Legal
The third parties that process data on our behalf so PageReflect can run, what each one does, and how to be told before the list changes.
We use the providers below to deliver the Service. Each is engaged as a subprocessor under the Data Processing Addendum, is bound by data protection obligations no less protective than that DPA, and processes data only to perform its function for us. We remain responsible to you for their performance.
We give at least 30 days' notice before adding or replacing a subprocessor. To receive those notices, email privacy@pagereflect.com with the subject line "subprocessor notices" and the address you want them sent to.
You may object to a new subprocessor on reasonable data protection grounds within the notice period. If we cannot resolve the objection, you may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for the unused term. That is your remedy for an objection.
Not every provider sees every kind of data. Hosting and database providers hold the full record. Extraction, measurement, and analysis providers receive the URL being audited and the content retrieved from it, in order to return a result. Payment and email providers receive only what their function requires.
Optional integrations you connect yourself, such as an outbound webhook destination or a Slack workspace, are not our subprocessors. You control them, you chose them, and data sent to them leaves our processing scope on delivery.
Our primary database and object storage run in the United States. Several providers process data in other countries. Transfers out of the European Economic Area, the United Kingdom, and Switzerland rely on the Standard Contractual Clauses and, where applicable, the UK Addendum, as described in the DPA.
We do not currently offer a self-serve EU data residency option. If your contract requires a specific region, contact support@pagereflect.com before you buy.
| Provider | Purpose | Data received |
|---|---|---|
| Vercel | Application hosting + edge network | Request metadata, deploy artifacts |
| Supabase | Postgres database + auth + storage | Account data, audit artifacts, reports |
| Stripe | Payment processing | Billing metadata, Stripe customer ids (no raw card data) |
| Resend | Transactional email | Recipient email, subject, template ids |
| Inngest | Durable audit execution | Event payloads with ids only, not full records |
| Jina Reader | Primary page extraction for audits | Public URL requested and extracted text/metadata |
| Google PageSpeed Insights | Lab performance metrics | Audited public URL sent to the PSI API |
| OpenAI | Report reasoning (default tier) | Extracted page content for the audited URL |
Questions about this document? Email privacy@pagereflect.com.