Version 1.0.5 · Effective
Slotlyy uses the third-party vendors below to operate the platform. We call them "subprocessors" because they process personal data on our behalf as a controller-processor relationship under Ghana Data Protection Act 2012 (Act 843), Nigeria Data Protection Act 2023, Kenya Data Protection Act 2019, and South Africa POPIA (the four African data protection laws in our active or planned markets).
Each vendor's contract status, including its Data Processing Agreement (DPA), is in the table below. Vendors that will process Protected Health Information (PHI) for medical-adjacent salons will also need a HIPAA Business Associate Agreement (BAA); every one is pending, as the table shows.
| Vendor | Purpose | Data categories | Residency | Contracts |
|---|---|---|---|---|
| Supabase Inc. Primary infrastructure. SOC 2 Type II + ISO 27001 certified. | Database (Postgres) + authentication + object storage |
| AWS eu-west-1 (Ireland) | DPA on file; HIPAA BAA (Team plan) pending vendor signature pre-launch (Enterprise Item #29 Phase 2) |
| Vercel Inc. Hosts both slotlyy.com (tenant-facing) + ops.slotlyy.com (internal). | Application hosting + CDN + serverless functions |
| AWS multi-region (global edge network) | DPA on file; HIPAA BAA (Pro plan) pending vendor signature pre-launch (Enterprise Item #29 Phase 2) |
| Cloudflare Inc. sltycdn.net custom domain on R2 serves every tenant asset. | DNS + DDoS protection + R2 object storage + CDN edge cache |
| Global edge network (250+ POPs) | DPA |
| Paystack Payments Ltd. PCI-DSS Level 1 certified. Slotlyy never stores raw card data. | Payment processing in Ghana (Nigeria once Slotlyy launches there) |
| Nigeria + UK (Paystack data centers) | Merchant Services Agreement + DPA |
| Flutterwave Inc. PCI-DSS Level 1 certified. Slotlyy never stores raw card data. | Planned, not yet in use: payment processing for Kenya, South Africa, Uganda, Tanzania, Rwanda, Côte d'Ivoire, Senegal and Cameroon once Slotlyy launches there |
| US + Africa (Flutterwave multi-region) | No merchant account yet |
| Upstash Inc. (QStash) Reliable delivery via QStash retry queue. Messages auto-expire post-delivery; failed deliveries land in dead-letter queue accessible to ops. | Notification message queue. Every booking confirmation / lapse-cascade / reminder email + SMS + push notification flows through QStash before delivery to the third-party sender. |
| Global (Upstash multi-region; QStash messages stored ≤ 30 days per Upstash retention default) | DPA |
| Upstash Inc. (Redis) Keys auto-expire at end of rate-limit window (60s for OTP cooldown, 1h for hourly limits, etc.). Same Upstash account as QStash above; shared DPA. | Rate-limiting buckets (OTP send/verify limits, booking creation limits, admin mutation limits per Bible §60 + SECURITY_CHECKLIST.md §17) |
| Global (Upstash multi-region; rate-limit windows ≤ 1 hour per @upstash/ratelimit defaults) | DPA |
| Resend Inc. No marketing email; transactional only. SPF + DKIM + DMARC configured per `docs/runbooks/email-dns-setup.md`. | Transactional email delivery (booking confirmations, receipts, reminders) |
| AWS eu-west-1 (Ireland), the sending region of the slotlyy.com domain — Resend infra runs on AWS SES | DPA |
| Arkesel SMS only. A WhatsApp-first path with 30-second SMS fallback is BUILT BUT DORMANT - the WhatsApp send is commented out pending Arkesel sender approval, so no OTP has ever been delivered over WhatsApp. This list states CURRENT data flows, never planned ones. | SMS OTP + transactional SMS delivery for Ghana |
| Ghana + Nigeria | Vendor services agreement + DPA pending |
| Google LLC (Firebase Cloud Messaging) No data is sent to Firebase today. Tokens would be stored in the user_devices table. | Planned, not yet in use: push notifications to staff (no device can register yet, register R-340) |
| Global (Google Cloud) | Google Cloud DPA |
| Functional Software Inc. (Sentry) Two separate projects: slotlyy-web + slotlyy-ops. The scrubber in `@slotlyy/sentry-shared` runs on errors, performance traces and spans. It removes phone numbers written in international format (+233…), emails, JWTs, bearer tokens and session cookies, and any value stored under a name such as password or otp. It does not recognise a phone number written in local format (024…) or a password written into free text under no such name. See `apps/web/src/__tests__/sentry-pii-scrub.test.ts`. | Error monitoring + release tracking for apps/web + apps/ops |
