricks, Inc.) The database. Every record in your program lives here: partners, customers, the ledger, and the encrypted payout credentials and tax forms. United States, AWS us-east-1 EU-US Data Privacy Framework with the UK Extension, certified with the US Department of Commerce, backed by the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum in the Databricks data processing addendum
Vercel Inc. Hosting and delivery for the dashboard, the partner portal, the API, the documentation, the tracker and the short-link redirector. Request logs include IP address and browser. United States, iad1 (Washington DC) 2021 Standard Contractual Clauses with the UK International Data Transfer Addendum, in Vercel's own data processing addendum. Vercel does not claim a Data Privacy Framework certification
Vercel Blob Files uploaded to a program: the resources you give your partners, and anything they upload back. United States As Vercel above, under the same addendum
Stripe, Inc. Two separate jobs. It takes our own subscription payments from you, where we are the controller. And with your permission it tells us about the sales your program produced, where we are your processor. Stripe retired read-only connections for new platforms, so the permission its screen asks you to grant is broader than we use; the key we point at your account is restricted to reading, and we never write to your Stripe account. United States, with Stripe Payments Europe in Ireland for European customers Standard Contractual Clauses, the UK International Data Transfer Addendum and Data Privacy Framework self-certification, through Stripe's data transfers addendum. Stripe's data processing agreement was last updated 18 November 2025
Resend (Plus Five Five, Inc.) Sends email: your partners' invitations, approvals, payout notices and campaigns, and our own account emails to you. United States EU-US Data Privacy Framework with the UK Extension, certified, plus the EU Standard Contractual Clauses and the UK Addendum in its data processing agreement
Crisp (CRISP IM SAS) The live chat in the bottom corner of the dashboard. It is told nothing about you until you open it. Open it and it is given your name, your email address, your plan, your program and the screen you were on, so whoever answers does not have to ask you who you are. It runs in the merchant dashboard only: never in the partner portal your affiliates use, never in the tracker on your website, and never on this marketing site. The European Union. Messages are stored in the Netherlands and plugin data in Germany, on DigitalOcean, by Crisp's own account. CRISP IM SAS, 2 boulevard de Launay, 44100 Nantes, France. Crisp also runs relay servers in the United States, the United Kingdom and Singapore, which hold no message content and keep only connection logs: IP address, time, browser and the site the chat was opened from None needed for the storage. The EU and the EEA are covered by the UK adequacy regulations, so a transfer to France needs no additional safeguard. The relay connection logs are the one part that leaves the EEA, and Crisp's own data processing agreement covers them. It is not signed yet. Crisp requires it to be signed and uploaded per workspace and ours is being done now, which is why this row says so rather than implying paperwork we have not finished
Upstash, Inc. A short-lived cache: rate-limit counters and 24 hours of replay protection on the API. It holds no record of a person, and losing all of it costs nothing. United States EU-US Data Privacy Framework with the UK Extension, plus Standard Contractual Clauses. Its addendum was last updated April 2025
Sentry (Functional Software, Inc.) Error reports when something breaks. Personal data is stripped before a report is sent, so what arrives is a stack trace and a request shape. United States (ingest.us.sentry.io) Data Privacy Framework, with the Standard Contractual Clauses and the UK Addendum as the fallback. Its addendum is version 5.1.0, 29 May 2024
PostHog, Inc. Which screens of the dashboard get used. Cookieless: no cookie, no local storage, no profile for anonymous traffic, no session replay, and no capture of anything you click. United States (us.i.posthog.com) EU-US Data Privacy Framework with the UK Extension, plus the Standard Contractual Clauses and the UK International Data Transfer Addendum
Ahrefs Pte. Ltd. Counts visits to the marketing site so we can see which pages bring people in. Cookieless: no cookie, no local storage, no profile, and no personal data by Ahrefs' own description. It runs on this site only, never in the dashboard or the affiliate portal. Singapore (analytics.ahrefs.com), Ahrefs Pte Ltd, 16 Raffles Quay, Singapore 048581 Not yet in force. Ahrefs publishes a data processing addendum with the Standard Contractual Clauses pre-signed on their side, but they bind only once we sign Annex I and send it back, which we have not yet done. Their addendum names no UK International Data Transfer Addendum. It is on this list because it is in the path, and the signature is being chased
Inngest, Inc. Runs our scheduled and background work: payout batches, campaign sends, imports, webhook delivery. Every message we send it is one of our own record ids and nothing else, so it holds no personal data. United States Not confirmed. We could not find a published data processing addendum, and one is being requested. It is on this list because it is in the path, not because personal data reaches it
Firecrawl Reads the public website an applicant gives us, so their application can be checked against something real. It receives that URL and nothing else about them. United States Not confirmed. A published addendum is being requested. Used only during application vetting
Anthropic, PBC Writes the optional AI drafts in the dashboard: a translation of a message to your partners, and swipe copy for your partner resources. It receives the text you ask it to work on and a short summary of your website. Both features stay off unless AI drafting is switched on. Anthropic says standard API inputs and outputs are deleted within 30 days, subject to its published safety and legal exceptions. United States Anthropic's data processing addendum and Standard Contractual Clauses are incorporated into its commercial terms

Your own payout methods are not on this list

When a payout goes out, we call PayPal, Wise or Payoneer using your credentials, on your account. They are your processors, engaged by you under your own agreement with them, and we are the software that presses the button. The money never passes through us and we hold no credential of our own with any of them.

Your billing provider is the same shape. If you connect Stripe, the permission you grant is yours to withdraw at any time, from your own Stripe dashboard.

What we do not do

Questions

Email support@affiliaterail.com. If your procurement process needs a signed copy of the data processing agreement rather than the accepted-by-reference version, say so and we will send one.

Published 26 August 2026, updated 28 September 2026