Subprocessors

Last updated: March 2026

CandleKeep uses the following third-party service providers (subprocessors) that process data on our behalf as part of providing the CandleKeep service.

SubprocessorPurposeData ProcessedLocationComplianceDPA Availability
ClerkAuthentication & user managementEmail, name, profile imageUSSOC2 Type IIAvailable
PostHogProduct analyticsUsage events, device info (with consent)EU (Frankfurt)SOC2 Type IIAvailable
RailwayApplication hosting & databaseAll application dataUSSOC2 Type IIAvailable
Railway BucketsFile storageUploaded documentsUSVia Railway SOC2Via Railway
PolarSubscription billingEmail, subscription status, payment data (via their payment processor)EU (Sweden)GDPR self-certified*Available
CloudflareDNS & email routingDomain traffic metadata, email addresses (routing)GlobalSOC2 Type II, ISO 27001Available
ResendTransactional email deliveryEmail addresses, email contentUSSOC2 Type IIAvailable

*GDPR compliance is self-reported by the vendor and has not been independently verified.

Data processing is governed by each vendor's standard data processing terms, which are incorporated by reference. For details on specific DPA arrangements, contact [email protected].

Changes to Subprocessors

We commit to providing at least 30 days' notice before adding new subprocessors. To subscribe to updates about subprocessor changes, contact us at [email protected].

Questions

If you have questions about our subprocessors, contact us at [email protected].