Our Suppliers
Every third party that processes personal data on Hostable's behalf, kept in sync with _facts.md and COMPLIANCE.md §1. We add or remove a supplier here before we start or stop using it, not after.
| Supplier | Role | What it processes | Data location | Safeguard for transfer |
|---|---|---|---|---|
| Linode (partial) + other self-hosted infrastructure | Processor (infrastructure) | Everything Hostable self-hosts: account/server database (PostgreSQL), session data, backups | Mixture of Linode and self-hosted — exact split/location(s) [TBC], see the Hostable repo's TODO.md, which tracks this as an open decision | [TBC — depends on final locations] |
| Stripe | Processor + independent controller (fraud/AML) | Payment data — integration is built and live in the product; awaiting production API keys | Stripe Payments Europe (Ireland) + US | Stripe's SCCs / DPF certification |
| Cloudflare | Processor | Traffic passing through the tunnel/edge (TLS termination) | US by default, EU option available | Cloudflare DPA, DPF certification |
| Resend | Processor | Transactional email content and recipient addresses | US (AWS) by default | Resend DPA [to be filed once accepted] |
Planned, not yet integrated — do not treat as a current sub-processor: Google AdSense (or another ad network, not yet chosen) for boost-earning ads, and a survey network (not yet chosen) for boost-earning surveys. Nothing in the product loads an ad-network script or sends it any data today — this row will move into the table above, with a real data location and safeguard filled in, only once a network is actually wired into the app and processing real user data.
Not on this list, deliberately: PostgreSQL, Docker, and DiscoPanel are self-hosted software running on Hostable's own infrastructure — they don't process data anywhere outside what's already covered by the hosting row above, so they aren't separate sub-processors. Paper, NeoForge, and Fabric (Minecraft server software) don't process Hostable account data at all — see the Acceptable Use Policy for the separate disclosure about third-party plugins/mods run on them.
We accept or file each supplier's data processing agreement before sending them personal data, and review this list at least annually or whenever a new supplier is added.
Right to change suppliers
We may add, remove, or replace a sub-processor. Material changes (a new supplier processing personal data, or a supplier moving data to a new location) will be reflected here with an updated date, and a versioned copy kept in the archive.
Questions
privacy@hostable.games