Trust

Sub-processors

Last updated 26 August 2026

In plain English

These are the companies that touch data on our behalf, what each one does, and where it happens. All of them process in the United States. When we add one, we tell you before it starts, so you have time to object.

Why this page exists

When you run an affiliate program on AffiliateRail, your affiliates and your referred customers are your data. You decide why it is held and we hold it for you, which makes you the controller and us the processor. UK GDPR says we may not pass that data to anyone else without your authorisation.

Publishing the list is how that authorisation works in practice. Accepting our terms, which include the data processing agreement, is your general authorisation for the companies below.

Telling you about changes

We give 30 days' notice before a new sub-processor starts processing your data. The notice goes to the email on your account and this page is updated on the same day. If you object during those 30 days, tell us and we will either find another way or, if we cannot, you may end your subscription and we refund the unused part of what you have paid.

To be told about changes, email support@affiliaterail.com with "sub-processor notices" in the subject. That is a list of addresses and nothing else goes to it.

The list

Checked against what the software actually calls, not against a document. The provider positions below were checked on 26 August 2026 against each provider's own published terms; where we could not confirm something, this page says so rather than filling the gap.

WhoWhat they do for usWhereTransfer mechanism
Neon (Neon, LLC, part of Databricks, Inc.) The database. Every record in your program lives here: partners, customers, the ledger, and the encrypted payout credentials and tax forms. United States, AWS us-east-1 EU-US Data Privacy Framework with the UK Extension, certified with the US Department of Commerce, backed by the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum in the Databricks data processing addendum
Vercel Inc. Hosting and delivery for the dashboard, the partner portal, the API, the documentation, the tracker and the short-link redirector. Request logs include IP address and browser. United States, iad1 (Washington DC) 2021 Standard Contractual Clauses with the UK International Data Transfer Addendum, in Vercel's own data processing addendum. Vercel does not claim a Data Privacy Framework certification
Vercel Blob Files uploaded to a program: the resources you give your partners, and anything they upload back. United States As Vercel above, under the same addendum
Stripe, Inc. Two separate jobs. It takes our own subscription payments from you, where we are the controller. And with your permission it tells us, read only, about the sales your program produced, where we are your processor. We never write to your Stripe account. United States, with Stripe Payments Europe in Ireland for European customers Standard Contractual Clauses, the UK International Data Transfer Addendum and Data Privacy Framework self-certification, through Stripe's data transfers addendum. Stripe's data processing agreement was last updated 18 November 2025
Resend (Plus Five Five, Inc.) Sends email: your partners' invitations, approvals, payout notices and campaigns, and our own account emails to you. United States EU-US Data Privacy Framework with the UK Extension, certified, plus the EU Standard Contractual Clauses and the UK Addendum in its data processing agreement
Upstash, Inc. A short-lived cache: rate-limit counters and 24 hours of replay protection on the API. It holds no record of a person, and losing all of it costs nothing. United States EU-US Data Privacy Framework with the UK Extension, plus Standard Contractual Clauses. Its addendum was last updated April 2025
Sentry (Functional Software, Inc.) Error reports when something breaks. Personal data is stripped before a report is sent, so what arrives is a stack trace and a request shape. United States (ingest.us.sentry.io) Data Privacy Framework, with the Standard Contractual Clauses and the UK Addendum as the fallback. Its addendum is version 5.1.0, 29 May 2024
PostHog, Inc. Which screens of the dashboard get used. Cookieless: no cookie, no local storage, no profile for anonymous traffic, no session replay, and no capture of anything you click. United States (us.i.posthog.com) EU-US Data Privacy Framework with the UK Extension, plus the Standard Contractual Clauses and the UK International Data Transfer Addendum
Inngest, Inc. Runs our scheduled and background work: payout batches, campaign sends, imports, webhook delivery. Every message we send it is one of our own record ids and nothing else, so it holds no personal data. United States Not confirmed. We could not find a published data processing addendum, and one is being requested. It is on this list because it is in the path, not because personal data reaches it
Firecrawl Reads the public website an applicant gives us, so their application can be checked against something real. It receives that URL and nothing else about them. United States Not confirmed. A published addendum is being requested. Used only during application vetting
Anthropic, PBC Not in use. AI-assisted drafting of campaign copy is behind a switch that is off. If it is ever turned on, this row becomes real and we give the 30 days' notice above first. United States Anthropic publishes a data processing addendum. We would sign it, and confirm the mechanism, before turning anything on

Your own payment rails are not on this list

When a payout goes out, we call PayPal, Wise or Payoneer using your credentials, on your account. They are your processors, engaged by you under your own agreement with them, and we are the software that presses the button. The money never passes through us and we hold no credential of our own with any of them.

Your billing provider is the same shape. If you connect Stripe, the read-only permission you grant is yours to withdraw.

What we do not do

Questions

Email support@affiliaterail.com. If your procurement process needs a signed copy of the data processing agreement rather than the accepted-by-reference version, say so and we will send one.