Skip to main content
Back to home

Subprocessors

Last updated: 2026-08-24

To run Mezbano we rely on a small number of third-party providers (“subprocessors”) that process data on our behalf. The table includes fixed provider services and the deployment-selected destination categories present in the code.

Optional providers operate only when their integration is configured. They process data only when the related feature is used.

Provider brand names do not establish the contracting legal entity or all processing locations; the deployment operator must verify those details against the live account and applicable data processing agreement. The two operator-selected rows disclose optional capabilities whose provider identity cannot be derived from this repository. Before either is enabled, the operator must publish its legal name, region, purpose, terms, and activation status. A generic row is not sufficient as the final contractual disclosure.

Mezbano subprocessors and the data they process
Subprocessor Purpose Data processed Region
Cloudflare Cloud hosting, application runtime, database, file storage, and optional Turnstile abuse protection Application data entered into the service, uploaded files, and request/security metadata; a Turnstile response token and visitor IP address are sent for challenge verification when that integration is enabled Global network; contracting entity and any data-localization configuration are deployment-specific
Resend (Plus Five Five, Inc.) Transactional email delivery when email is configured Recipient email address and message content for account and workspace emails (invitations, password resets, and notifications) Provider account and sending-region configuration are deployment-specific and must be verified by the operator
Stripe Subscription checkout, payment management, invoicing, and billing reconciliation when Stripe is configured Billing contact details, Stripe customer and subscription references, and payment details entered directly in Stripe-hosted Checkout or the Customer Portal. Mezbano does not store full card details. Global; contracting entity and account configuration are customer-specific
Operator-selected offsite storage provider Optional cross-provider recovery storage when the offsite S3-compatible integration is completely configured Completed database backup generations, archived audit records, and claimed attachment bytes and recovery metadata Deployment-specific; must be published before activation
Operator-selected incident alert receiver Optional operational incident notification when an alert webhook endpoint is configured Service name, deployment environment, severity, generic error code and class, correlation request ID, parameterized route ID, HTTP status when available, and timestamp. Raw error messages, stack traces, causes, provider bodies, interpolated paths, user IDs, and email fields are not sent Deployment-specific; must be published before activation

Customer-directed identity providers

A workspace can configure its own OIDC or SAML identity provider for single sign-on. That provider receives the identity and authentication-flow data needed to complete the customer’s directed sign-in. Because Mezbano does not select that provider, it is not listed above as a Mezbano-appointed subprocessor; the customer must assess its own provider relationship.

Changes to this list

We will update this page before a new fixed or deployment-selected subprocessor begins processing customer data and give reasonable advance notice — at least 30 days where practical and subject to the applicable customer agreement — so customers can review the change. Questions? Email support@mezbano.com.

See also our security posture and privacy policy.