Subprocessor List
Onflay LLC Last updated: [INSERT: Effective Date]
Overview
Onflay LLC ("Onflay") uses third-party service providers ("Sub-processors") to operate the Platform. These Sub-processors may process personal data of Creators, Customers, and other users in connection with the services they provide to Onflay.
This page identifies Onflay's current Sub-processors, their role, the categories of data they process, their location, and the transfer mechanism applicable where data originates from jurisdictions with cross-border transfer restrictions (EU/EEA, UK, Brazil, Dominican Republic).
Onflay reviews and updates this list when Sub-processors are added, changed, or removed. Material changes will be communicated to registered users through the Platform or by email.
For questions about this list or to exercise data subject rights, contact privacy@onflay.com.
Current Sub-processors
Stripe, Inc.
| Field | Details | |---|---| | Headquarters | United States (San Francisco, CA) | | Role | Payment processing (customer payments); creator Connect Express account management; subscription billing; automated sales tax calculation (Stripe Tax); payment dispute management | | Data processed | Customer transaction data; payment event data; creator Connect account identifiers; tax calculation inputs | | Data subject regions served | All regions (global) | | Privacy policy | stripe.com/privacy | | DPA / transfer mechanism (EU/EEA → US) | Stripe's Data Processing Agreement; Standard Contractual Clauses | | DPA / transfer mechanism (UK → US) | Stripe's DPA with UK IDTA addendum | | DPA / transfer mechanism (Brazil → US) | [PLACEHOLDER: Confirm LGPD Art. 33 basis with Stripe and Brazilian counsel] | | DPA / transfer mechanism (DR → US) | [PLACEHOLDER: Confirm LPDP transfer mechanism with Stripe and DR counsel] |
Wise Payments Limited / Wise US Inc.
| Field | Details | |---|---| | Headquarters | United Kingdom (Wise Payments Limited); United States (Wise US Inc.) | | Role | International bank transfer payouts to Creators who elect Wise as their payout method | | Data processed | Creator payout recipient details (account holder name, destination country, currency, Wise recipient identifier) | | Data subject regions served | Creators in countries supported by Wise (LATAM availability subject to Wise's regulatory status per country) | | Privacy policy | wise.com/privacy-policy | | DPA / transfer mechanism (EU/EEA → UK/US) | Wise's DPA; Standard Contractual Clauses | | DPA / transfer mechanism (Brazil → UK/US) | [PLACEHOLDER: Confirm LGPD basis] | | DPA / transfer mechanism (DR → UK/US) | [PLACEHOLDER: Confirm LPDP basis; confirm Wise DR payout availability with Wise] |
Google LLC
| Field | Details | |---|---| | Headquarters | United States | | Role | Google OAuth 2.0 authentication — enables users to sign in with their Google account | | Data processed | Google account identifier; email address (transmitted to Onflay at time of login) | | Data subject regions served | All regions | | Privacy policy | policies.google.com/privacy | | DPA / transfer mechanism (EU/EEA → US) | Google's Data Processing Addendum; Standard Contractual Clauses | | DPA / transfer mechanism (UK → US) | Google's DPA with UK IDTA addendum | | DPA / transfer mechanism (Brazil → US) | [PLACEHOLDER: Confirm LGPD basis] | | DPA / transfer mechanism (DR → US) | [PLACEHOLDER: Confirm LPDP basis] |
Amazon Web Services, Inc. (Simple Email Service)
| Field | Details | |---|---| | Headquarters | United States | | Role | Transactional email delivery — purchase receipts, payout notifications, account communications, system alerts | | Data processed | Recipient email addresses; email content (transaction details, payout amounts, account notices) | | Primary processing region | US-East-1 (Virginia) | | Data subject regions served | All regions | | Privacy policy | aws.amazon.com/privacy | | DPA / transfer mechanism (EU/EEA → US) | AWS Data Processing Addendum; Standard Contractual Clauses | | DPA / transfer mechanism (UK → US) | AWS DPA with UK IDTA addendum | | DPA / transfer mechanism (Brazil → US) | [PLACEHOLDER: Confirm LGPD basis] | | DPA / transfer mechanism (DR → US) | [PLACEHOLDER: Confirm LPDP basis] |
PostHog, Inc.
| Field | Details | |---|---| | Headquarters | United States | | Role | Product analytics — event tracking, session recordings (input fields masked in payment-adjacent areas), usage metrics | | Data processed | Page views; click events; session recordings (masked); device and browser metadata; user identifiers | | Processing region | US Cloud (default); EU Cloud available but not confirmed as active | | Data subject regions served | All regions | | Privacy policy | posthog.com/privacy | | DPA / transfer mechanism (EU/EEA → US) | PostHog's DPA; Standard Contractual Clauses | | DPA / transfer mechanism (UK → US) | PostHog's DPA with UK addendum | | DPA / transfer mechanism (Brazil → US) | [PLACEHOLDER: Confirm LGPD basis; consider routing BR users through PostHog EU Cloud] | | DPA / transfer mechanism (DR → US) | [PLACEHOLDER: Confirm LPDP basis] | | Cookie / consent note | PostHog sets analytics cookies. These require consent in EU/UK jurisdictions. LATAM consent requirements vary; see Cookie Notice. |
Cloud Hosting Provider
| Field | Details | |---|---| | Headquarters | [PLACEHOLDER: Confirm primary cloud hosting provider — Railway, Vercel, or other] | | Role | Application hosting — API, web apps, admin, checkout, landing, mobile infrastructure | | Data processed | All data transiting Onflay's application layer, including user credentials, transaction data, and application logs | | Processing region | [PLACEHOLDER: Confirm primary hosting region] | | Privacy policy | [PLACEHOLDER: Link to provider's privacy policy] | | DPA / transfer mechanism | [PLACEHOLDER: Confirm DPA and transfer mechanism with provider] |
Object Storage Provider
| Field | Details | |---|---| | Headquarters | [PLACEHOLDER: Confirm storage provider — Cloudflare R2, AWS S3, or other] | | Role | Object storage — creator-uploaded files, product assets, digital content delivery | | Data processed | Creator-uploaded files and associated metadata; customer-download records | | Processing region | [PLACEHOLDER: Confirm storage region(s)] | | Privacy policy | [PLACEHOLDER: Link to provider's privacy policy] | | DPA / transfer mechanism | [PLACEHOLDER: Confirm DPA and transfer mechanism with provider] |
Sub-processor Change Process
When Onflay adds, replaces, or removes a Sub-processor that processes personal data, Onflay will:
- Update this page with the effective date of the change.
- Provide registered Creators with advance notice through the Platform or by email.
- Afford Creators who have executed a DPA the opportunity to object to new Sub-processors on reasonable data protection grounds, as described in the DPA.
Contact
For questions about this Sub-processor List:
Onflay LLC — Privacy 1021 E Lincolnway, Suite 10028 Cheyenne, Wyoming 82001 United States Email: privacy@onflay.com