Last updated: 9 providers

Subprocessors

The companies that process personal data when you use useClick, what each one does, where the data is, and what covers any transfer outside the EU. This list is part of our Data Processing Addendum.

1. Overview

When you use useClick to shorten links, run Link in bio pages, collect email addresses or measure your website, you are the controller of your visitors' data and useClick is your processor. The companies below help us provide the service. They are our subprocessors under Art. 28(2) and (4) GDPR, and each is bound by a data processing agreement with obligations at least as strict as those in our DPA.

  • Where the data is stored: the database, including all click and page-view records, is hosted by Supabase in Frankfurt, Germany.
  • What never reaches the database: IP addresses and full user agent strings. They pass through the hosting and edge providers at request time and are used to route the request, derive a coarse location and parse browser, OS and device.
  • Transfers outside the EU: several providers are US companies or serve requests from a worldwide edge network. For each one the table names the safeguard: the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR) for certified companies, and Standard Contractual Clauses (Art. 46(2)(c) GDPR).

2. Subprocessors for customer data

These providers process Customer Personal Data as defined in the DPA: data about the people who click your links, visit your website or Link in bio page, or submit their email address through your email capture link.

Subprocessors that process Customer Personal Data
ProviderPurposePersonal dataLocationTransfer safeguard
SupabaseSupabase, Inc. (USA)Database, sign-in and file storage for the whole serviceAll stored Customer Personal Data: click and page-view records, conversions, captured email addresses, Link in bio content; account dataEU: Frankfurt, GermanyStored in the EU. Standard Contractual Clauses for any access from outside the EU
VercelVercel Inc. (USA)Hosting of the web app, dashboard, API and website analytics endpoint; redirects on custom domains; scheduled jobsRequests in transit, including IP address and user agent (used at request time, not stored by useClick); data passing between the app and the databaseUSA; edge network worldwide (a request is served near the visitor)EU-US Data Privacy Framework and Standard Contractual Clauses
CloudflareCloudflare, Inc. (USA)DNS, CDN and DDoS protection for useclick.io; redirects and click tracking for links on useclick.io and uclk.me; live visitor counts; Turnstile bot check on sign-in and sign-upRequests in transit, including IP address and user agent (not stored by useClick); derived country, region and city; short-lived session IDs for live visitor countsGlobal edge network (a request is handled at the data center closest to the visitor)EU-US Data Privacy Framework and Standard Contractual Clauses
SentryFunctional Software, Inc. (USA)Error monitoring and performance tracing; replays of a sample of browser sessions with page text maskedTechnical error data (stack traces, request URLs, browser and OS) that can incidentally contain Customer Personal DataEU data region (Germany)Stored in the EU. EU-US Data Privacy Framework and Standard Contractual Clauses for access from the US
ResendResend (USA)Sending email: double opt-in confirmations for email capture links, account and team emails, reportsRecipient email address and the content of the emailUSAStandard Contractual Clauses
GoogleGoogle LLC (USA)Safe Browsing check of destination URLs when a link is created; website icons for links on Link in bio pages, fetched by our server (fonts on bio pages are self-hosted)Destination URLs and their hostnames; no visitor dataUSA; global networkEU-US Data Privacy Framework and Standard Contractual Clauses

3. Other service providers

These providers handle data about useClick account holders or visitors to useclick.io itself, where useClick is the controller. They do not receive your visitors' data. The providers in section 2 also process account data (for example, Supabase stores your account and Resend sends your account emails).

Service providers for accounts, billing, support and the useClick website
ProviderPurposePersonal dataLocationTransfer safeguard
StripeStripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA)Subscription payments, invoices and taxAccount holder's name, email, billing address and payment details (card data is handled by Stripe only)EU (Ireland) and USAEU-US Data Privacy Framework and Standard Contractual Clauses
CrispCrisp IM SAS (France)Support chat inside the dashboardChat messages and anything a user types into the chat; browser detailsEUNot needed (EU)
Plausible AnalyticsSelf-hosted by useClickCookieless visitor statistics for useClick's own marketing pagesPage URL, referrer, country, browser, OS and device type; no cookies, no stored IP addressesServer operated by useClickNot applicable (no third-party processor for the analytics software)

4. What is not on this list

Some features contact other services without sending them your visitors' personal data, or only when you choose to:

  • Twitch, Kick and YouTube: for the automatic live status and latest video blocks on Link in bio pages, our server requests the public status or video feed of the channel you entered. No visitor data is sent.
  • Embeds you add: YouTube, Spotify, SoundCloud or Vimeo players on a Link in bio page load from those services in the visitor's browser. You decide whether to add them.
  • Site icons in the dashboard: to show the icon of a referrer or website, your browser loads it from the DuckDuckGo or Google favicon service. This sends your own IP address, not your visitors'.
  • Sign in with Google: optional. If you use it, Google confirms your identity to us under its own terms.

5. How we announce changes

Before a new subprocessor starts processing Customer Personal Data, we update this page and email the owner of every useClick account at least 30 days in advance. The email names the provider, what it will do and where it processes data.

If you have a reasonable data protection objection, email [email protected] within those 30 days. We will look for a solution with you, and if there is none, you can end the affected subscription before the change takes effect. The process is set out in section 8 of the DPA.

Last updated

. This is the first published version of the list.

6. Contact

For questions about this list, a copy for your records of processing activities, or an objection, email [email protected]. How we handle personal data as a controller is described in our Privacy Policy.