Subprocessors

    Last updated: 2026-04-24

    A subprocessor is a third party that Unshift LLC ("Unshift") engages to process personal data on behalf of our customers in the course of delivering the Services (the Unshift Studio and hosted websites). This page lists our current subprocessors and is incorporated by reference into our Privacy Policy and our Data Processing Addendum.

    If you are a customer who requires advance notice of new subprocessors, subscribe to this page's changes at subprocessors@unshift.ai and we will email you at least 30 days before adding or replacing a subprocessor that processes Customer Personal Data.

    Current subprocessors

    VendorService usedCategoryCustomer personal data processedLocation of processingTransfer mechanism
    Supabase Inc.Managed PostgreSQL, Auth, Storage, RealtimeInfrastructure / databaseAccount identifiers, project metadata, user-submitted content, session tokensUnited States (AWS us-east-1)EU SCCs + UK IDTA
    Cloudflare, Inc.CDN, Workers for Platforms, R2 object storage, DNSInfrastructure / hostingAll data served to and from published sites; request logs (IP, user agent, URL)Global edge; metadata in USEU SCCs + UK IDTA
    Stripe, Inc.Payment processing, billing, tax, Customer PortalPaymentsName, email, billing address, tax ID, card details (Stripe is PCI-DSS Level 1)United States (global edge)EU SCCs + UK IDTA
    Amazon Web ServicesSES (transactional email), S3 (legacy file storage)Infrastructure / emailRecipient email addresses, email content, file contentsUnited States (us-east-1)EU SCCs + UK IDTA
    Functional Software, Inc. (Sentry)Error and performance monitoringObservabilityStack traces, user ID, IP address (scrubbed after collection), browser metadataUnited StatesEU SCCs + UK IDTA
    Google LLCGoogle Analytics 4 (GA4) on marketing site onlyAnalyticsIP address (anonymized), device identifiers, page views; loaded only after cookie consentUnited StatesEU SCCs + UK IDTA
    PostHog, Inc.Product analytics and session replay in the Studio (optional, separate opt-ins)AnalyticsPseudonymous user ID, page views, interaction events, masked session replay (if separately opted in); loaded only after cookie consentGermany (EU Cloud, Frankfurt)EU SCCs + UK IDTA
    OpenAI, L.L.C.GPT-class models via OpenAI APIAI inferencePrompt content (including any personal data the customer inputs), generated outputUnited StatesEU SCCs (OpenAI DPA)
    Anthropic PBCClaude models via Anthropic APIAI inferencePrompt content (including any personal data the customer inputs), generated outputUnited StatesEU SCCs (Anthropic DPA)
    GitHub, Inc.Source-control integration for exported projects (when customer chooses to connect)Developer toolingRepository content created by the customer, GitHub username, access tokenUnited StatesEU SCCs + UK IDTA
    Netlify, Inc.Optional production hosting for exported projects (when customer chooses to connect)DeploymentSite content, environment variables, deployment logsUnited StatesEU SCCs + UK IDTA

    Customer-initiated integrations (for example, connecting a customer's own GitHub or Netlify account, or configuring a custom analytics provider in their site) add additional data flows that are outside the scope of Unshift's subprocessor obligations because the customer is controlling them directly.

    How we select subprocessors

    We require every subprocessor to:

    1. Execute a Data Processing Agreement (DPA) that includes the EU Standard Contractual Clauses (Module Three or Module Four as applicable) and the UK International Data Transfer Addendum where relevant.
    2. Maintain security certifications appropriate to the data they handle (SOC 2 Type II, ISO 27001, or equivalent).
    3. Notify us of security incidents affecting our tenant within a defined timeframe (24 to 72 hours depending on the vendor).
    4. Be contractually prohibited from using Customer Personal Data to train their own models, except as strictly necessary to provide the service we purchased.

    Our AI providers (OpenAI and Anthropic) have published commitments that API customer data is not used to train their foundation models. See their enterprise API terms:

    How we notify you of changes

    We maintain this page as the single source of truth. When we add, remove, or replace a subprocessor that processes Customer Personal Data, we:

    1. Update this page.
    2. Email customers on the notification list (subscribe at subprocessors@unshift.ai) at least 30 days in advance.
    3. If a customer objects to a new subprocessor on reasonable grounds related to data protection, we work with the customer to find an alternative. If no alternative is possible, the customer may terminate the affected part of the Services with a pro-rata refund.

    In emergency cases (for example, a subprocessor suffers a material breach and we must replace them faster than 30 days allows), we notify as far in advance as practical and document the reason.

    Historical changes

    DateChangeReason
    2026-04-20Initial publication of subprocessor listLaunch of Unshift Studio

    Future additions, removals, and replacements will be appended here.

    Contact

    • Subprocessor questions or objections: privacy@unshift.ai
    • Subscribe to subprocessor change notifications: subprocessors@unshift.ai
    • Postal address: Unshift LLC, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States