| United States (sentry.io) | DPA |
| PostHog Inc. Session recording runs only on public salon pages (/b/*) of tenants that are not PHI-bearing, and never on the booking confirmation page or the /booking magic-link routes (per `recordingAllowed()`, applied by `RecordingGate` inside the salon page layout; a salon whose type cannot be read is treated as PHI-bearing). In recordings all text on the page and all typed input are masked, embedded frames (the payment windows) are blocked, and network requests, console output and canvas are never captured. Booking and review tokens are redacted from event properties and page addresses before they are sent (`redactUrlTokens()`); what a recording shows of the page is protected by the masking and blocking, not by that redaction. The session recorder is served from the Slotlyy site itself; no PostHog script is loaded. PostHog browser SDK is initialized with `respect_dnt: true` so users with Do-Not-Track enabled are not tracked. | Product analytics, funnel tracking and session recording of public salon pages (named events only; no autocapture) |
| European Union (eu.i.posthog.com — default set in `initPostHog()`, `apps/web/src/lib/analytics/posthog.ts`; operator can override via NEXT_PUBLIC_POSTHOG_HOST env var) | DPA |
| Better Stack (Logtail Inc.) External HTTP / DNS / SSL probes only; never reads tenant data. See `docs/runbooks/external-monitoring-setup.md`. | External HTTP monitoring + status page |
| United States + Europe (Better Stack multi-region) | DPA (free tier — pending paid-tier upgrade) |
| Smile Identity Used at tenant onboarding (Starter + Pro/Business plans) per Bible §33.3.A. Raw response retained 7 years per §33.3.6. | KYC verification (ID document + facial biometric check) per Bible §33.3 |
| Africa-multi-region (per Smile Identity infra) | DPA aligned with Ghana DPA + Nigeria NDPA + Kenya DPA + POPIA (Slotlyy is Africa-only-focus per CLAUDE.md lock 2026-04-24) |
| Zoho Corporation (Zoho Mail) Tenant data never flows into Zoho Mail. Used only for internal team comms ([email protected] / [email protected] / etc.). Corrected 2026-09-03: this row previously named Google Workspace, which was never the live mailbox provider — the slotlyy.com apex has always run on Zoho. | Internal email for the Slotlyy team |
| Global (Zoho) | Zoho DPA |
| Amazon Web Services Inc. (S3 + KMS) Not yet provisioned: no Slotlyy data is sent to AWS today. It will be set up per `docs/runbooks/aws-audit-archive-setup.md` (Enterprise Item #1 Commit C). | Planned, not yet in use: write-once archive of audit records, and a separate encryption key for each salon |
| Planned: AWS us-east-1 (N. Virginia, United States), replicated to us-east-2 (Ohio, United States) | AWS BAA (HIPAA) + DPA — pending the AWS account setup before launch (Enterprise Item #1 Commit C) |
Slotlyy commits to 30 days' advance notice before adding a new subprocessor to this list. Existing tenants will be notified via in-app banner + email to the account-owner address registered for billing. The window gives covered entities time to assess the new vendor against their own compliance program (HIPAA / DPC registration / etc.) before the change becomes effective.
Material changes to an existing vendor relationship (new data category, new residency, terminated BAA) are treated the same — 30-day advance notice + this page updated with a new version + revision-history entry.
If you object to a new subprocessor on reasonable grounds (security / compliance / regulatory concern), contact [email protected] within the 30-day notice window. We will work with you in good faith to resolve the concern OR provide a clear notice of inability to do so (which then gives you the right to terminate the affected services per our Terms of Service).
The authoritative version of this list lives at slotlyy.com/subprocessor. Material updates trigger an email to the account-owner address; you may opt-out of any non-essential subprocessor- change emails by contacting [email protected] (we cannot opt you out of the material-change emails — those are legally required notification).