Subprocessors
Last updated: 6 June 2026
Shower uses the third-party companies listed below (“Subprocessors”) to help deliver our service. Each Subprocessor is contractually bound to data protection obligations consistent with our Data Processing Agreement.
For details about how we secure customer data, see our Security page. This page is the single source of truth for the subprocessor list — our Privacy Policy and DPA reference it directly rather than maintaining a separate copy. The canonical machine-readable URL is https://shower.dev/subprocessors.
| Subprocessor | Purpose | Region | Privacy Policy |
|---|---|---|---|
| Vercel | Application hosting and edge network | United States / Global edge | View |
| Supabase | Authentication and PostgreSQL database | EU | View |
| Cloudflare | CDN, DNS, and R2 object storage | Global edge (R2 project storage located in Western Europe) | View |
| Anthropic | AI code generation (Claude API) | United States | View |
| Google LLC | Gemini AI inference and analytics measurement where enabled | United States / Global | View |
| OpenAI | AI review, fallback inference, and Codex-assisted workflows | United States | View |
| Stripe | Payment processing and subscription billing | EU / Global | View |
| Sentry | Error monitoring and crash reporting | EU | View |
| PostHog | Product analytics and session replay | EU | View |
| RudderStack | Event pipeline and marketing attribution routing | United States | View |
| Modal | Sandboxed code execution containers | Not region-pinned — builds observed in the EU and the United States | View |
| Customer.io | Lifecycle and transactional email | EU by default (Track API: track-eu.customer.io) — account region not independently verified | View |
| Resend | Transactional email delivery and customer-authorized email connector | United States (sending region may vary by domain) | View |
| Upstash | Redis cache, rate limiting, semantic cache of prompts and AI responses, and customer memory recall | EU (Redis and Vector: AWS eu-west-1, Ireland) | View |
| Axiom | Application logging and observability | United States | View |
| Temporal Cloud | Workflow orchestration for sandbox lifecycle | EU (eu-central-1) | View |
| Braintrust | LLM observability for chat generations | Not verified — our account region has not been read | View |
| Google Cloud Run | Sandbox orchestration — runs customer-generated code and environment variables | EU (europe-west4 per service URL — service config not yet verified) | View |
| PhotoRoom | Image background removal and compositing | Global — not region-pinned | View |
| Pexels | Stock photo search and preview thumbnails | Global — not region-pinned (vendor policy names the United States, European Union, United Kingdom, Australia, Singapore, Philippines and New Zealand) | View |
International Transfers
Where a Subprocessor is located outside the European Economic Area, transfers are protected by the European Commission's Standard Contractual Clauses and supplementary measures where applicable. Personal data sent to AI providers (Anthropic, Google, OpenAI) is transmitted via API integrations under agreements that prohibit training on customer data.
Updates
We update this list whenever we add or remove a Subprocessor. Customers with an active Data Processing Agreement receive at least 30 days' advance notice of new Subprocessors via email to the technical contact on file. To subscribe to changes, email legal@smoothly.dev.
Questions
For questions about our Subprocessors or data processing arrangements, contact legal@smoothly.dev.