Legal

Every third party that touches your data.

Last updated · 27 June 2026
The position
Every third party Verdscore relies on to deliver the service, what data each one sees, and where they're located. We commit to 30 days' notice before adding or removing a subprocessor — see the DPA for the objection mechanism.

Current subprocessors

The full list. We'll bump the date at the top whenever it changes.

VendorPurposeData seenLocationCertifications
StripePayment processing + subscription managementEmail, name, billing address, payment card (Stripe-side only)Ireland (EU) + USPCI DSS Level 1 · SOC 1/2 · DPF certified
Hetzner Online GmbHApplication hosting (Postgres + Next.js compute)All application data at rest, encryptedGermany 🇩🇪ISO 27001 · GDPR-native
CloudflareCDN, DNS, WAF, bot protection (Turnstile)Public HTTP traffic metadata (IP, User-Agent, request path)Global (EU + US edge nodes)SOC 2 · ISO 27001 · DPF certified
Google Maps PlatformVenue search + Place Details API (the canonical place_id source)Venue queries + lat/lng (no end-user PII)USISO 27001 · DPF certified
TripAdvisor Content APISource of public restaurant reviews (read-only, via TripAdvisor Developer Program)Venue listing URLs (no end-user PII)USContractual data-processing terms via TripAdvisor Developer Program
AnthropicLLM provider for sentiment scoring + reply draft generationReview text + reviewer display name (transient — not retained for training)USSOC 2 Type 2 · zero-retention API tier · EU SCC (2021/914 Module 2) + Transfer Impact Assessment on file
AWS (Amazon Web Services)Encrypted database + object-storage backupsFull application data (at rest, AES-256 encrypted)eu-central-1 (Frankfurt) 🇩🇪ISO 27001 · SOC 1/2/3 · DPF certified
ResendTransactional email delivery (verification, alerts, receipts)Recipient email + message contentUSSOC 2 · DPF certified

International transfers

Verdscore is operated from the EU. Where a subprocessor stores or processes data outside the EEA, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for transfers to the United States, the EU-US Data Privacy Framework where the subprocessor is certified. The certifications column above shows which framework each one uses.

Data we never share

  • Your password — only the bcrypt hash is stored; the original is never seen by anyone, including us.
  • Your card details — handled directly by Stripe; we only see the subscription state Stripe sends back via webhook.
  • End-user PII to the review-API aggregator — they receive venue place IDs and listing URLs only, never anyone's personal data.
  • Marketing trackers — no Meta Pixel, no TikTok pixel, no LinkedIn Insight Tag. See Cookies.

Notification of changes

We notify signed customers via email at least 30 days before a new subprocessor takes on customer data, or before we remove one. The DPA gives you the right to object; if your objection can't be resolved, you can terminate the affected service without penalty.

Questions about this document? Send me a message — I read every one.
Subprocessors · Verdscore.ai · Verdscore