Service Providers
Last updated: 4 October 2026
This page identifies PageJoy's providers and how they handle information. It separates business-data subprocessors from services that handle information for their own purposes.
1. Our responsibility
PageJoy operates pagejoy.app. Contact support@pagejoy.app about a provider or processing location. Read our Privacy Notice and Plugin Privacy Notice for the relevant flow.
A provider's role depends on the activity and contract. A processor follows our instructions for information we control. A subprocessor follows our instructions for business customer data we process for that customer. An independent controller decides its own purposes. A provider can have different roles for different activities. EDPB role guidance.
2. Provider register
Account information, saved invoice details and shared Business workspace records are stored in a company-operated Supabase database on a computer operated by our company. Ask support for information about the location relevant to your account. Both ChatGPT and Claude quota records are tied to the free account. The register below also covers security activity, 2-step data, sessions, code challenges, request limits and security-alert delivery.
Our account service uses Supabase Auth and email codes. Google and Microsoft are sign-in options where enabled. Apple sign-in is switched off. The register explains each provider's separate role and the information involved.
| Provider | Function | Information involved | Role for this function | Processing and access countries | Privacy and contract reference |
|---|---|---|---|---|---|
| Stripe, including Link | Stripe Managed Payments merchant of record, payment, sales tax and VAT; Link functions: payment and order support where offered on your Stripe checkout screen | checkout, event and receipt identifiers, workspace and Owner IDs, chosen plan, country, currency, quantity, amounts, status, consent time, business name and tax ID if supplied. We do not receive the full card number | independent payment and merchant-of-record functions under the purchase terms; our company supplies the software and controls account entitlements | the provider's international infrastructure, as described in its privacy notice. Ask us about the locations relevant to your use | Stripe privacy, Stripe services and the purchase terms displayed at checkout |
| a company-operated Supabase database | Account storage and saved Templates details in free or paid Business workspaces and paid Personal accounts | account ID, verified email, linked provider and identity IDs, sign-in methods, optional name, workspace preference and notification settings; authentication tokens and security state stay on the server; business details, clients, items, logos and business name, contact and address details, tax and payment details, logo, clients, saved items, document type and number, dates, line descriptions, quantities, prices, tax, currency, totals, notes, status, links, approvals and design preferences | our company operates the database. Supabase does not receive records merely because we use its open-source software | Database storage: a computer operated by our company. Ask support for information about the location relevant to your account; other access: a computer operated by our company. Ask support for information about the location relevant to your account | Supabase privacy, DPA and its open-source software notices. Our database is operated by our company |
| Cloudflare Workers; current website hosting provider | Serve the website and server routes. No public chat file-processing server is in use | Network address, request URL and headers, information submitted to account and Templates server routes, and operational event, status and error records. Website PDF and Photo file contents are excluded | Processor for website hosting and subprocessor for Business workspace information handled through the server routes under the applicable DPA | Cloudflare's international network and support locations, as described in its privacy policy and DPA | Cloudflare privacy and DPA |
| Vercel; not in use today | No current hosting function | fixed event name or route, source, time, HTTP status and operational error code; private authentication and rate records are separate. File contents, file names and signed links are excluded | no current processing of our application records. A provider receiving such records on our instructions must act under an applicable data-processing agreement | our company-operated computer; these providers do not currently receive application records | Vercel privacy and DPA. We do not send application records to Vercel |
| Resend; email delivery provider | Send every PageJoy email: sign-in and confirmation codes, account security alerts and Business invitations | Recipient email or Apple relay address and the message, including any code or invitation link; for invitations, the inviter's email address and the workspace name; delivery status | Processor under Resend's DPA | Outside the UK, as described in Resend's privacy policy and DPA | Resend privacy and DPA |
| Third-party analytics providers, only after you press Accept | Count visits, pages opened and finished downloads | a random analytics ID, page address, event, referring site, browser, device type and country; no file contents, file names, signed links or account secrets | processor, acting under its data-processing terms | may be outside the UK, under their data-processing terms | their privacy notices and data-processing terms apply |
| Sentry; server error reporting | Tell us when a server error happens so we can fix it | A fixed message ("An unexpected PageJoy server error occurred."), the time, whether it was the live or preview site and which part of the service failed. No customer details, file contents, credentials or links are sent | Processor under Sentry's DPA | Sentry's EU data region in Germany | Sentry privacy and DPA |
| Supabase Auth; deployment and contracting party: Supabase Auth operated by our company; Supabase does not receive account records merely because we use its software | Account authentication, verified identities and provider linking through the server broker | Confirmed account email, account and provider identity, server-held authentication tokens; further fields: account ID, verified email, linked provider and identity IDs, sign-in methods, optional name, workspace preference and notification settings; authentication tokens and security state stay on the server | our company operates the database. Supabase does not receive records merely because we use its open-source software | a computer operated by our company. Ask support for information about the location relevant to your account | Supabase privacy, DPA and its open-source software notices. Our company operates the account service |
