Sign inStart free

Legal

Subprocessor Register

Last updated: August 6, 2026

A current, plain-language register of the providers that help ReTestimonial host, secure, deliver, analyze, and extend the service.

This page is provided for transparency and is not legal advice. If you have questions about your obligations, please consult your own counsel.

1. How to read this register

In shortThe register names service providers that may process customer data for ReTestimonial and states when optional providers are used.

ReTestimonial uses the providers below to operate the service or to perform a feature a workspace customer chooses. Not every provider receives every category of data, and conditional providers are invoked only for the stated workflow.

This register describes product use and data categories. Customer-specific processing instructions, confidentiality, security, deletion, audit, transfer, and change-notice terms are governed by the applicable agreement or Data Processing Agreement. Contact privacy@retestimonial.com for those terms or for current transfer-location details relevant to your account.

2. Core infrastructure

In shortProviders used to host, secure, store, process, and deliver the service.

  • Clerk — Authentication, account security, and workspace identity management. Data may include account identifiers, profile details, authentication events, and session data. Used for ReTestimonial account access.
  • Vercel — Application hosting, server execution, and delivery. Data may include request data, application content processed by a request, and operational logs. Used for the hosted ReTestimonial application and APIs.
  • Supabase — Managed PostgreSQL database infrastructure. Data may include account, workspace, testimonial, configuration, and product-event records. Used for primary application data storage.
  • Cloudflare — Object storage, edge delivery, caching, security, and worker execution. Data may include uploaded files, generated assets, request data, cache keys, and operational metadata. Used for media/assets and selected public delivery surfaces.
  • Upstash — Distributed rate limiting and short-lived abuse-prevention counters. Data may include pseudonymous or salted actor keys, project keys, counters, and expiry times. Used when distributed rate limiting is configured.
  • Mux — Video upload, hosting, streaming, playback analytics, and transcripts. Data may include video files, captions/transcripts, playback events, and related request metadata. Used when video features are enabled.
  • Amazon Web Services — Serverless rendering of social-video exports. Data may include selected testimonial content, source media, render configuration, and generated video. Used when a social-video render is requested.

3. Communications, billing, and rewards

In shortProviders used only when the related communication or commercial workflow runs.

  • Resend — Transactional and customer-configured email delivery. Data may include recipient address, sender details, message content, and delivery events. Used when ReTestimonial sends email.
  • Stripe — Subscription, credit, invoice, payment, refund, and billing-management processing. Data may include account and billing details, transaction records, and processor-hosted payment details. Used for provider-hosted payment entry and billing operations; ReTestimonial does not store full card details.
  • Tremendous — Gift-card reward fulfillment. Data may include reward recipient details, reward selection, and fulfillment status. Used only when a customer enables and issues rewards.

4. Observability and product analytics

In shortProviders that help diagnose errors and understand authenticated product usage.

  • Sentry — Application error reporting and operational diagnosis. Data may include error context, stack traces, account correlation, request metadata, and diagnostic events. Used when error monitoring is configured; sensitive request bodies and secrets are not intended inputs.
  • PostHog — Product analytics for authenticated ReTestimonial usage. Data may include account identifier, plan/workspace context, page or feature events, and device/request metadata. Used when product analytics is configured.

5. Optional AI, OCR, and imports

In shortProviders invoked only for customer-selected processing or import workflows.

  • Anthropic — Customer-requested AI analysis, writing, extraction, and OCR features. Data may include the testimonial, document, image, or prompt content selected for the requested operation. Used only for features routed to Anthropic.
  • OpenAI — Fallback or customer-requested AI and OCR processing. Data may include the testimonial, document, image, or prompt content selected for the requested operation. Used only for features routed to OpenAI.
  • Apify — Customer-requested review and social-content imports. Data may include public business/profile identifiers, source URLs, and imported public review or post content. Used only when a supported import invokes Apify.
  • Bright Data — Customer-requested review-platform discovery and imports. Data may include public business identifiers, source URLs, and imported public review content. Used only when a supported import invokes Bright Data.
  • Outscraper — Customer-requested Capterra and configured Product Hunt review imports. Data may include public product identifiers, source URLs, and imported public review content. Used only when a supported import invokes Outscraper.
  • Google — Customer-requested Google account connection, business discovery, and review imports. Data may include OAuth/account identifiers, public business/location data, search input, and imported review content. Used only when a customer connects or searches a supported Google integration.

6. Updates and questions

In shortThe publication date identifies the current register; contract-specific change notice follows the applicable agreement.

We update this register when our provider set or a provider's material role changes. A customer's right to advance notice, objection, or termination is determined by its applicable agreement or Data Processing Agreement; this page does not replace those terms.

Questions about a provider, a feature-specific data flow, or a transfer mechanism can be sent to privacy@retestimonial.com.

Questions? Contact privacy@retestimonial.com. View our Privacy Policy.