Compliance
Subprocessors
Last updated: August 28, 2026
This page lists the subprocessors authorized under the Data Processing Addendum to Process Customer Personal Data. Mapperoni may also use the listed providers for its own account, billing, website, and operational data as described below.
| Provider | Purpose | Relevant location |
|---|---|---|
| Hetzner Online GmbH | Hosts the production application and PostgreSQL database; provides S3-compatible storage for encrypted database backups. | Germany |
| Mailgun Technologies, Inc. | Sends transactional email, including account access, invitations, and service messages. The Service is configured to use Mailgun's EU API endpoint. | European Union endpoint; provider processing locations are governed by Mailgun's terms. |
| Stripe, Inc. | Processes subscriptions, payments, billing portal requests, and related billing events. Mapperoni sends the billing account email and team identifier needed for this purpose. | Provider-managed locations; see Stripe's data-processing terms. |
| Mapbox, Inc. | Provides map tiles and mapping services. When a user loads a map, their browser connects directly to Mapbox. | Provider-managed locations; see Mapbox's data-processing terms. |
The following provider does not Process Customer project content, form answers, or map data, but may Process personal information in its own limited role:
| Provider | Purpose | Relevant location |
|---|---|---|
| Plausible Analytics OÜ | Lightweight, cookie-free website and application route-visit analytics. It receives page-visit and region information. | Provider-managed location; the application configuration does not fix the analytics endpoint. |
Mapperoni will update this page at least 30 days before adding or replacing a subprocessor that Processes Customer Personal Data. The objection process is in Section 6 of the DPA.
