Last updated September 9, 2026
Uprityrelies on third-party service providers to deliver the Service. We review available contractual, privacy, and security terms according to the provider's role and the data involved.
This page lists all current sub-processors. Changes are announced 30 days in advance via email to account holders.
| Provider | Purpose | Data Processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All user & business data | AWS (US, EU) |
| Google Gemini | AI-generated review replies & insights | Review text, business name | US |
| Resend | Transactional email delivery | Name, email, invoice data | US |
| Razorpay | Payment processing (India) | Billing info (tokenized) | India |
| Paddle | Payment processing (International) | Billing info (tokenized) | International; see provider notice |
| Hostinger | Application hosting | Request logs, error traces | Depends on deployment configuration |
| Cloudflare | CDN, DDoS protection, analytics, Turnstile bot protection on chat + public forms | IP, request metadata, browser signals for Turnstile | Global |
| PostHog | Product analytics & session replay | Usage events, feature interactions | Depends on active configuration |
| Google Analytics | Website traffic analytics | Anonymized page views, conversions | US |
Purpose: PostgreSQL database, real-time API, authentication, and file storage.
Data: All account data, business information, review data, and user-uploaded files.
Privacy: supabase.com/privacy
Purpose:Generates AI-powered review replies and audit insights. Not used to train Google’s models.
Data: Review text, business name, and optional context. Transmissions are encrypted.
Privacy: policies.google.com/privacy
Purpose: Sends transactional emails (password resets, invoices, alerts).
Data: Email address, name, invoice details.
Privacy: resend.com/privacy
Purpose: Processes payments for Indian customers (UPI, card, net banking).
Data: Billing name, email, amount (card data is tokenized and never stored by Uprity).
Privacy: razorpay.com/privacy
Purpose: Acts as merchant of record and processes eligible international purchases.
Data: Billing name, email, amount (card data is tokenized).
Privacy: paddle.com/legal/privacy
Purpose: Hosts the Uprity web application.
Data: Request logs, error traces, and performance metrics.
Privacy: hostinger.com/legal/privacy-policy
Purpose: CDN, DDoS protection, analytics proxy, and Turnstile bot protection on the chat widget and other public submission surfaces.
Data: IP address, request metadata, access logs. Turnstile additionally analyzes browser signals (invisible mode) to distinguish real visitors from automated traffic.
Privacy: cloudflare.com/privacypolicy · Turnstile Privacy Addendum
Purpose: Tracks feature usage and user interactions for product improvement when enabled under the applicable consent and deployment configuration.
Data: Feature interactions, session duration, error events (no PII by default).
Privacy: posthog.com/privacy
Purpose: Tracks website traffic and user behavior for analytics.
Data: Anonymized page views, referrer, device type (consent-based for EU).
Privacy: policies.google.com/privacy
Depending on the provider's role and risk, our review may consider:
For certain sub-processors, you can opt out:
Core database, hosting, delivery, and payment providers cannot generally be disabled because they are necessary to provide the applicable Service.
We may engage new sub-processors or replace existing ones. You will be notified by email 30 days in advance of any changes that materially affect the processing of your personal data.
You have the right to object to a new sub-processor within 30 days by emailing privacy@uprity.com. If you object, we will work with you to find an alternative solution or enable you to export your data and terminate your account.
For questions about our sub-processors, contact: