PaperJSX Subprocessors
Effective: May 10, 2026
Summary
This page lists third-party providers that help operate PaperJSX. The DPA authorizes use of subprocessors for Customer Personal Data. We give at least 30 days’ notice before adding or replacing a subprocessor that processes Customer Personal Data, with a 14-day objection window for reasonable data-protection objections.
Active subprocessors
| Provider | Purpose | Data categories | Location | Role |
|---|---|---|---|---|
| Vercel Inc. | Website, documentation, application hosting, serverless or edge functions, license portal or hosted features | Account Data, Service Data, request logs, and Customer Personal Data if submitted to hosted features | United States and global edge | Processor/subprocessor |
| Supabase Inc. | Database, authentication, storage, account and entitlement records | Account Data, license records, Service Data, and Customer Personal Data if stored in hosted features | United States unless configured otherwise | Processor/subprocessor |
| Cloudflare Inc. | DNS, CDN, DDoS protection, bot management, edge security | IP addresses, request headers, security logs, traffic metadata | Global | Processor/subprocessor |
| Resend Inc. | Transactional email, account notices, license notices, support notifications | Email address, name, organization, message metadata, email content | United States | Processor/subprocessor |
| Functional Software Inc. (Sentry) | Error monitoring, diagnostics, performance monitoring | Error logs, stack traces, device/browser metadata, IP address, diagnostic data, limited user identifiers | United States unless configured otherwise | Processor/subprocessor |
| PostHog Inc. | Product analytics for website, documentation, account portal, or hosted features if enabled | Pseudonymous usage events, device/browser metadata, pages viewed, feature events | EU or United States depending on active project configuration | Processor/subprocessor |
Optional subprocessors
These providers are used only if the relevant feature or support channel is enabled.
| Provider | Purpose | Data categories | Location | Role |
|---|---|---|---|---|
| Channel Corp. (Channel.io) | Support chat, if enabled | Contact details, chat messages, support metadata, browser/device data | Republic of Korea and other locations described by provider | Processor/subprocessor |
| Customer-selected storage, CI/CD, registry, or integration provider | Enterprise or customer-configured integration | Data configured by Customer | Customer-selected | Customer-controlled provider |
Independent controllers and platform providers
The following providers are not treated as subprocessors for Customer Personal Data under our DPA by default. They may process data under their own terms, as independent controllers, independent processors selected by you, or platform providers.
| Provider | Purpose | Notes |
|---|---|---|
| Paddle.com Market Limited and affiliates | Merchant of record, checkout, invoices, taxes, payments, statutory buyer rights, refunds | Paddle is an independent controller for payment-transaction data. We receive transaction and entitlement metadata but not full card or bank details. |
| GitHub, Inc. | Repository hosting, issue tracking, pull requests, releases, Actions, community contributions | GitHub processes your GitHub account and contribution data under GitHub’s own terms and privacy notice. |
| npm, Inc. / GitHub | Public package registry and package downloads | npm processes registry access and account data under npm/GitHub terms. Public open-source package access is governed by the applicable package license and npm terms. |
| Customer-controlled CI/CD, package registry, storage, or deployment provider | Customer uses PaperJSX in its own environment | Customer controls these providers and is responsible for their terms, permissions, and data handling. |
Change notices
We will update this page when we add or replace subprocessors. Customers with an executed DPA or paid account may request email notices by contacting privacy@paperjsx.com.
If you object to a new subprocessor on reasonable data-protection grounds within 14 days after notice, we will work with you to address the concern. If we cannot resolve it, you may terminate the affected hosted feature or service and receive a prorated refund for the unused prepaid portion of that affected service.
Contact
Privacy and subprocessor questions: privacy@paperjsx.com