Skip to main content

Subprocessors

Last updated: 6 June 2026

Shower uses the third-party companies listed below (“Subprocessors”) to help deliver our service. Each Subprocessor is contractually bound to data protection obligations consistent with our Data Processing Agreement.

For details about how we secure customer data, see our Security page. This page is the single source of truth for the subprocessor list — our Privacy Policy and DPA reference it directly rather than maintaining a separate copy. The canonical machine-readable URL is https://shower.dev/subprocessors.

SubprocessorPurposeRegionPrivacy Policy
VercelApplication hosting and edge networkUnited States / Global edgeView
SupabaseAuthentication and PostgreSQL databaseEUView
CloudflareCDN, DNS, and R2 object storageGlobal edge (R2 project storage located in Western Europe)View
AnthropicAI code generation (Claude API)United StatesView
Google LLCGemini AI inference and analytics measurement where enabledUnited States / GlobalView
OpenAIAI review, fallback inference, and Codex-assisted workflowsUnited StatesView
StripePayment processing and subscription billingEU / GlobalView
SentryError monitoring and crash reportingEUView
PostHogProduct analytics and session replayEUView
RudderStackEvent pipeline and marketing attribution routingUnited StatesView
ModalSandboxed code execution containersNot region-pinned — builds observed in the EU and the United StatesView
Customer.ioLifecycle and transactional emailEU by default (Track API: track-eu.customer.io) — account region not independently verifiedView
ResendTransactional email delivery and customer-authorized email connectorUnited States (sending region may vary by domain)View
UpstashRedis cache, rate limiting, semantic cache of prompts and AI responses, and customer memory recallEU (Redis and Vector: AWS eu-west-1, Ireland)View
AxiomApplication logging and observabilityUnited StatesView
Temporal CloudWorkflow orchestration for sandbox lifecycleEU (eu-central-1)View
BraintrustLLM observability for chat generationsNot verified — our account region has not been readView
Google Cloud RunSandbox orchestration — runs customer-generated code and environment variablesEU (europe-west4 per service URL — service config not yet verified)View
PhotoRoomImage background removal and compositingGlobal — not region-pinnedView
PexelsStock photo search and preview thumbnailsGlobal — not region-pinned (vendor policy names the United States, European Union, United Kingdom, Australia, Singapore, Philippines and New Zealand)View

International Transfers

Where a Subprocessor is located outside the European Economic Area, transfers are protected by the European Commission's Standard Contractual Clauses and supplementary measures where applicable. Personal data sent to AI providers (Anthropic, Google, OpenAI) is transmitted via API integrations under agreements that prohibit training on customer data.

Updates

We update this list whenever we add or remove a Subprocessor. Customers with an active Data Processing Agreement receive at least 30 days' advance notice of new Subprocessors via email to the technical contact on file. To subscribe to changes, email legal@smoothly.dev.

Questions

For questions about our Subprocessors or data processing arrangements, contact legal@smoothly.dev.