Skip to main content

Last updated: April 30, 2026

Masarap Cafe relies on the following sub-processors to operate the platform. Each sub-processor is bound by a written Data Processing Agreement (GDPR Article 28) that limits processing to the purposes listed below, requires equivalent security controls, and prohibits onward transfer without authorization. International transfers are made under the EU-U.S. Data Privacy Framework (where the vendor is certified) or under the European Commission’s 2021/914 Standard Contractual Clauses with supplementary technical measures (encryption in transit and at rest).

We notify customers of material changes to this list via this page and (for registered users) via email at least 30 days before a new sub-processor begins processing personal data, unless the change is required by law or to address a critical security risk.

Sub-processorPurposeRegionTransfer mechanism
RenderApplication hosting (API, web, KDS)United States — OregonStandard Contractual Clauses (2021/914)
MongoDB AtlasPrimary database (orders, users, audit log)United StatesStandard Contractual Clauses (2021/914)
Upstash / Render RedisCache, rate limiting, session stateUnited StatesStandard Contractual Clauses (2021/914)
StripePayment processing for sauce orders, refunds, fraud signalsUnited States, globalEU-U.S. Data Privacy Framework (DPF)
SquarePayment processing for food orders, kitchen display syncUnited StatesStandard Contractual Clauses (2021/914)
EasyPostShipping label generation and trackingUnited StatesStandard Contractual Clauses (2021/914)
CloudinaryProduct imagery storage and CDN deliveryUnited States, global CDNEU-U.S. Data Privacy Framework (DPF)
ResendTransactional email delivery (receipts, password reset, alerts)United StatesEU-U.S. Data Privacy Framework (DPF)
SentryError monitoring with PII redaction enabledUnited StatesStandard Contractual Clauses (2021/914)
Google (Sign-In, Analytics)Federated login; consent-gated analyticsUnited StatesEU-U.S. Data Privacy Framework (DPF)
Apple (Sign-In)Federated login (iOS / mobile)United StatesApple Privacy Policy / SCCs
VercelFrontend hosting and CDNUnited States, globalEU-U.S. Data Privacy Framework (DPF)

Questions about sub-processors, DPAs, or international transfer mechanisms can be sent to dpo@masarapcafe.com.