Subprocessor List

Version 1.0.5 · Effective

Revision history (5 prior versions)
  • v1.0.4 — Its Sentry row said the request data sent was the URL path and status code, with all personal data scrubbed by one hook. The error-monitoring library could also send request cookies, including the sign-in session cookie, every request header and up to about 10 KB of a request body, and performance traces were not scrubbed at all (SECURITY_CHECKLIST.md §60.2.312); corrected in 1.0.5.
  • v1.0.3 — Gave the Supabase database residency as AWS us-east-1 (United States); the live project is in eu-west-1 (Ireland). Its AWS row described a write-once audit archive and per-salon keys as running, its introduction said each health-data vendor had a Business Associate Agreement on file, while every one is pending, and its banner certified the vendor facts, while the Flutterwave and Firebase rows described flows that do not run, the rate-limit row called stored phone numbers hashed, the email row gave the wrong region, and the queue row said sign-in codes pass through it; corrected in 1.0.4.
  • v1.0.2 — Corrected the Arkesel row again: purpose "SMS OTP + transactional SMS delivery for Ghana", and the notes say SMS only, with the WhatsApp path built but dormant. Its PostHog row still said "custom events only" and "NO PII" and did not list session recordings as a data category; corrected in 1.0.3, which lists them and says all page text and typing are masked.
  • v1.0.1 — Corrected Arkesel: purpose was "WhatsApp Business + SMS OTP delivery", and the notes claimed "WhatsApp first; auto SMS fallback after 30s". No OTP has ever been delivered over WhatsApp — the send is commented out pending ARKESEL_WHATSAPP_SENDER approval — so the row described a data flow that has never occurred. Now states SMS-only and marks the WhatsApp path BUILT BUT DORMANT (SECURITY_CHECKLIST.md §60.2.251).
  • v1.0.0 — Initial published version. Listed SMS Online GH (retired Phase 19, receives no data) and named Google Workspace as the mailbox provider (never live — the apex has always been Zoho Mail). Both corrected in 1.0.1.
Engineering template — counsel review pending. This page lists every third-party subprocessor that processes Slotlyy data. Counsel completes the contract-status column before Slotlyy publicly launches, and this notice is removed once that review is done.

1. About this list

Slotlyy uses the third-party vendors below to operate the platform. We call them "subprocessors" because they process personal data on our behalf as a controller-processor relationship under Ghana Data Protection Act 2012 (Act 843), Nigeria Data Protection Act 2023, Kenya Data Protection Act 2019, and South Africa POPIA (the four African data protection laws in our active or planned markets).

Each vendor's contract status, including its Data Processing Agreement (DPA), is in the table below. Vendors that will process Protected Health Information (PHI) for medical-adjacent salons will also need a HIPAA Business Associate Agreement (BAA); every one is pending, as the table shows.

2. The vendor list

VendorPurposeData categoriesResidencyContracts
Supabase Inc.

Primary infrastructure. SOC 2 Type II + ISO 27001 certified.

Database (Postgres) + authentication + object storage
  • All personal data
  • Authentication credentials
  • Booking records
  • Payment metadata
AWS eu-west-1 (Ireland)DPA on file; HIPAA BAA (Team plan) pending vendor signature pre-launch (Enterprise Item #29 Phase 2)
Vercel Inc.

Hosts both slotlyy.com (tenant-facing) + ops.slotlyy.com (internal).

Application hosting + CDN + serverless functions
  • Request logs (HTTP headers, IP addresses)
  • Anonymised analytics
AWS multi-region (global edge network)DPA on file; HIPAA BAA (Pro plan) pending vendor signature pre-launch (Enterprise Item #29 Phase 2)
Cloudflare Inc.

sltycdn.net custom domain on R2 serves every tenant asset.

DNS + DDoS protection + R2 object storage + CDN edge cache
  • Static assets (images, logos, staff photos)
  • Request logs (IP, user agent)
Global edge network (250+ POPs)DPA
Paystack Payments Ltd.

PCI-DSS Level 1 certified. Slotlyy never stores raw card data.

