Subprocessors
The companies that process personal data when you use useClick, what each one does, where the data is, and what covers any transfer outside the EU. This list is part of our Data Processing Addendum.
1. Overview
When you use useClick to shorten links, run Link in bio pages, collect email addresses or measure your website, you are the controller of your visitors' data and useClick is your processor. The companies below help us provide the service. They are our subprocessors under Art. 28(2) and (4) GDPR, and each is bound by a data processing agreement with obligations at least as strict as those in our DPA.
- Where the data is stored: the database, including all click and page-view records, is hosted by Supabase in Frankfurt, Germany.
- What never reaches the database: IP addresses and full user agent strings. They pass through the hosting and edge providers at request time and are used to route the request, derive a coarse location and parse browser, OS and device.
- Transfers outside the EU: several providers are US companies or serve requests from a worldwide edge network. For each one the table names the safeguard: the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR) for certified companies, and Standard Contractual Clauses (Art. 46(2)(c) GDPR).
2. Subprocessors for customer data
These providers process Customer Personal Data as defined in the DPA: data about the people who click your links, visit your website or Link in bio page, or submit their email address through your email capture link.
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| SupabaseSupabase, Inc. (USA) | Database, sign-in and file storage for the whole service | All stored Customer Personal Data: click and page-view records, conversions, captured email addresses, Link in bio content; account data | EU: Frankfurt, Germany | Stored in the EU. Standard Contractual Clauses for any access from outside the EU |
| VercelVercel Inc. (USA) | Hosting of the web app, dashboard, API and website analytics endpoint; redirects on custom domains; scheduled jobs | Requests in transit, including IP address and user agent (used at request time, not stored by useClick); data passing between the app and the database | USA; edge network worldwide (a request is served near the visitor) | EU-US Data Privacy Framework and Standard Contractual Clauses |
| CloudflareCloudflare, Inc. (USA) | DNS, CDN and DDoS protection for useclick.io; redirects and click tracking for links on useclick.io and uclk.me; live visitor counts; Turnstile bot check on sign-in and sign-up | Requests in transit, including IP address and user agent (not stored by useClick); derived country, region and city; short-lived session IDs for live visitor counts | Global edge network (a request is handled at the data center closest to the visitor) | EU-US Data Privacy Framework and Standard Contractual Clauses |
| SentryFunctional Software, Inc. (USA) | Error monitoring and performance tracing; replays of a sample of browser sessions with page text masked | Technical error data (stack traces, request URLs, browser and OS) that can incidentally contain Customer Personal Data | EU data region (Germany) | Stored in the EU. EU-US Data Privacy Framework and Standard Contractual Clauses for access from the US |
| ResendResend (USA) | Sending email: double opt-in confirmations for email capture links, account and team emails, reports | Recipient email address and the content of the email | USA | Standard Contractual Clauses |
| GoogleGoogle LLC (USA) | Safe Browsing check of destination URLs when a link is created; website icons for links on Link in bio pages, fetched by our server (fonts on bio pages are self-hosted) | Destination URLs and their hostnames; no visitor data | USA; global network | EU-US Data Privacy Framework and Standard Contractual Clauses |
3. Other service providers
These providers handle data about useClick account holders or visitors to useclick.io itself, where useClick is the controller. They do not receive your visitors' data. The providers in section 2 also process account data (for example, Supabase stores your account and Resend sends your account emails).
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| StripeStripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) | Subscription payments, invoices and tax | Account holder's name, email, billing address and payment details (card data is handled by Stripe only) | EU (Ireland) and USA | EU-US Data Privacy Framework and Standard Contractual Clauses |
| CrispCrisp IM SAS (France) | Support chat inside the dashboard | Chat messages and anything a user types into the chat; browser details | EU | Not needed (EU) |
| Plausible AnalyticsSelf-hosted by useClick | Cookieless visitor statistics for useClick's own marketing pages | Page URL, referrer, country, browser, OS and device type; no cookies, no stored IP addresses | Server operated by useClick | Not applicable (no third-party processor for the analytics software) |
4. What is not on this list
Some features contact other services without sending them your visitors' personal data, or only when you choose to:
- Twitch, Kick and YouTube: for the automatic live status and latest video blocks on Link in bio pages, our server requests the public status or video feed of the channel you entered. No visitor data is sent.
- Embeds you add: YouTube, Spotify, SoundCloud or Vimeo players on a Link in bio page load from those services in the visitor's browser. You decide whether to add them.
- Site icons in the dashboard: to show the icon of a referrer or website, your browser loads it from the DuckDuckGo or Google favicon service. This sends your own IP address, not your visitors'.
- Sign in with Google: optional. If you use it, Google confirms your identity to us under its own terms.
5. How we announce changes
Before a new subprocessor starts processing Customer Personal Data, we update this page and email the owner of every useClick account at least 30 days in advance. The email names the provider, what it will do and where it processes data.
If you have a reasonable data protection objection, email [email protected] within those 30 days. We will look for a solution with you, and if there is none, you can end the affected subscription before the change takes effect. The process is set out in section 8 of the DPA.
Last updated
. This is the first published version of the list.
6. Contact
For questions about this list, a copy for your records of processing activities, or an objection, email [email protected]. How we handle personal data as a controller is described in our Privacy Policy.