| Cloudflare Turnstile; contracting entity: Cloudflare; its applicable terms identify the contracting company | Check for bots and protect sign-in, code, permission, free-use, invite, contact and support actions | Network and browser signals, site context and verification result; data and retention: browser, user-agent, network and challenge signals, site context, token and verification result. Cloudflare's notice explains its separate handling and retention | Protection: processor; detection improvement: independent controller, subject to the actual agreement and assessment | Cloudflare's network processing and support locations under its provider privacy notice. Ask us about the locations relevant to your use | Turnstile Privacy Addendum; Turnstile Privacy Addendum and the applicable Cloudflare terms |
| not used; no approximate-location lookup is enabled | Optional approximate place shown for signed-in devices, if enabled | Trusted network address sent for approximate-place lookup; returned rough place; final fields: not used; no approximate-location lookup is enabled | not used; no approximate-location lookup is enabled | not used; no approximate-location lookup is enabled | not used; no approximate-location lookup is enabled |
| Sign-in only, when you choose it | Verified provider email and provider identity; further fields: provider identity and verified email, including a private relay address where offered. Provider access and refresh tokens stay on the server. Apple sign-in is switched off | the provider independently controls its sign-in service; we control our account administration. No role beyond the actual selected sign-in flow is implied | the provider's international infrastructure, as described in its privacy notice. Ask us about the locations relevant to your use | Google privacy. Google controls its sign-in service under its own terms | |
| Microsoft | Sign-in only, when you choose it | Verified email, Microsoft identity and server-held OAuth state | Independent sign-in provider; our company controls account administration | Microsoft's international infrastructure, as described in its privacy notice | Microsoft privacy and the terms of its sign-in service |
| Apple | Sign-in only, when you choose it | Verified provider email or private relay address and provider identity; further fields: provider identity and verified email, including a private relay address where offered. Provider access and refresh tokens stay on the server. Apple sign-in is switched off | the provider independently controls its sign-in service; we control our account administration. No role beyond the actual selected sign-in flow is implied | the provider's international infrastructure, as described in its privacy notice. Ask us about the locations relevant to your use | Apple privacy. Apple sign-in is switched off |
Turnstile is an external script and verification service. It can receive an IP address, TLS fingerprint, user-agent information, sitekey and origin. Cloudflare separates processing for website protection from processing to improve bot detection. Its privacy notice explains these separate purposes. Turnstile Privacy Addendum.
Registering an email sender for Apple private relay supports delivery to the relay address. It does not give us permission to discover the person's underlying email address. Supabase Apple setup. We do not use an approximate-device-location service.
3. Business-data subprocessors
Our company operates the database. Cloudflare Workers hosts the website and server routes as a subprocessor for Business workspace information handled through those routes under the current Data Processing Addendum. OpenAI and Anthropic operate separate platform services. Any additional provider must be authorised under the addendum before receiving customer data. This register is service version 2026-10-04, dated 4 October 2026.
Only providers that process customer personal data on our instructions belong in the business-data subprocessor register. This covers shared Business documents, approvals, member permissions and activity records within the DPA scope. Website PDF and Photo work remains on each person's device and is not uploaded by those tools. Server plugin processing requires a separately agreed scope. Claude tools select files only inside our panel and do not read files uploaded to the Claude chat.
The DPA gives general written authorisation for the approved list and a notice and objection procedure for changes. Notices are sent through written email to the authorised workspace Owner or nominated customer privacy contact at least 30 days before an intended addition or replacement. Objections are sent to support@pagejoy.app within 14 days, as explained in the DPA.
4. ChatGPT and Claude
OpenAI and Anthropic handle chats under their own terms when you use our plugin through ChatGPT or Claude. They are part of the user's platform flow. Their own processing is described in OpenAI's Privacy Policy and Anthropic's Privacy Policy.
In both ChatGPT and Claude, the monthly free-use count is tied to your free PageJoy account. We store a keyed account identity, the tool and UTC month association, completed-output identifiers to prevent duplicate counting, and pending reservations. We treat these as pseudonymous personal information. No anonymous ChatGPT quota identifier or anonymous ChatGPT permission is used. These records enforce the allowance of 3 completed uses per tool per month and are separate from file copies. Our independently controlled counting records, their fields and retention are explained in the Plugin Privacy Notice. The relevant plugin infrastructure and locations are a company-operated Next.js server and Supabase database. No public chat file-processing service or processing queue is in use. OpenAI and Anthropic separately control their platform services.
We do not describe either platform as an approved subprocessor without a contract and role assessment supporting that description.
5. Overseas safeguards
Customer records remain on a computer operated by our company. Any restricted international provider transfer requires the applicable safeguards and assessment before it starts. Contact support@pagejoy.app for information about relevant safeguards and permitted redacted copies. UK and EU transfer rules are assessed separately. An overseas support team's access may itself need a transfer assessment. ICO international transfers guide.
6. Updates
We update this register when providers or their processing change. Material privacy changes follow the notice procedure in our Privacy Notice. Business subprocessor changes follow the separate DPA notice and objection procedure.
The person responsible for privacy at our company reviews this register before a change to a provider or its handling of information.