Subprocessors

Annex III to the Data Processing Agreement · Last updated: August 2026

These are the processors onpack engages to provide the platform. The list is authoritative: it is generated from the same source the privacy policy and the DPA read, so the three cannot drift apart.

We will give thirty days' notice before adding or replacing a subprocessor. To be told, write to [email protected] with "subprocessor notice" in the subject.

Platform subprocessors

Provider Purpose Location Data Transfer basis
Hetzner Online GmbH Application and database hosting Germany (EEA) All platform data — brand accounts, product records, scans, collector accounts None — processing takes place within the EEA
Cloudflare, Inc. CDN, TLS termination and DDoS protection in front of the application United States, with EEA edge locations Request metadata in transit: IP address, user agent, requested URL Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
Cloudinary Storage and delivery of product images, brand logos, 3D models and supporting documents United States / Israel Brand-supplied media and documents. No consumer personal data. Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
Google Ireland Limited (Google Workspace) Transactional email — account confirmations, password resets, reward codes, expiry notices Ireland (EEA), with processing in the United States Recipient email address and message content Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
Stripe Payments Europe, Ltd. / Stripe, Inc. Subscription billing for brand accounts Ireland (EEA) and United States Brand billing contact and payment details. Card numbers never reach our servers. Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
IPinfo, LLC IP-to-country lookup for scan analytics; optional VPN/proxy detection for company signup review United States Scan IP addresses only with collector consent. Company signup IP addresses for abuse prevention when the signup lookup is configured. Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
Anthropic, PBC Draft product-label translations and summarise company signup risk signals for human review United States Product text for requested translations. Signup risk flags and coarse timing/network classifications; no signup email address, raw IP address, password or browser identifier. Standard Contractual Clauses (Art. 46(2)(c) GDPR), incorporated in the provider's DPA
JustShipIt Pte. Ltd. (DataFast) Visitor analytics for the marketing site onpack.io — not the brand app, not product or collector pages Singapore, with hosting in the United States Page opened, referrer, browser language, timezone and screen size, plus the IP address of the request. Cookieless: the visitor identifier is hashed server-side with a salt that rotates daily. DataFast's data processing agreement (Singapore law), which relies on its hosting providers' Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Functional Software, Inc. (Sentry) Application error monitoring Germany (Sentry EU region) Error diagnostics. Collector IP addresses and request headers are stripped before sending. None — processing takes place within the EEA

Tags a brand can switch on

Not our subprocessors. A brand can enter a Google Analytics measurement ID or a Meta pixel ID in its own settings, and we then render that tag on that brand's collector pages. The brand is the controller for it and has to cover it in its own privacy notice. Both are off by default and onpack receives nothing from either. They are listed because we render the script, and because a reader auditing our Content-Security-Policy will find these two hosts on it.

Google Analytics 4 Optional, brand-configured. Off unless a brand enters a measurement ID. United States The brand is the controller and provides its own basis
Meta Pixel Optional, brand-configured. Off unless a brand enters a pixel ID. United States The brand is the controller and provides its own basis

International transfers

7 of the 9 providers above involve a transfer outside the EEA. Each is covered by the Standard Contractual Clauses under Art. 46(2)(c) GDPR, incorporated in that provider's own data processing agreement. Where a provider is additionally self-certified under the EU–US Data Privacy Framework, that certification is an alternative basis we do not rely on in place of the clauses — a certification can be withdrawn between you reading this page and an incident; the clauses cannot.

Everything that constitutes the product — accounts, product records, passports, scans, collector data — is stored in Germany. The third-country processors handle transit metadata, outbound email, billing, an IP lookup, and brand-supplied media.

We use cookies to remember your preferences and improve your experience. See our Privacy Policy for details.