Scripe 4.0 is here!

|

Read the update

Sub-processors

Last updated: August 2026

This page lists the sub-processors Scripe GmbH engages to process personal data on behalf of its customers ("Customer Data") under the Data Processing Agreement, as well as the service providers Scripe uses for processing for which Scripe itself is the controller (see our privacy notice).

Transfer safeguards: Where a provider processes personal data outside the EU/EEA, the transfer is based on an adequacy decision of the European Commission and/or the EU Standard Contractual Clauses concluded with the provider, and — where the recipient is certified — the EU–U.S. Data Privacy Framework. Details of the safeguard used with a specific provider are available on request at privacy@scripe.io.

Change notice: We announce intended additions or replacements of sub-processors on this page at least 30 days in advance. Business customers can subscribe to change notifications by e-mailing privacy@scripe.io.

1. Sub-processors of Customer Data

These providers process Customer Data as part of delivering the Scripe service:

Sub-processor Country Purpose
Vercel Inc. USA Application hosting and content delivery (frontend)
Railway Corp. USA Backend hosting, Redis caching and job queues
PlanetScale, Inc. USA (data residency: EU / Frankfurt) Managed database (application data)
Amazon Web Services EMEA SARL Luxembourg (region: EU / Frankfurt) File and media storage, backups (S3)
Cloudflare, Inc. USA Image CDN (post and profile images)
Upstash, Inc. USA Serverless Redis (API rate limiting, queues)
Clerk, Inc. USA Authentication and user management of workspace users
Microsoft Corporation (Azure OpenAI Service / Azure AI Foundry, incl. Anthropic Claude models) USA (regions: EU — Germany, Sweden — and USA) AI text generation, embeddings, image generation and related processing
Deepgram, Inc. USA Speech-to-text transcription and voice agent
ElevenLabs, Inc. USA Speech synthesis (voice agent output)
Features and Labels, Inc. (fal.ai) USA AI image generation and optional per-workspace image personalization
Exa Labs, Inc. USA AI-supported web research (search queries)
Pinecone Systems, Inc. USA Vector database (embeddings for content matching)
Braintrust Data, Inc. USA AI quality assurance and observability (prompt/response logging)
Pusher Ltd United Kingdom Realtime notifications (WebSockets)
Plus Five Five, Inc. (Resend) USA Transactional and notification e-mails
650 Industries, Inc. (Expo) USA Mobile push notification delivery (via Apple APNs / Google FCM)

2. Service providers for Scripe's own processing

For processing for which Scripe is itself the controller (account management, billing, product analytics, error monitoring, support, marketing — see our privacy notice), Scripe uses in particular: Stripe (payments), Apple (in-app purchases), Mixpanel (product analytics, EU data residency), Statsig (feature flags), Sentry (error monitoring, EU ingest), Axiom (technical logging), Intercom (support), Churnkey (cancellation flows), HubSpot (CRM), ActiveCampaign (e-mail marketing), FirstPromoter (affiliate program), Meta Platforms (advertising measurement, consent-based), Google (sign-in, YouTube metadata), Mux (marketing site videos) and Sanity (marketing content CDN).

3. Connected services you choose to use

The following services are connected only at the direction of the customer or its users (e.g. via OAuth) and act as independent services outside Scripe's sub-processing chain: LinkedIn (LinkedIn Ireland Unlimited Company — publishing, analytics), Slack (Salesforce, Inc. — notifications into your workspace), Notion (Notion Labs, Inc. — knowledge import), WhatsApp (Meta Platforms Ireland Ltd. — content capture channel), Giphy (GIF search) and Unsplash (stock photo search) in the post editor.

4. Data sources

For publicly available LinkedIn post data relating to connected accounts, Scripe uses a third-party provider of publicly available data. The provider receives only the connected account's public LinkedIn identifier — no customer content, credentials or access tokens — and processes no Customer Data on Scripe's behalf; it is an independent data source, not a sub-processor.

5. Infrastructure locations and jurisdictions (Art. 28 EU Data Act)

Notice pursuant to Art. 28 of Regulation (EU) 2023/2854 (Data Act): The Scripe service is operated on the infrastructure of the providers listed above, which are established in the EU, the United Kingdom and the USA; customer files and media are stored primarily in the EU (AWS, Frankfurt region). Providers established outside the EU may be subject to the laws of their country of establishment (in particular US law). Measures in place to prevent unlawful governmental access to or transfer of data held in the service include: encryption in transit (TLS) and at rest, EU data residency for primary storage where offered, contractual confidentiality and data protection obligations with all providers (Art. 28 GDPR agreements, EU Standard Contractual Clauses and/or EU–U.S. Data Privacy Framework) and the access controls described in Annex 2 of the Data Processing Agreement. Information on switching and data export is set out in Section XII of our terms.

For questions about this list, contact privacy@scripe.io.