Sub-processors
Last updated: 17 May 2026
Rivestack is operated by OPSAFLOW SAS, a company incorporated in France (SIREN 990 431 215, 60 rue François 1er, 75008 Paris). To deliver our managed PostgreSQL service we rely on a small number of carefully selected third-party providers — our "sub-processors" — who may process customer personal data on our behalf.
This page lists every sub-processor we currently use, what they do, and where they process data. It is part of our Data Processing Agreement (DPA) and is referenced from Annex C of that document.
How we notify you of changes
We will update this page whenever we add or replace a sub-processor. If you want to be notified by email before changes take effect, please email legal@rivestack.io with the subject "Subscribe: sub-processor updates" and we'll add you to the notification list. New or replacement sub-processors are announced at least 30 days before they begin processing customer data, giving you time to object as set out in our DPA.
Current sub-processors
| # | Sub-processor | Entity & location | Purpose | Data processed |
|---|---|---|---|---|
| 1 | Hetzner Online GmbH | Germany (EEA) | Core compute and storage infrastructure for customer PostgreSQL clusters and the Rivestack control plane | All data customers store in their databases; account metadata |
| 2 | DigitalOcean, LLC (Spaces) | Frankfurt, Germany (EEA) | Encrypted object storage for database backups | Encrypted backup files |
| 3 | Okta, Inc. (Auth0) | Ireland / United States | Authentication for the Rivestack console (login, MFA, SSO) | Account identifiers, email addresses, IP addresses, login metadata |
| 4 | Cloudflare, Inc. | Global edge network; EU PoPs serve EU traffic | CDN, DDoS protection, Web Application Firewall | IP addresses, request headers and metadata |
| 5 | Lemon Squeezy LLC | United States | Subscription management, payments, invoicing, tax | Billing name, email, address, payment-method metadata, transaction history |
| 6 | Resend, Inc. | United States / EU | Transactional email (account, billing, security notifications) | Email address, name, transactional email content |
| 7 | Loops Inc. | United States | Lifecycle / product email communications | Email address, name, engagement metadata |
| 8 | Groq, Inc. | United States | LLM API for in-product assistant features | Prompts and metadata submitted to the assistant; no customer database content unless the customer explicitly initiates it |
| 9 | Google Ireland Limited (Google Analytics) | Ireland (EEA) | Aggregated, IP-anonymised analytics on use of rivestack.io | Truncated IP address, browser metadata, page-view events |
International transfers
Customer database content is hosted in the EEA (Hetzner, Germany) and backups remain in the EEA (DigitalOcean Spaces, Frankfurt). A subset of operational sub-processors above is located outside the EEA. For those, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, the UK International Data Transfer Agreement, together with the technical and organisational safeguards described in our DPA.
Questions
Email legal@rivestack.io for any question about this page, to request a copy of our DPA, or to subscribe to update notifications.
This sub-processor list forms part of the Rivestack Data Processing Agreement.