Legal

    Sub-processors

    Last updated May 7, 2026 · Effective immediately

    In short: We rely on a small set of audited infrastructure providers. We will give you at least 30 days' notice before adding or changing any sub-processor.

    Current sub-processors

    ProviderPurposeRegionSafeguards
    SupabasePostgres database, authentication, edge functions, storageUnited StatesSCCs, SOC 2 Type II, ISO 27001
    CloudflareEdge worker, Pages Functions middleware, and CDN/DNS that route bot trafficGlobal edgeSCCs, US Data Boundary, ISO 27001/27018, SOC 2
    Render.comHosts the headless Puppeteer rendererUnited StatesSCCs, SOC 2
    VercelHosts the marketing site and dashboard frontendUnited States / global edgeSCCs, SOC 2 Type II
    StripePayment processing, invoicing, subscription managementUnited StatesSCCs, PCI DSS Level 1, US DPF
    ResendTransactional email delivery (from noreply@notify.renderbeam.com)United StatesSCCs, SOC 2
    OpenAI / Lovable AI GatewayAI features used in optional tooling (e.g. llms.txt generator)United StatesSCCs, no training on customer data, US DPF
    SnapSello InsightsCookieless aggregate analytics for the marketing siteUnited StatesNo personal identifiers collected
    Google (OAuth)Optional sign-in with GoogleGlobalSCCs, US DPF

    Notification of changes

    We notify customers at least 30 days before adding or replacing a sub-processor by updating this page and emailing the primary contact on the account. Customers may object on reasonable data-protection grounds — see the Data Processing Addendum.

    Subscribe to changes

    To be notified of changes, email privacy@renderbeam.com with the subject “Subscribe sub-processor updates”.

    Explore RenderBeam

    Learn what we do, how we price it, and how to get set up.