SUBPROCESSORS
Subprocessors.
To deliver our managed hosting and related services, Schwen Scalability uses a small set of trusted third-party providers ("subprocessors") that may process personal data on our clients' behalf. This page discloses who they are and what each does. It supports our Privacy Policy and any Data Processing Addendum (DPA).
Provider Register
The specific providers that apply depend on the services you use. "Current" means the provider is used by the live platform, "Consent-dependent" means it is used only after a visitor opts in, "Conditional" means it is used only when configured and selected, and "Planned" means code exists but the integration is not activated.
| Subprocessor | Status | Purpose | Data processed |
|---|---|---|---|
| Vercel | Current | Application & website hosting; serverless API hosting | Hosted site/app content, request logs, and end-user data passing through hosted applications |
| Supabase | Current | Managed database & authentication | Intake contact details, transcripts, extracted document text or image descriptions, portal project data, and authentication records |
| Resend | Current | Transactional email delivery | Recipient email addresses and the content of transactional emails sent on your behalf |
| GitHub | Current | Private project-context and source-code repository hosting | After verified intake completion: project summary, full intake transcript, extracted uploaded-document text or image descriptions, Project Brain/Graphify seed artifacts, source code, configuration, and repository metadata |
| Anthropic | Current | AI intake, portal assistant, image description, and pre-call preparation | Relevant conversation and project details; extracted text from uploaded text/PDF files; original uploaded images for a one-time description pass; resulting image descriptions |
| Google Analytics (Google LLC) | Consent-dependent | Public-site traffic, engagement, and conversion measurement after visitor consent | Public-page URLs, referral/campaign data, approximate location, device/browser data, and non-content interaction events; no client-portal activity, intake answers, account details, or uploaded files |
| Conditional | Google Sign-In and identity-token verification when configured and selected | Identity token and verified email; intake may also store the name and profile-image URL returned by Google | |
| Cloudflare | Planned | DNS & domain management after Stack Factory activation | DNS records, domain configuration, and network-level request metadata |
| Stripe | Current | Hosted checkout, recurring billing, invoices, and customer billing management | Billing contact details, payment-method metadata, subscription and invoice records, and payment status (we do not receive full card or bank-account numbers) |
Notice of Changes
We may add or replace subprocessors as services evolve, and this page is the current public list. There is not yet an automated subprocessor-change notification workflow. If a signed DPA requires advance notice or an objection period, those terms and the notification method must be agreed with the client for that engagement.
Data Processing Addendum
Clients who need a signed DPA governing our processing of end-user personal data can request one at matthew@schwen.me. The DPA incorporates this subprocessor list.
Schwen Scalability · Last updated: July 31, 2026 · schwenscalability.com