Annex III to the Data Processing Agreement · Last updated: August 2026
These are the processors onpack engages to provide the platform. The list is authoritative: it is generated from the same source the privacy policy and the DPA read, so the three cannot drift apart.
We will give thirty days' notice before adding or replacing a subprocessor. To be told, write to [email protected] with "subprocessor notice" in the subject.
| Provider | Purpose | Location | Data | Transfer basis |
|---|---|---|---|---|
| Hetzner Online GmbH | Application and database hosting | Germany (EEA) | All platform data — brand accounts, product records, scans, collector accounts | None — processing takes place within the EEA |
| Cloudflare, Inc. | CDN, TLS termination and DDoS protection in front of the application | United States, with EEA edge locations | Request metadata in transit: IP address, user agent, requested URL | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| Cloudinary | Storage and delivery of product images, brand logos, 3D models and supporting documents | United States / Israel | Brand-supplied media and documents. No consumer personal data. | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| Google Ireland Limited (Google Workspace) | Transactional email — account confirmations, password resets, reward codes, expiry notices | Ireland (EEA), with processing in the United States | Recipient email address and message content | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Subscription billing for brand accounts | Ireland (EEA) and United States | Brand billing contact and payment details. Card numbers never reach our servers. | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| IPinfo, LLC | IP-to-country lookup for scan analytics; optional VPN/proxy detection for company signup review | United States | Scan IP addresses only with collector consent. Company signup IP addresses for abuse prevention when the signup lookup is configured. | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| Anthropic, PBC | Draft product-label translations and summarise company signup risk signals for human review | United States | Product text for requested translations. Signup risk flags and coarse timing/network classifications; no signup email address, raw IP address, password or browser identifier. | Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA |
| JustShipIt Pte. Ltd. (DataFast) | Visitor analytics for the marketing site onpack.io — not the brand app, not product or collector pages | Singapore, with hosting in the United States | Page opened, referrer, browser language, timezone and screen size, plus the IP address of the request. Cookieless: the visitor identifier is hashed server-side with a salt that rotates daily. | DataFast's data processing agreement (Singapore law), which relies on its hosting providers' Standard Contractual Clauses (Art. 46(2)(c) GDPR) |
| Functional Software, Inc. (Sentry) | Application error monitoring | Germany (Sentry EU region) | Error diagnostics. Collector IP addresses and request headers are stripped before sending. | None — processing takes place within the EEA |
Not our subprocessors. A brand can enter a Google Analytics measurement ID or a Meta pixel ID in its own settings, and we then render that tag on that brand's collector pages. The brand is the controller for it and has to cover it in its own privacy notice. Both are off by default and onpack receives nothing from either. They are listed because we render the script, and because a reader auditing our Content-Security-Policy will find these two hosts on it.
| Google Analytics 4 | Optional, brand-configured. Off unless a brand enters a measurement ID. | United States | The brand is the controller and provides its own basis |
| Meta Pixel | Optional, brand-configured. Off unless a brand enters a pixel ID. | United States | The brand is the controller and provides its own basis |
7 of the 9 providers above involve a transfer outside the EEA. Each is covered by the Standard Contractual Clauses under Art. 46(2)(c) GDPR, incorporated in that provider's own data processing agreement. Where a provider is additionally self-certified under the EU–US Data Privacy Framework, that certification is an alternative basis we do not rely on in place of the clauses — a certification can be withdrawn between you reading this page and an incident; the clauses cannot.
Everything that constitutes the product — accounts, product records, passports, scans, collector data — is stored in Germany. The third-country processors handle transit metadata, outbound email, billing, an IP lookup, and brand-supplied media.
We use cookies to remember your preferences and improve your experience. See our Privacy Policy for details.