Subprocessors
Effective September 4, 2026 · last updated September 4, 2026
Every company that touches PaddleLens data, what each one gets, and where it is. If you are a club deciding whether to put your roster here, this is the page to read alongside the Privacy Policy.
Optional Sentry error monitoring is a subprocessor service: it receives only the minimized diagnostic fields listed in its row, in the United States, with no exception message or request address, and is retained for no more than 90 days. The last three rows below are not subprocessors of club data — Google Analytics, PostHog, and our advertising measurement partner. None receives a roster, an athlete, a report, a photo or a message. Google counts public visits and major conversions under a server-generated pseudonymous code; PostHog counts product workflows under a different pseudonymous account code. Meta sees eligible public visits and, for a consenting adult, the successful-signup fact with connection and Meta browser/click IDs — no PaddleLens identity. They are listed anyway, because a page that claims to name every company that touches anything should not have a footnote.
They get a promise of their own, narrower and easier to check: we name an advertising or measurement partner on this page before it runs, never after, and every one of them inherits the same two limits — the person's own consent, and the closed list of what may be sent, which is written out in Privacy §6 and cannot be widened without asking again. If your club's procurement review needs a fixed notice period in writing, say so at info@paddlelens.com and we will agree one with you in your data processing agreement.
Who we use
| Company | What it does | What it receives | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosting — the server the application runs on | Everything, as it passes through the server. What stays stored there: uploaded video while it is being analyzed, annotated frames, Community media, and the encrypted local backup archives. The database records themselves live with Supabase — the next row. | Falkenstein, Germany |
| Supabase, Inc. | Managed hosting of the primary database (PostgreSQL) | The database contents: accounts, athlete data, measurements, reports, Community text, and the operational records around them. Not video, not media files, not annotated frames — those stay on the Hetzner server above. | Frankfurt, Germany — the data resides there; Supabase, Inc. is a US company |
| Anthropic PBC | Writes the technique report and the crew plan | Text only. For a report: measurements, scores, the paddler's first name, coach notes. For a crew plan: each selected athlete's name, height, weight, paddling side, trial results, scores and notes. Never video, never images. | United States |
| Stripe, Inc. | Processes PaddleLens purchases and payments made directly to connected clubs; verifies and pays out connected account holders | Name, email, connected-account identity and business details, bank details and the card details entered directly with Stripe. We never see full card or bank numbers, or Stripe's identity documents. | United States |
| Brevo (Sendinblue) | Sends transactional email | Your email address and the contents of the message: invites, receipts, password resets, service notices | France |
| Google LLC — Identity Services | Authenticates optional Google sign-in and confirms which Google account you chose | A stable Google account identifier and your verified email and display name, plus the ordinary IP, browser and device information Google receives during sign-in. Never your PaddleLens password, phone number, birth date, club or athlete data. PaddleLens keeps no Google access or refresh token. | United States and elsewhere |
| Twilio Inc. Only reaches you if you added a mobile number | Sends text messages, receives coded RSVP replies, and sends the one-time code that confirms a number is yours | Your mobile number and the message itself — a club name, session label, date, time and RSVP code, or whatever a coach typed. If you reply, Twilio also receives the reply text, time and provider message ID and passes them to us. Never a report, a score, a measurement, an image or a link. Nobody who has not added a number is known to Twilio at all. | United States |
| WeatherAPI.com (Weather API Ltd) | Supplies the forecast shown against a scheduled session | The map coordinates of a club's training venue — a lake, a river or a town a coach chose from a search box — and nothing else. No name, no email, no account identifier, no athlete data, and nothing about any individual person. It cannot tell one member of a club from another, or that anyone in particular is going. | United Kingdom |
| Sentry (Functional Software, Inc.) | Optionally receives backend error reports so we can diagnose crashes and failed requests | Only when configured: event time and level, application release, exception type, a stack trace limited to file, function and line/column numbers, and the request method. Exception messages, request addresses, local variables, cookies, headers, IP addresses, user context, breadcrumbs and arbitrary extras are not sent. Performance tracing is off; retained for no more than 90 days. | United States — US ingest region only |
| Google LLC — Analytics 4 | Counts public-site visits and major conversions | Only if you accepted analytics cookies: normalized public route templates, device type, approximate region, and the successful signup or checkout-start events. For a signed-in account, Google receives a stable server-generated pseudonymous code in its reserved User-ID field — never the database account ID, name or email. See Privacy §9. | United States and elsewhere |
| PostHog, Inc. — US cloud | Counts which pages and app features get used | Only if you accepted analytics cookies, and never any club or athlete data: normalized pages and screens, the product moments listed in Privacy §2, device and browser type — under a pseudonymous account code for signed-in members, never a name or email. Session replay and autocapture are off. See Privacy §9. | United States |
| Meta Platforms — Meta Pixel Meta Platforms Ireland Ltd for visitors in the EU/EEA; Meta Platforms, Inc. elsewhere | Measures whether the ads we buy on Facebook and Instagram bring anyone here | Only if you accepted advertising cookies, and only on eligible public URLs: that a browser opened one, plus its IP, browser type, Meta browser ID and any Meta ad-click ID. If you are over 18, a successful account creation may also send that signup fact with a random event ID, request IP and Meta's browser/ad-click IDs so browser and server copies count once; the server does not forward the raw User-Agent header. No name, email, phone, birth date, PaddleLens account ID, purchase, club or athlete data, and never a private account route. Unlike everyone else on this list Meta is not our processor: for what the pixel collects we and Meta are joint controllers under Meta's Controller Addendum, and Meta also uses it for its own advertising purposes. Privacy §6 sets out which of us answers for what. | United States and elsewhere |
Google Drive, and why it isn't on that list
If your club switches on the club photo drop, photos and video go into a folder in your club manager's own Google account — under your club's relationship with Google, not ours. We relay the files and keep no copy, and our access is scoped so we can only reach the folder we created for your club. So Google is your club's processor for those photos rather than our subprocessor, and only your club manager can delete them. Privacy §3 explains this properly, and everyone is shown it before their first upload.
Push notifications, and why your browser picks the company
If you turn notifications on, they reach your device through the push relay built into your browser — Google's for Chrome, Mozilla's for Firefox, Apple's for Safari, Microsoft's for Edge. We don't choose that company and can't replace it; your browser does. What it sees is an encrypted payload it cannot read — each message is enciphered to keys held only by your browser — plus the delivery address your browser assigned to itself. Turning notifications off deletes that address from our server, and deleting your account does too.
What we don't do
- No data brokers, no analytics beyond the two rows above, and no advertising network beyond the one named above — which measures our own ads, only with your consent, and never sees a signed-in screen or anything on one.
- Nothing here trains an AI model on your data — not ours, not Anthropic's.
- We have never sold personal information for money. Since August 2026 we do share, in the California sense, if you accept advertising cookies: eligible public-page visits and, for adults, the successful-signup fact. Privacy §6 explains it and Cookie settings turns it off.
- No PaddleLens identity, club or athlete data ever reaches an advertising platform — no name, email, account ID, roster, profile, measurement, report, frame, photo, message, phone number or birth date; not raw, hashed, as a customer list, or for a custom or lookalike audience. A consenting adult signup carries only the fact it succeeded, a deduplication ID, connection data and Meta's own browser/click IDs. Purchases are not reported. Widening that closed list requires a new notice and acceptance.
Changes
This list was last changed on September 4, 2026. The date moves when the table moves, not when we tidy the wording, so you can trust it as a change log. Clubs with a data processing agreement in place also get the notice by email.
Questions, or a request about your data? Write to info@paddlelens.com.