Subprocessors
Checked against the code: 13 September 2026
Every third party that processes data for us, what it does, what it can see and where it runs. The list is compiled from the code rather than from memory, so a call added to a new provider and a row added here are the same change. The policy this supports is the privacy policy.
| Processor | What it does for us | What it can see | Where it processes |
|---|---|---|---|
| Stripe | Card payments, subscriptions and prepaid credit top-ups. | Your email, the amount and the subscription state. Card numbers go to Stripe directly and never reach us. | Europe and the United States |
| Resend | Transactional email: magic-link verification and sign-in links, contact-form delivery, and quota threshold alerts. | The recipient address, the subject and the body of that one message. | United States |
| Supabase | The database behind our own sales CRM, which records contact-form enquiries and support tickets. | The name, email address, message, products selected and first-touch attribution you submit on the contact form. | Stated on request for a review |
| OpenAI | The voice Copilot demo only: it mints the realtime session and renders guidance phrases to speech. | What you say into the Copilot demo while it is running, and the guidance sentences it speaks back. Nothing else on the site or the API touches it. | United States |
| analytics.unified.studio | The Plausible analytics instance that serves our website analytics script and receives its events. | Page views and the events named in the privacy policy. Cookieless, with no persistent identifier and nothing stored on your device. | Europe (served from Hetzner infrastructure) |
| PostHog | Cookieless product analytics, for example how many visitors complete signup. | The same page and event data, held in memory for the visit only. | European Union (eu.i.posthog.com) |
| Hetzner | The servers the API gateway and its data run on. | Everything the hosted API handles, as the infrastructure under it. | European Union |
| Vercel | Hosting for this website, its API routes and the signup proxy. | Requests to this website, including the request metadata any host sees. | United States company, website served from its global edge |
| Sentry | Error and performance monitoring for this website. | A crash report carrying the page, the browser and the originating IP address. | United States |
Transfers, changes and self-hosting
Where a processor is outside the United Kingdom we rely on the transfer terms in that provider's own data processing agreement. Our own data processing agreement, with a United Kingdom international data transfer addendum, is being drafted; until it is published, ask us and we will send you the provider terms we rely on for your review.
This list is part of the privacy policy's promise to keep the processor list current. We will update this page before a new processor starts handling personal data for us, and we will tell an affected customer by email where their agreement requires it. If a change matters to you and you want notice in writing, say so and we will add you to that list.
Self-hosted deployments are outside this list entirely. A self-hosted MapMap stack reports nothing to us and sends nothing to any processor here; the operator of that deployment chooses its own.
The Copilot demo, specifically
The voice Copilot is the one surface on this site that sends anything to a model provider, and it only does so while you are using it. Running the Copilot app on your own infrastructure still calls OpenAI unless you supply your own key and endpoint, so a self-hosted Copilot is not automatically an OpenAI-free one.
Related: the privacy policy, what we collect at the telemetry disclosure, and the imagery notice at /legal/roadside-imagery. A question from a data protection officer reaches a person at hello@mapmap.ai.