Subprocessors used by SupaMail

These providers support the hosted service. The register identifies their purpose, the data involved, and the current service location where known.

Provider register

ProviderPurposeData involvedCurrent location
SupabaseAuthentication, Postgres control plane and mirror, private body StorageUser identity, Tenant records, encrypted credentials, mailbox metadata and bodiesUnited States for SupaMail-managed infrastructure
VercelWebsite, authentication callbacks, dashboard, onboarding, and billing routesWeb requests, session data, and transient setup payloadsProvider-managed global network; primary service data is in the United States
Fly.ioAlways-on synchronization, API, MCP, and mailbox operation runtimeMailbox content and credentials in transit; operational metadataSan Jose, United States
turbopufferManaged Hosting searchBounded searchable message text and result metadata in a per-Tenant namespaceUnited States
StripeCheckout, subscriptions, invoices, and billing portalBilling identity and transaction metadata; no mailbox contentProvider-managed
ResendTransactional authentication email deliveryRecipient email address and authentication-email contentIreland
GitHubOptional sign-inOAuth identity data when the User chooses GitHub authenticationProvider-managed
Google FontsPublic and product page font deliveryBrowser request data such as IP address and user agentProvider-managed

Customer-selected providers

The connected mailbox provider and a customer's BYO Supabase organization are selected by the customer. They are not SupaMail-selected subprocessors for that service relationship.

Changes to this register

Material changes will be published here and handled under the Privacy Notice and Data Processing Addendum. Questions may be sent to hi@supamail.dev.