We rely on a handful of trusted third parties to run the platform. This page lists every one of them — what they do, what they receive, and where they process it.
Last updated: 25 May 2026
Each subprocessor below acts on documented instructions from get that bread, under written terms requiring confidentiality and appropriate security. International transfers are handled in line with the safeguards described in our Privacy Policy §5.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Stripe | Payment processing, Stripe Connect creator payouts, KYC for payouts, chargeback handling. | Card data (handled directly by Stripe — we never see full PANs), payment metadata, identity verification data submitted by creators, payout destination details. | United States, Ireland (EU), Singapore. |
| Supabase | Primary database, authentication, file storage (project images, profile pictures, KYC documents). | All platform records: accounts, profiles, projects, pledges, messages, creator KYC fields, uploaded media. | Singapore (ap-southeast-1). |
| Vercel | Web hosting, serverless function execution, edge delivery. | Request logs (IP, user-agent, path), build artefacts, application logs. | Multi-region edge with primary functions in Singapore (sin1). |
| Resend | Transactional and newsletter email delivery. | Recipient email addresses, message bodies, delivery/open/click events. | United States. |
| Sentry | Application error tracking, error-only session replay (Section 7 of the Privacy Policy). | Stack traces, browser environment, anonymised user ID, masked replay recordings of error sessions. | United States. |
| Google (Google Analytics 4) | Aggregated platform-usage analytics — loaded only when the user opts in via the cookie banner. | Page views, traffic sources, anonymised IP, interaction events. | United States (Google global infrastructure). |
| HubSpot | Visitor identification + chat widget — loaded only when the user opts in to Marketing cookies. Also our CRM for inbound creator/backer conversations. | Cookie identifiers, page-view history once identified, form submissions, chat transcripts. | United States, Germany (EU). |
| GovTech (Singpass MyInfo) | Government-backed identity verification for creator KYC. | UINFIN/NRIC, full name, date of birth, nationality, residential status — disclosed by GovTech only with the user's explicit Singpass consent. | Singapore. |
| LinkedIn (public-profile fetch) | Creator trust-score signal. We retrieve publicly accessible LinkedIn profile content from a URL the creator provides; we do not sign in or scrape behind authentication. | Public profile text excerpts and derived signal flags. | United States. |
When we add, remove, or replace a subprocessor that handles personal data, we update this page. For material changes — for example, adding a new category of data to an existing subprocessor or switching to a different storage region — we notify users by email or by an in-product notice at least 14 days before the change takes effect, in line with Terms §19.
Questions about a subprocessor or how we manage transfers? Write to our Data Protection Officer at hello@getthatbread.sg.