Subprocessors used by SupaMail
These providers support the hosted service. The register identifies their purpose, the data involved, and the current service location where known.
Provider register
| Provider | Purpose | Data involved | Current location |
|---|---|---|---|
| Supabase | Authentication, Postgres control plane and mirror, private body Storage | User identity, Tenant records, encrypted credentials, mailbox metadata and bodies | United States for SupaMail-managed infrastructure |
| Vercel | Website, authentication callbacks, dashboard, onboarding, and billing routes | Web requests, session data, and transient setup payloads | Provider-managed global network; primary service data is in the United States |
| Fly.io | Always-on synchronization, API, MCP, and mailbox operation runtime | Mailbox content and credentials in transit; operational metadata | San Jose, United States |
| turbopuffer | Managed Hosting search | Bounded searchable message text and result metadata in a per-Tenant namespace | United States |
| Stripe | Checkout, subscriptions, invoices, and billing portal | Billing identity and transaction metadata; no mailbox content | Provider-managed |
| Resend | Transactional authentication email delivery | Recipient email address and authentication-email content | Ireland |
| GitHub | Optional sign-in | OAuth identity data when the User chooses GitHub authentication | Provider-managed |
| Google Fonts | Public and product page font delivery | Browser request data such as IP address and user agent | Provider-managed |
Customer-selected providers
The connected mailbox provider and a customer's BYO Supabase organization are selected by the customer. They are not SupaMail-selected subprocessors for that service relationship.
Changes to this register
Material changes will be published here and handled under the Privacy Notice and Data Processing Addendum. Questions may be sent to hi@supamail.dev.
