Sub-processors
Updated 2026-05-01
Sortly uses the third-party services listed below to deliver the product. We update this page within 30 days of any change. The same list is enforced by a CI check against plans/infrastructure.md §2; if you spot a discrepancy, please email privacy@igloo-labs.com.
Scroll across the table to see all details.
| Provider | Service | Data shared | Country of processing |
|---|---|---|---|
| Supabase | Postgres, Auth, Realtime, Storage, Edge Functions | Account data, household data, child profiles, social graph, availability, playdates, push tokens | Ireland (eu-west-2) |
| Vercel | Next.js marketing site hosting | Browser request metadata; submitted email address (for the email-capture form) | Ireland (lhr1 / fra1) |
| Twilio Verify | SMS OTP delivery for phone-number verification | Phone number; one-time verification code | Ireland |
| Apple APNs | iOS push notifications | Push token; notification payload (no PII in payload) | USA (Apple-managed) |
| Google FCM | Android push notifications (not used in H1; reserved for H2) | Push token; notification payload (no PII in payload) | USA (Google-managed) |
| Resend | Transactional email (magic links, co-parent invites, support, GDPR exports) | Email address; first name; transactional content | Ireland |
| Sentry | Error reporting (iOS, Edge Functions, Next.js) | Pseudonymous analytics ID; stack traces; release version (no PII) | Germany (EU-region) |
| PostHog | Product analytics, cohort analysis, feature flags | Pseudonymous analytics ID; product event names + properties (no PII) | Germany (EU cloud) |
| Cloudflare | DNS for getsortly.app + CDN for public marketing assets | Browser request metadata (IP, user agent, request URL) | Global (edge nodes; UK-resident traffic served from London) |
| GitHub | Source control, code review, CI (no customer data) | Engineering source code only — no end-user data | USA |
| 1Password | Team secret store (no customer data) | Internal team credentials only — no end-user data | Canada |
| GIAS (gov.uk) | UK schools reference data feed | One-way pull from gov.uk; no Sortly user data shared with GIAS | United Kingdom |
How we vet sub-processors
We choose providers that (a) offer EU or UK data residency where possible, (b) have a published GDPR sub-processor agreement we can rely on, and (c) we can replace without re-architecting. New sub-processors require an internal review and an entry in the relevant ADR before we send them any user data.