Subprocessors
The third parties that process personal data on Salaaz's behalf, what each one does, and where the processing happens. Read alongside the Privacy Policy.
Subprocessors current as of May 22, 2026.
Why this list exists
Salaaz's promise is that you can know where things come from. Holding vendors to supply-chain disclosure while withholding which companies handle your password would be the kind of asymmetry the platform rejects. So we publish the list.
We notify account holders at least thirty days before adding a new subprocessor that processes account or order data, except where law requires immediate engagement (for example, a fraud response that requires onboarding a security vendor without delay).
Current subprocessors
| Subprocessor | Purpose | Data processed | Processing region |
|---|---|---|---|
| Clerk | Authentication, sessions, password reset, MFA | Email, password hash, session token, device metadata | United States |
| Square | Card payment processing | Card token, billing address, order total | United States |
| Mixpanel | Product analytics (opt-in) | Pseudonymous event data, IP-anonymized | United States |
| Google Analytics 4 | Platform analytics (opt-in) | Pseudonymous event data, IP-anonymized | United States, EU |
| Beehiiv | Editorial newsletter delivery | Email, subscription preferences | United States |
| OpenStreetMap Nominatim | Address autocomplete at checkout | Query string (not associated with Salaaz identity) | Germany (OSMF) |
Transfers outside Canada
Some subprocessors process data outside Canada. For transfers from the EU/UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum), supplemented by encryption in transit and at rest, role-based access controls, and contractual commitments from each subprocessor.
How we choose subprocessors
- Each subprocessor signs a Data Processing Agreement that binds them to GDPR Art 28 obligations.
- Each must support security baselines: encryption in transit (TLS 1.2+), encryption at rest, access logging, and timely breach notification.
- We prefer providers with independent attestation (SOC 2 Type II, ISO 27001) where the function justifies the cost.
- We do not engage subprocessors whose business model conflicts with the platform's no-paid-ranking commitment (advertising networks, retargeting platforms).
When this list changes
Adding, replacing, or removing a subprocessor that processes account or order data triggers a 30-day notice to account holders. We update the "as of" date at the top of this page on every change so the freshness is visible. Past versions of this list can be requested by email.
Contact
Questions about subprocessors
general@salaaz.com