RECEIVERX ← Back to ReceiverX

Legal

Sub-processors

Effective Date: July 7, 2026 Last Updated: July 29, 2026

This page lists the third-party Sub-processors that ReceiverX LLC, a Texas limited liability company ("ReceiverX"), engages to Process Personal Data on our customers' behalf in connection with the Service. It supplements our Privacy Policy and our Data Processing Addendum (DPA).

We require all Sub-processors to provide a level of data protection consistent with our DPA, including security, confidentiality, and breach-notification obligations.

Stay informed of changes

By default, we email all Tenant administrative and legal contacts of record (in addition to updating this page) when a new or replacement Sub-processor is added. Tenant contacts that wish to receive notices at additional addresses, or to opt a separate distribution list into notifications, may write to legal@receiver-x.com (subject: "Subscribe — sub-processor updates").

We will give at least 30 days' prior notice of any new or replacement Sub-processor by updating this page and notifying Tenant contacts as described above. Where security or continuity requires it (for example, a Sub-processor breach or insolvency), we may engage a replacement on shorter notice and will inform Customers as soon as reasonably practicable.

If a Tenant has a reasonable, documented data-protection objection, contact us within the notice window and we will work in good faith to provide an alternative; if we cannot, the Tenant may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees for the unused portion (see DPA §6.3).


Current Sub-processors

Scroll horizontally to see all columns →

# Sub-processor Role / Service Location of Processing Cross-Border Transfer Mechanism
1 Railway Corp. Application hosting and compute (web app, API, background workers) United States EU SCCs (Module 2/3) + UK Addendum
2 Neon Inc. Managed PostgreSQL (Customer data, account, audit logs) United States EU SCCs + UK Addendum
3 Cloudflare, Inc. DNS, CDN, and WAF/edge security; static site hosting (Pages — marketing site); file storage (R2) United States; global edge EU SCCs + UK Addendum
4 Resend (Resend, Inc.) Transactional email delivery (verification, password reset, magic-link reports, security notices) United States EU SCCs + UK Addendum
5 Upstash Inc. Rate limiting and ephemeral cache (Redis) United States EU SCCs + UK Addendum
6 Google LLC Single sign-on (only if user signs in with Google) United States; global EU-US Data Privacy Framework where available; SCCs
7 Amazon Web Services, Inc. AI image analysis (AWS Bedrock); ancillary AWS services as needed United States EU SCCs + UK Addendum
8 BunnyWay d.o.o. (bunny.net) Video content delivery (embedded commodity training videos) EU (Slovenia); global edge EEA-based provider; SCCs for onward transfers

Platform providers (independent controllers / data importers; not DPA Sub-processors for Tenant Customer Content)

The following platforms are not Sub-processors of Customer Content under our DPA. They are independent controllers / data importers that we list here for transparency. Their Processing of Personal Data in connection with the platform is governed by their own terms and privacy policies.

Platform Role Location
Paddle (Paddle.com Inc. — U.S.; Paddle.com (Canada) Ltd. — Canada; Paddle.com Market Limited — all other countries) Merchant of record, payment processing, and subscription billing for purchases made on our website; the purchase transaction is between you and Paddle. Acts as an independent business / controller for payments, invoicing, tax calculation and remittance, fraud-prevention, anti-money-laundering, and regulatory purposes; PCI-DSS compliant United States; Canada; United Kingdom
Apple Inc. Mobile app distribution; in-app purchase processing (where used) under Apple Media Services Terms United States
Google LLC (Google Play) Mobile app distribution; in-app purchase processing (where used) under Google Play terms United States

"Cross-Border Transfer Mechanism" describes the safeguard we rely on for transfers from the EEA, the UK, or Switzerland to the United States or other third countries. Where a Sub-processor self-certifies under the EU-US, UK Extension to the EU-US, or Swiss-US Data Privacy Framework, we may rely on that certification for the relevant transfer leg.

Affiliates

If we engage our own affiliates (entities under common control) as Sub-processors for support, sales, or security functions, they will be subject to the same data-protection obligations described above and will be added to the table above. (Billing and payment processing are handled outside processor scope under DPA §2.3.)

Questions

For DPA, sub-processor, or data-protection questions, contact privacy@receiver-x.com or legal@receiver-x.com.