1. Infrastructure
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and related backend services | Account information, profile information, linked account data, vouches, activity history, reports, moderation records, uploaded files, and related Service data | United States |
| Vercel | Website hosting, deployment, serverless functions, routing, and related hosting services | IP address, user agent, request metadata, page requests, and related technical information | United States and global edge network |
| Cloudflare | Bot protection, security, performance, and related edge services | IP address, browser and device information, request metadata, bot-detection signals, and related technical information | Global edge network |
2. Observability and analytics
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| PostHog | Product analytics, usage measurement, funnels, and feature improvement | Account identifiers, profile identifiers, device and browser information, usage events, page views, and in-app actions | United States |
| Sentry | Error monitoring, diagnostics, performance monitoring, and session replay where enabled | Account identifiers, technical logs, error reports, stack traces, device and browser information, and limited interaction data related to errors | United States |
3. Communications
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Resend | Transactional and service-related email | Email address, name where provided, message content where applicable, delivery metadata, and related email information | United States |
4. Verification providers
When you choose to verify ownership of an external account, Cellopack may use an authorization flow, manual review, public profile review, backlink, or another supported verification method.
For authorization-based verification, the external platform may provide information confirming that you control the linked account. Cellopack may receive and store verification-related tokens or metadata needed to complete or maintain verification.
We do not receive your password for external accounts.
When we connect to these platforms, we request the minimum, read-only access needed to confirm the account is yours. We do not use this access to post on your behalf or read private messages, we do not use the information for advertising, we do not sell it, and we do not use it to train machine-learning or artificial-intelligence models. Cellopack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
| Provider | Purpose | Data processed |
|---|---|---|
| eBay | Verification of linked eBay accounts | Authorization metadata and verification-related account information you approve during connection |
| Google / YouTube | Verification of linked YouTube channels or Google-connected accounts | Authorization metadata and verification-related account information you approve during connection |
| TikTok | Verification of linked TikTok accounts | Authorization metadata and verification-related account information you approve during connection |
| Meta / Threads | Verification of linked Threads accounts | Authorization metadata and verification-related account information you approve during connection |
| Stripe Identity | Identity verification through government-issued document and selfie capture | Government-issued identity document image, selfie image, and related verification information you provide during the verification flow. Identity documents and selfie images are processed and retained by the verification provider; Cellopack receives only the verification outcome and limited verification metadata (such as document type, issuing country, and verification dates). |
You may remove a verified link from your profile at any time. When you remove a verified link, or edit it so that it is no longer verified, we delete or de-identify verification tokens from active systems, except where retention is needed for security, fraud prevention, legal compliance, dispute resolution, backups, audit purposes, or enforcement of our Terms.
5. Payments
When you purchase a paid membership, payment processing is handled by our payment processor. Cellopack does not receive or store card numbers, card verification values, full bank account numbers, or other payment-instrument secrets.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Stripe (Stripe Payments, Stripe Billing, Stripe Tax) | Subscription billing, payment processing, invoice generation, customer portal, tax calculation, and related billing services | Cardholder name and email where provided, billing address where required for tax or fraud-prevention purposes, payment-method tokens, subscription identifiers, transaction identifiers, invoice metadata, and related billing metadata. Cellopack receives and stores only subscription and billing-status metadata (such as the customer and subscription identifiers, plan, status, and renewal date). | United States and global |
Payment-instrument information is processed by the payment processor under its own terms and privacy policy.
7. Changes to this list
We may update this page when we add, remove, or materially change a subprocessor.
When we make changes, we will update the "Last updated" date above. For changes that meaningfully affect how personal information is processed, we may provide notice by email, in-app notice, banner, or another reasonable method.
To request notice of updates to this list, contact us at support@cellopack.xyz.
6. Social and preview providers
Cellopack profiles may include metadata that helps third-party platforms generate previews when profile links are shared.
Third-party platforms may process shared links, previews, and related metadata under their own terms and privacy policies.