Legal
Subprocessors
Last updated September 28, 2026
No platform is built alone. These are the service providers ("subprocessors") that help us run givevery and may process personal information on behalf of the nonprofits we serve. We chose each one carefully. Each subprocessor is bound by a written agreement that requires it to protect personal information, use it only to provide services to givevery, and meet obligations at least as protective as our Data Processing Addendum.
Primary data location: our primary database, authentication and file storage are hosted in Canada (AWS ca-central-1, Montréal). The providers listed below may process data in the locations shown.
Core infrastructure (used for every nonprofit)
| Subprocessor | Legal entity | Purpose | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| Supabase | Supabase, Inc. (USA) | Primary database, authentication, file storage | All Customer Data | Canada (AWS ca-central-1) | Data at rest in Canada; SCCs for any support access |
| Stripe | Stripe Payments Canada, Ltd. and Stripe, Inc. | Payment processing, Connect accounts, payouts, fraud prevention | Donor name, email, billing address, payment details; nonprofit KYC data | United States, Canada and other Stripe locations | SCCs; EU-U.S. Data Privacy Framework (DPF) |
| Vercel | Vercel Inc. (USA) | Application hosting, serverless functions, content delivery | Data in transit through requests; request logs (IP address, user agent) | United States; global edge network | SCCs; DPF |
| Resend | Plus Five Five, Inc. d/b/a Resend (USA) | Transactional email: receipts, confirmations, dedication notices | Recipient name and email, email content | United States | SCCs; DPF |
| Trigger.dev | API Hero Ltd d/b/a Trigger.dev (UK) | Background jobs (receipt generation, scheduled tasks) | Data in job payloads, such as receipt details | United States (AWS us-east-1) | UK adequacy; SCCs |
| Google Maps Platform | Google LLC (USA) | Address autocomplete on donation forms | Partial address text as typed; IP address | United States | SCCs; DPF |
| Upstash | Upstash, Inc. (USA) | API rate limiting and abuse prevention | IP address, request identifiers | United States | SCCs |
| Sentry | Functional Software, Inc. d/b/a Sentry (USA) | Error and performance monitoring, with personal-information scrubbing enabled | Limited technical data (IP address, user ID, browser); PII fields scrubbed | United States | SCCs; DPF |
Optional features (only when a nonprofit opts in)
| Subprocessor | Legal entity | Purpose | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| Anthropic | Anthropic PBC (USA) | Claude API: suggests dashboard widget layouts and queries from natural-language prompts when the AI widget builder is enabled | Prompt text typed by dashboard users and read-only schema metadata (table/column names and allowed metrics). Donation rows and donor PII are not sent; widgets load data on Givevery servers after creation | United States | SCCs; see Anthropic Privacy Policy and Commercial Terms |
| Salesforce | Salesforce, Inc. (USA) | Optional CRM sync: when a nonprofit connects Salesforce, Givevery sends donor and gift records to that org (Nonprofit Cloud, NPSP, or standard objects) | Donor name, email, address, phone, birthday; gift amount, date, payment method, campaign and dedication details as configured by the nonprofit | United States and the Salesforce region of the connected org | SCCs; DPF; customer-instructed processing |
Not subprocessors
These providers don't process Customer Data on our behalf, and are listed here for transparency:
| Provider | Purpose |
|---|---|
| Google Analytics (Google LLC) | Opt-in analytics on the givevery.com marketing website only. Never used on donation pages or in the dashboard. |
| PostHog | Not in use. If we enable it later, it will be platform analytics only — never donation pages or donor personal information — and we will add it to this list and give 30 days' notice first. |
Changes to this list
We will give at least 30 days' notice before a new subprocessor begins processing Customer Data. We will do this by updating this page and emailing nonprofits that have subscribed to updates. If you have a reasonable, data-protection-based objection to a new subprocessor, you may object in writing during the notice period, as described in section 5 of the DPA.
Subscribe to updates: email privacy@givevery.com with the subject line "Subscribe to subprocessor updates". Nonprofit account owners are subscribed automatically.
Questions: privacy@givevery.com
Related: Data Processing Addendum · Privacy Policy · Trust Center