Trust
Sub-processors
Last updated 26 August 2026
In plain English
These are the companies that touch data on our behalf, what each one does, and where it happens. All of them process in the United States. When we add one, we tell you before it starts, so you have time to object.
Why this page exists
When you run an affiliate program on AffiliateRail, your affiliates and your referred customers are your data. You decide why it is held and we hold it for you, which makes you the controller and us the processor. UK GDPR says we may not pass that data to anyone else without your authorisation.
Publishing the list is how that authorisation works in practice. Accepting our terms, which include the data processing agreement, is your general authorisation for the companies below.
Telling you about changes
We give 30 days' notice before a new sub-processor starts processing your data. The notice goes to the email on your account and this page is updated on the same day. If you object during those 30 days, tell us and we will either find another way or, if we cannot, you may end your subscription and we refund the unused part of what you have paid.
To be told about changes, email support@affiliaterail.com with "sub-processor notices" in the subject. That is a list of addresses and nothing else goes to it.
The list
Checked against what the software actually calls, not against a document. The provider positions below were checked on 26 August 2026 against each provider's own published terms; where we could not confirm something, this page says so rather than filling the gap.
| Who | What they do for us | Where | Transfer mechanism |
|---|---|---|---|
| Neon (Neon, LLC, part of Databricks, Inc.) | The database. Every record in your program lives here: partners, customers, the ledger, and the encrypted payout credentials and tax forms. | United States, AWS us-east-1 | EU-US Data Privacy Framework with the UK Extension, certified with the US Department of Commerce, backed by the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum in the Databricks data processing addendum |
| Vercel Inc. | Hosting and delivery for the dashboard, the partner portal, the API, the documentation, the tracker and the short-link redirector. Request logs include IP address and browser. | United States, iad1 (Washington DC) | 2021 Standard Contractual Clauses with the UK International Data Transfer Addendum, in Vercel's own data processing addendum. Vercel does not claim a Data Privacy Framework certification |
| Vercel Blob | Files uploaded to a program: the resources you give your partners, and anything they upload back. | United States | As Vercel above, under the same addendum |
| Stripe, Inc. | Two separate jobs. It takes our own subscription payments from you, where we are the controller. And with your permission it tells us, read only, about the sales your program produced, where we are your processor. We never write to your Stripe account. | United States, with Stripe Payments Europe in Ireland for European customers | Standard Contractual Clauses, the UK International Data Transfer Addendum and Data Privacy Framework self-certification, through Stripe's data transfers addendum. Stripe's data processing agreement was last updated 18 November 2025 |
| Resend (Plus Five Five, Inc.) | Sends email: your partners' invitations, approvals, payout notices and campaigns, and our own account emails to you. | United States | EU-US Data Privacy Framework with the UK Extension, certified, plus the EU Standard Contractual Clauses and the UK Addendum in its data processing agreement |
| Upstash, Inc. | A short-lived cache: rate-limit counters and 24 hours of replay protection on the API. It holds no record of a person, and losing all of it costs nothing. | United States | EU-US Data Privacy Framework with the UK Extension, plus Standard Contractual Clauses. Its addendum was last updated April 2025 |
| Sentry (Functional Software, Inc.) | Error reports when something breaks. Personal data is stripped before a report is sent, so what arrives is a stack trace and a request shape. | United States (ingest.us.sentry.io) | Data Privacy Framework, with the Standard Contractual Clauses and the UK Addendum as the fallback. Its addendum is version 5.1.0, 29 May 2024 |
| PostHog, Inc. | Which screens of the dashboard get used. Cookieless: no cookie, no local storage, no profile for anonymous traffic, no session replay, and no capture of anything you click. | United States (us.i.posthog.com) | EU-US Data Privacy Framework with the UK Extension, plus the Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Inngest, Inc. | Runs our scheduled and background work: payout batches, campaign sends, imports, webhook delivery. Every message we send it is one of our own record ids and nothing else, so it holds no personal data. | United States | Not confirmed. We could not find a published data processing addendum, and one is being requested. It is on this list because it is in the path, not because personal data reaches it |
| Firecrawl | Reads the public website an applicant gives us, so their application can be checked against something real. It receives that URL and nothing else about them. | United States | Not confirmed. A published addendum is being requested. Used only during application vetting |
| Anthropic, PBC | Not in use. AI-assisted drafting of campaign copy is behind a switch that is off. If it is ever turned on, this row becomes real and we give the 30 days' notice above first. | United States | Anthropic publishes a data processing addendum. We would sign it, and confirm the mechanism, before turning anything on |
Your own payment rails are not on this list
When a payout goes out, we call PayPal, Wise or Payoneer using your credentials, on your account. They are your processors, engaged by you under your own agreement with them, and we are the software that presses the button. The money never passes through us and we hold no credential of our own with any of them.
Your billing provider is the same shape. If you connect Stripe, the read-only permission you grant is yours to withdraw.
What we do not do
- We do not sell data, and we do not share it with anyone not on this page.
- We run no advertising trackers, on the marketing site or in the product.
- We use no analytics that stores anything in a visitor's browser.
- No personal data is processed inside the UK or the EEA today. Every company above processes in the United States, and the mechanisms in the last column are what makes that lawful. The full detail is in the transfers annex of the data processing agreement.
Questions
Email support@affiliaterail.com. If your procurement process needs a signed copy of the data processing agreement rather than the accepted-by-reference version, say so and we will send one.