trust
Subprocessors
Last updated: August 22, 2026
To provide the Services, PandaStack uses the third-party subprocessors listed below. Each is bound by contractual confidentiality and data-protection terms consistent with our Data Processing Agreement and Privacy Policy.
1. Current subprocessors
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud Platform | Core infrastructure — compute hosts for microVMs, block storage, object storage for snapshots and backups | Customer content (sandbox disks, database volumes, backups), service logs | United States |
| Amazon Web Services | Supplementary infrastructure | Service infrastructure data | United States |
| Cloudflare | DNS, TLS termination, CDN, and edge routing for app, preview, and API traffic | Request metadata (IPs, headers), traffic in transit | Global (edge network) |
| Stripe | Billing and payments (checkout, invoices, metering) | Billing contact details, payment method (held by Stripe; card data never touches PandaStack) | United States |
| Supabase | Authentication for the dashboard and API | Account email, authentication identifiers | United States |
| Resend | Transactional email (account and lifecycle notifications) | Account email, notification content | United States |
| PostHog | Product analytics for the marketing site and dashboard | Usage events, device metadata (consent-gated where required) | United States / European Union |
| GitHub | Repository access for git-driven app deploys (only when you connect the GitHub App) | Repository metadata and contents you authorize; short-lived installation tokens | United States |
2. Changes to this list
We may add or replace subprocessors as the Services evolve. We update this page when we do. If you have executed our DPA and want advance notice of subprocessor changes with the right to object, email legal@pandastack.ai and we will add you to the notification list.