Subprocessors
A residency claim is only as good as the list behind it. Every third party that touches customer data and what it sees, complete rather than representative.
The list
Every third party that processes Mercleo customer data, and what each one sees. It is complete rather than representative: if a provider touches customer data, it is on this list, and when a provider is added or removed this page changes with it.
- Supabase: hosted databases and authentication infrastructure. Holds customer records, including the names and contact details your organization manages.
- Vercel: application hosting. Processes every request, including IP addresses and request logs.
- Cloudflare: file storage. Holds files your organization uploads, such as documents and applicant résumés.
- Clerk: authentication for certain products. Sees names, email addresses, and sign-in metadata.
- Stripe: payments. Sees billing contacts and payment details; card data goes to Stripe directly and never reaches Mercleo.
- Resend: email delivery. Sees recipient addresses and message content for mail sent through the Services.
- Twilio: SMS and phone verification. Sees phone numbers and message content.
- PostHog: product analytics. Sees usage events and account identifiers.
- Sentry: error reporting. Exception payloads can incidentally contain personal data, which is why it is on this list.
- Upstash: rate limiting. Sees keys derived from request metadata.
- Sanity: help-centre content. Holds our published documentation, not customer records; listed for completeness.
- OpenAI and Anthropic: model providers behind AI-assisted features. See the content a feature sends when you use it, described at /trust/ai.
- Google: maps and address lookups in the products, and advertising measurement for our own marketing.
What is not on this page yet
Hosting region and the data-processing terms we hold with each provider, per row. Those claims go in as they are verified against the actual contracts and dashboards rather than assumed from provider marketing. Several of these providers process data in the United States; the jurisdictional picture is set out plainly at /trust/data-residency.
When the list changes
We update this page when a provider is added or removed. If your organization needs contractual notice of subprocessor changes, or a route to object to one, raise it when you ask about data-processing terms. Those commitments belong in a signed agreement, and we would rather make them there than imply them here.
If a provider on this list is a problem
Tell us before you buy. Some obligations rule out specific providers or countries, and we would rather have that conversation early than at renewal.
The rest of the trust centre. Everything else a reviewer asks for.
- Where your data livesWhere the infrastructure runs, who runs it, and whose law can reach the data.
- SecurityTenant isolation, staff access, and the supply chain.
- Privacy and your rightsThe processing agreement, retention, export, deletion and breach notice.
- AI and your dataWhat uses a model, what gets sent, and whether it trains on anything.
- AccessibilityWhat has actually been checked, what has not been assessed, and how to report a barrier.
- ComplianceWhat we hold, what we are working towards, and what we do not have.
- Report a vulnerabilityHow to reach us, what is in scope, and what happens after you do.