Sub-processors
Last updated: August 14, 2026
01About This List
This is the complete list of third parties that receive data from CueSync. It is derived from what the software actually does — every entry exists because a code path in the product sends something to that provider — rather than from a summary written once and left behind.
It supports the sub-processor clause of our Data Processing Agreement, and it covers more than that clause strictly requires: the advertising and sign-in providers below are not all processors of Studio content, but a reader trying to understand where their data goes should not have to work out which legal category each one falls into.
Retention of each category of data is published separately in the Data Retention Schedule, and the purposes we process for are in the Privacy Policy.
02Infrastructure & Core Services
These providers store or serve the data the service is made of. If you are assessing where your Studio content lives, this is the section that matters.
| Sub-processor | Purpose | Data categories | Location / region | Transfer mechanism |
|---|---|---|---|---|
| Paddle | Merchant of Record. Sells the licence, takes payment, issues invoices, handles sales tax, and runs the customer billing portal. Paddle is the seller of record and an independent controller for payment data, not merely our processor — it is listed here so the list is complete. | Name, email address, billing address and country, payment card details (which are collected by Paddle and never reach us), subscription and transaction records. | To be confirmed | To be confirmed |
| Cloudflare | Three distinct roles: Turnstile bot protection on public forms; DNS and CDN in front of the website; and R2 object storage, which holds every file uploaded to Studio — audio masters, PDFs, images, specs and the computed waveform data. | IP address and browser signals (Turnstile and CDN); the full content of Studio uploads and the derived waveform data (R2). | Global edge network. The R2 bucket's jurisdiction is not pinned in configuration, so the storage region is to be confirmed. | To be confirmed |
| Vercel | Hosting and edge delivery for the website front end, including its request and function logs. | Request metadata — URL, IP address, user agent, timing — and anything carried in a request to a hosted route. | Frankfurt, Germany (the deployment is pinned to the fra1 region). | To be confirmed |
| Hetzner | The virtual server that runs the API and the PostgreSQL database behind every account and Studio project — which also holds the short-lived key-value tables used for sessions and rate limiting, there being no separate cache service — plus the off-site encrypted database backups. | Everything the service stores: accounts, subscriptions, licence keys, devices, Studio projects and membership, audit logs, and server request logs. | The primary server's data centre is to be confirmed. Off-site backups are written to a Hetzner Storage Box, also to be confirmed. | To be confirmed |
| Sentry | Error and performance monitoring for the website, the API and the desktop application. Events pass through a redaction filter in our own code before they are sent, which strips credentials, tokens and licence keys. | Error events with stack traces and request context, including IP address, and — from the desktop app — crash and diagnostic context. | To be confirmed | To be confirmed |
03Support, Email & CRM
These providers carry what a person writes to us and what we send back. The chat path is the one worth reading twice, because a message typed into the widget goes from the visitor's browser to ClientFlow directly and from there to a language-model provider — see the AI Use Statement.
| Sub-processor | Purpose | Data categories | Location / region | Transfer mechanism |
|---|---|---|---|---|
| Resend | Transactional email delivery: account verification, magic sign-in links, licence key delivery, billing notices and security alerts. | Recipient email address and the content of the message sent to them. | To be confirmed | To be confirmed |
| ClientFlow | Support chat, contact and support tickets, and the customer-relationship record. The chat widget talks to ClientFlow directly from the visitor's browser; contact and ticket forms are forwarded server-to-server after our own validation. | Name, email address, message and chat content, IP address, the campaign details of the visit (UTM tags, click IDs, landing page, referrer) and, on a purchase, the edition, billing cycle and Paddle subscription reference. No payment card details. | To be confirmed | To be confirmed |
| ClientFlow's LLM provider (downstream) | ClientFlow sends chat messages to a third-party large-language-model provider to compose a reply. That provider is ClientFlow's sub-processor, not ours directly, and it is listed because the data originates with our visitors. | The text of a chat message, after ClientFlow removes recognisable personal details such as phone numbers, email addresses and card-like number sequences. | To be confirmed | To be confirmed |
04Analytics, Advertising & Sign-In
Everything in this section other than the sign-in providers is loaded only after the visitor accepts the matching cookie category, and the advertising rows are what the Do Not Sell or Sharepage is about: under California law, disclosing an identifier to an advertising platform for cross-context behavioural advertising counts as a "sale" or "share" even though no money changes hands.
