Legal

Subprocessors

Last updated September 28, 2026

No platform is built alone. These are the service providers ("subprocessors") that help us run givevery and may process personal information on behalf of the nonprofits we serve. We chose each one carefully. Each subprocessor is bound by a written agreement that requires it to protect personal information, use it only to provide services to givevery, and meet obligations at least as protective as our Data Processing Addendum.

Primary data location: our primary database, authentication and file storage are hosted in Canada (AWS ca-central-1, Montréal). The providers listed below may process data in the locations shown.


Core infrastructure (used for every nonprofit)

SubprocessorLegal entityPurposePersonal data processedProcessing locationTransfer safeguard
SupabaseSupabase, Inc. (USA)Primary database, authentication, file storageAll Customer DataCanada (AWS ca-central-1)Data at rest in Canada; SCCs for any support access
StripeStripe Payments Canada, Ltd. and Stripe, Inc.Payment processing, Connect accounts, payouts, fraud preventionDonor name, email, billing address, payment details; nonprofit KYC dataUnited States, Canada and other Stripe locationsSCCs; EU-U.S. Data Privacy Framework (DPF)
VercelVercel Inc. (USA)Application hosting, serverless functions, content deliveryData in transit through requests; request logs (IP address, user agent)United States; global edge networkSCCs; DPF
ResendPlus Five Five, Inc. d/b/a Resend (USA)Transactional email: receipts, confirmations, dedication noticesRecipient name and email, email contentUnited StatesSCCs; DPF
Trigger.devAPI Hero Ltd d/b/a Trigger.dev (UK)Background jobs (receipt generation, scheduled tasks)Data in job payloads, such as receipt detailsUnited States (AWS us-east-1)UK adequacy; SCCs
Google Maps PlatformGoogle LLC (USA)Address autocomplete on donation formsPartial address text as typed; IP addressUnited StatesSCCs; DPF
UpstashUpstash, Inc. (USA)API rate limiting and abuse preventionIP address, request identifiersUnited StatesSCCs
SentryFunctional Software, Inc. d/b/a Sentry (USA)Error and performance monitoring, with personal-information scrubbing enabledLimited technical data (IP address, user ID, browser); PII fields scrubbedUnited StatesSCCs; DPF

Optional features (only when a nonprofit opts in)

SubprocessorLegal entityPurposePersonal data processedProcessing locationTransfer safeguard
AnthropicAnthropic PBC (USA)Claude API: suggests dashboard widget layouts and queries from natural-language prompts when the AI widget builder is enabledPrompt text typed by dashboard users and read-only schema metadata (table/column names and allowed metrics). Donation rows and donor PII are not sent; widgets load data on Givevery servers after creationUnited StatesSCCs; see Anthropic Privacy Policy and Commercial Terms
SalesforceSalesforce, Inc. (USA)Optional CRM sync: when a nonprofit connects Salesforce, Givevery sends donor and gift records to that org (Nonprofit Cloud, NPSP, or standard objects)Donor name, email, address, phone, birthday; gift amount, date, payment method, campaign and dedication details as configured by the nonprofitUnited States and the Salesforce region of the connected orgSCCs; DPF; customer-instructed processing

Not subprocessors

These providers don't process Customer Data on our behalf, and are listed here for transparency:

ProviderPurpose
Google Analytics (Google LLC)Opt-in analytics on the givevery.com marketing website only. Never used on donation pages or in the dashboard.
PostHogNot in use. If we enable it later, it will be platform analytics only — never donation pages or donor personal information — and we will add it to this list and give 30 days' notice first.

Changes to this list

We will give at least 30 days' notice before a new subprocessor begins processing Customer Data. We will do this by updating this page and emailing nonprofits that have subscribed to updates. If you have a reasonable, data-protection-based objection to a new subprocessor, you may object in writing during the notice period, as described in section 5 of the DPA.

Subscribe to updates: email privacy@givevery.com with the subject line "Subscribe to subprocessor updates". Nonprofit account owners are subscribed automatically.


Questions: privacy@givevery.com

Related: Data Processing Addendum · Privacy Policy · Trust Center

Givevery