Legal
Every third party that touches your data.
Last updated · 27 June 2026
The position
Every third party Verdscore relies on to deliver the service, what data each one sees, and where they're located. We commit to 30 days' notice before adding or removing a subprocessor — see the DPA for the objection mechanism.
Current subprocessors
The full list. We'll bump the date at the top whenever it changes.
| Vendor | Purpose | Data seen | Location | Certifications |
|---|---|---|---|---|
| Stripe | Payment processing + subscription management | Email, name, billing address, payment card (Stripe-side only) | Ireland (EU) + US | PCI DSS Level 1 · SOC 1/2 · DPF certified |
| Hetzner Online GmbH | Application hosting (Postgres + Next.js compute) | All application data at rest, encrypted | Germany 🇩🇪 | ISO 27001 · GDPR-native |
| Cloudflare | CDN, DNS, WAF, bot protection (Turnstile) | Public HTTP traffic metadata (IP, User-Agent, request path) | Global (EU + US edge nodes) | SOC 2 · ISO 27001 · DPF certified |
| Google Maps Platform | Venue search + Place Details API (the canonical place_id source) | Venue queries + lat/lng (no end-user PII) | US | ISO 27001 · DPF certified |
| TripAdvisor Content API | Source of public restaurant reviews (read-only, via TripAdvisor Developer Program) | Venue listing URLs (no end-user PII) | US | Contractual data-processing terms via TripAdvisor Developer Program |
| Anthropic | LLM provider for sentiment scoring + reply draft generation | Review text + reviewer display name (transient — not retained for training) | US | SOC 2 Type 2 · zero-retention API tier · EU SCC (2021/914 Module 2) + Transfer Impact Assessment on file |
| AWS (Amazon Web Services) | Encrypted database + object-storage backups | Full application data (at rest, AES-256 encrypted) | eu-central-1 (Frankfurt) 🇩🇪 | ISO 27001 · SOC 1/2/3 · DPF certified |
| Resend | Transactional email delivery (verification, alerts, receipts) | Recipient email + message content | US | SOC 2 · DPF certified |
International transfers
Verdscore is operated from the EU. Where a subprocessor stores or processes data outside the EEA, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for transfers to the United States, the EU-US Data Privacy Framework where the subprocessor is certified. The certifications column above shows which framework each one uses.
Data we never share
- Your password — only the bcrypt hash is stored; the original is never seen by anyone, including us.
- Your card details — handled directly by Stripe; we only see the subscription state Stripe sends back via webhook.
- End-user PII to the review-API aggregator — they receive venue place IDs and listing URLs only, never anyone's personal data.
- Marketing trackers — no Meta Pixel, no TikTok pixel, no LinkedIn Insight Tag. See Cookies.
Notification of changes
We notify signed customers via email at least 30 days before a new subprocessor takes on customer data, or before we remove one. The DPA gives you the right to object; if your objection can't be resolved, you can terminate the affected service without penalty.
Questions about this document? Send me a message — I read every one.