Payment processing in Ghana (Nigeria once Slotlyy launches there)
  • Cardholder details (last 4 + expiry only)
  • Mobile money numbers
  • Transaction metadata
Nigeria + UK (Paystack data centers)Merchant Services Agreement + DPA
Flutterwave Inc.

PCI-DSS Level 1 certified. Slotlyy never stores raw card data.

Planned, not yet in use: payment processing for Kenya, South Africa, Uganda, Tanzania, Rwanda, Côte d'Ivoire, Senegal and Cameroon once Slotlyy launches there
  • Cardholder details (last 4 + expiry only)
  • Mobile money numbers
  • Transaction metadata
US + Africa (Flutterwave multi-region)No merchant account yet
Upstash Inc. (QStash)

Reliable delivery via QStash retry queue. Messages auto-expire post-delivery; failed deliveries land in dead-letter queue accessible to ops.

Notification message queue. Every booking confirmation / lapse-cascade / reminder email + SMS + push notification flows through QStash before delivery to the third-party sender.
  • Phone numbers
  • Email addresses
  • Booking reference numbers
  • Notification payload (templated copy)
Global (Upstash multi-region; QStash messages stored ≤ 30 days per Upstash retention default)DPA
Upstash Inc. (Redis)

Keys auto-expire at end of rate-limit window (60s for OTP cooldown, 1h for hourly limits, etc.). Same Upstash account as QStash above; shared DPA.

Rate-limiting buckets (OTP send/verify limits, booking creation limits, admin mutation limits per Bible §60 + SECURITY_CHECKLIST.md §17)
  • Phone numbers and email addresses keying rate-limit buckets (stored as given; they expire with the window)
  • IP addresses keying rate-limit buckets
  • User IDs keying rate-limit buckets
  • NO message content
Global (Upstash multi-region; rate-limit windows ≤ 1 hour per @upstash/ratelimit defaults)DPA
Resend Inc.

No marketing email; transactional only. SPF + DKIM + DMARC configured per `docs/runbooks/email-dns-setup.md`.

Transactional email delivery (booking confirmations, receipts, reminders)
  • Email addresses
  • First name
  • Booking reference numbers
AWS eu-west-1 (Ireland), the sending region of the slotlyy.com domain — Resend infra runs on AWS SESDPA
Arkesel

SMS only. A WhatsApp-first path with 30-second SMS fallback is BUILT BUT DORMANT - the WhatsApp send is commented out pending Arkesel sender approval, so no OTP has ever been delivered over WhatsApp. This list states CURRENT data flows, never planned ones.

SMS OTP + transactional SMS delivery for Ghana
  • Phone numbers
  • 6-digit OTP codes (60-second TTL)
Ghana + NigeriaVendor services agreement + DPA pending
Google LLC (Firebase Cloud Messaging)

No data is sent to Firebase today. Tokens would be stored in the user_devices table.

Planned, not yet in use: push notifications to staff (no device can register yet, register R-340)
  • Device tokens (anonymous)
  • Notification payload
Global (Google Cloud)Google Cloud DPA
Functional Software Inc. (Sentry)

Two separate projects: slotlyy-web + slotlyy-ops. The scrubber in `@slotlyy/sentry-shared` runs on errors, performance traces and spans. It removes phone numbers written in international format (+233…), emails, JWTs, bearer tokens and session cookies, and any value stored under a name such as password or otp. It does not recognise a phone number written in local format (024…) or a password written into free text under no such name. See `apps/web/src/__tests__/sentry-pii-scrub.test.ts`.

Error monitoring + release tracking for apps/web + apps/ops
  • Error stack traces and the breadcrumbs that led to them
  • Performance traces (timings of requests and database calls)
  • Request address, method and query string, with the tokens in booking and review links and known credential fields redacted, and the browser type (User-Agent); cookies, other request headers and request bodies are removed before sending
United States (sentry.io)DPA
PostHog Inc.