| Sub-processor | Purpose | Data categories | Location / region | Transfer mechanism |
|---|---|---|---|---|
| PostHog | Product analytics and session replay on the website, loaded only after analytics consent is given and never when the browser asserts Global Privacy Control or Do Not Track. Replay masks all form inputs and any element marked sensitive. | Page views, interactions, device and browser information, IP address, and replayed session activity with inputs masked. | United States (the us.i.posthog.com ingest region). | To be confirmed |
| Three roles: Google Analytics 4 (measurement, consent-gated); Google Ads, including Enhanced Conversions and a server-side conversion fired from the purchase webhook; and Google as an OAuth sign-in provider, which is not consent-gated because it only runs when someone chooses to sign in with it. | Page views and events, click IDs (gclid, gbraid, wbraid), a hashed email address on purchase, purchase value and currency, buyer country; for sign-in, the account identifier and email address returned by Google. | Global, primarily United States. | To be confirmed | |
| Meta Platforms | Meta Pixel on the site plus a server-side Conversions API event on purchase, for conversion measurement and remarketing on Facebook and Instagram. Consent-gated. | Page views, click IDs (fbclid), a hashed email address on purchase, purchase value and currency, buyer country. | Global, primarily United States. | To be confirmed |
| Insight Tag on the site plus a server-side Conversions API event on purchase, for conversion measurement and Matched Audiences retargeting. Consent-gated. | Page views and interactions, a hashed email address on purchase, purchase value and currency. | Global, primarily United States. | To be confirmed | |
| Microsoft (Bing Ads) | The Bing UET tag for conversion measurement on Microsoft Advertising. Consent-gated, with the consent signal pushed to the tag explicitly rather than relying on region defaults. Client-side only — there is no server-side fire. | Page views and conversion events, IP address, browser information. | Global, primarily United States. | To be confirmed |
| X (Twitter) | The X pixel plus a server-side Conversions API event on purchase, for conversion measurement on X Ads. Consent-gated. | Page views, a hashed email address on purchase, purchase value and currency. | Global, primarily United States. | To be confirmed |
| Apple | Sign in with Apple, as an OAuth identity provider. Runs only when someone chooses to sign in with Apple; it is not an advertising or measurement integration. | The account identifier and email address (or Apple's private relay address) returned by Apple at sign-in. | Global, primarily United States. | To be confirmed |
05Cells Marked “To Be Confirmed”
Several cells above read "To be confirmed". That is a deliberate answer, not an oversight, and it means what it says: we can prove from our own code that the provider receives the data, and we have not yet verified the region it lands in or the contractual mechanism covering the transfer.
Two things drive most of them. The storage region of a provider is a dashboard setting rather than something visible in the application, so it has to be read off each provider's console and recorded. And the transfer analysis itself depends on where CueSync's controlling entity is established, which is currently recorded as: to be confirmed — write to contact@cuesync.live. Until that is settled, naming a specific mechanism for each provider would be asserting a conclusion whose premise is missing.
If you need a specific cell answered for your own compliance review, ask at privacy@cuesync.live and we will answer it directly and then publish the answer here.
06Change Notification
We give notice before a new or replacement sub-processor begins processing personal data, not after it has started. Notice is given in two places at the same time:
- This page is updated, and the "Last updated" date at the top changes with it
- An email goes to everyone subscribed to sub-processor notifications
Subscribing to notifications
Email privacy@cuesync.live with the subject "Subscribe to sub-processor notifications". Say which address should receive them — for most organisations that is a shared privacy or compliance mailbox rather than an individual. Unsubscribe the same way at any time.
This list is used for nothing else. It is not a marketing list and it is not merged into one.
07Objecting to a Sub-processor
A customer under our Data Processing Agreement may object to a newly announced sub-processor on reasonable data-protection grounds within 30 days of the notice. We will work with you in good faith to find a way forward — a configuration that avoids that provider, or an alternative. If there is none, you may terminate the affected part of the service and we will refund fees paid for the period after termination.
08Contact
Questions about this list, or a request to verify a specific cell: privacy@cuesync.live.