Session recording runs only on public salon pages (/b/*) of tenants that are not PHI-bearing, and never on the booking confirmation page or the /booking magic-link routes (per `recordingAllowed()`, applied by `RecordingGate` inside the salon page layout; a salon whose type cannot be read is treated as PHI-bearing). In recordings all text on the page and all typed input are masked, embedded frames (the payment windows) are blocked, and network requests, console output and canvas are never captured. Booking and review tokens are redacted from event properties and page addresses before they are sent (`redactUrlTokens()`); what a recording shows of the page is protected by the masking and blocking, not by that redaction. The session recorder is served from the Slotlyy site itself; no PostHog script is loaded. PostHog browser SDK is initialized with `respect_dnt: true` so users with Do-Not-Track enabled are not tracked.

Product analytics, funnel tracking and session recording of public salon pages (named events only; no autocapture)
  • Page-view and booking-funnel events under a random identifier, with booking and review tokens removed from URLs
  • Session recordings of public salon pages: page layout, clicks and scrolls, with all page text and typed input masked and payment windows blocked
European Union (eu.i.posthog.com — default set in `initPostHog()`, `apps/web/src/lib/analytics/posthog.ts`; operator can override via NEXT_PUBLIC_POSTHOG_HOST env var)DPA
Better Stack (Logtail Inc.)

External HTTP / DNS / SSL probes only; never reads tenant data. See `docs/runbooks/external-monitoring-setup.md`.

External HTTP monitoring + status page
  • Probe target URLs
  • Response status codes
  • Latency measurements — no payload data
United States + Europe (Better Stack multi-region)DPA (free tier — pending paid-tier upgrade)
Smile Identity

Used at tenant onboarding (Starter + Pro/Business plans) per Bible §33.3.A. Raw response retained 7 years per §33.3.6.

KYC verification (ID document + facial biometric check) per Bible §33.3
  • Government ID number (hashed in our DB)
  • Selfie photo (immediately discarded post-verification)
  • Verification outcome
Africa-multi-region (per Smile Identity infra)DPA aligned with Ghana DPA + Nigeria NDPA + Kenya DPA + POPIA (Slotlyy is Africa-only-focus per CLAUDE.md lock 2026-04-24)
Zoho Corporation (Zoho Mail)

Tenant data never flows into Zoho Mail. Used only for internal team comms ([email protected] / [email protected] / etc.). Corrected 2026-09-03: this row previously named Google Workspace, which was never the live mailbox provider — the slotlyy.com apex has always run on Zoho.

Internal email for the Slotlyy team
  • Internal communications
  • No tenant data
Global (Zoho)Zoho DPA
Amazon Web Services Inc. (S3 + KMS)

Not yet provisioned: no Slotlyy data is sent to AWS today. It will be set up per `docs/runbooks/aws-audit-archive-setup.md` (Enterprise Item #1 Commit C).

Planned, not yet in use: write-once archive of audit records, and a separate encryption key for each salon
  • Hash-chained audit log records (`admin_audit_log` + `company_audit_log`), once the archive starts
Planned: AWS us-east-1 (N. Virginia, United States), replicated to us-east-2 (Ohio, United States)AWS BAA (HIPAA) + DPA — pending the AWS account setup before launch (Enterprise Item #1 Commit C)

3. Notice of changes

Slotlyy commits to 30 days' advance notice before adding a new subprocessor to this list. Existing tenants will be notified via in-app banner + email to the account-owner address registered for billing. The window gives covered entities time to assess the new vendor against their own compliance program (HIPAA / DPC registration / etc.) before the change becomes effective.

Material changes to an existing vendor relationship (new data category, new residency, terminated BAA) are treated the same — 30-day advance notice + this page updated with a new version + revision-history entry.

4. How to object to a subprocessor

If you object to a new subprocessor on reasonable grounds (security / compliance / regulatory concern), contact [email protected] within the 30-day notice window. We will work with you in good faith to resolve the concern OR provide a clear notice of inability to do so (which then gives you the right to terminate the affected services per our Terms of Service).

5. Subscribe to updates

The authoritative version of this list lives at slotlyy.com/subprocessor. Material updates trigger an email to the account-owner address; you may opt-out of any non-essential subprocessor- change emails by contacting [email protected] (we cannot opt you out of the material-change emails — those are legally required notification).

Related documents