Legal
Sub-processors
Last updated
Running checks from four continents means customer data touches several vendors. This page names every one of them. It is referenced by the privacy policy and forms part of any data processing agreement we sign.
Vendors every account uses
| Vendor | What it does | Data it can see | Where |
|---|---|---|---|
| Supabase | Authentication and the primary PostgreSQL database | Account email, credentials, monitor configuration, incident history, encrypted integration keys | Managed Supabase cloud; region not yet published |
| Vercel | Hosting for the web app and API | Everything you send to or read from the app, plus request logs | United States, with a global edge network |
| Hetzner Online GmbH | ClickHouse time-series storage for check results | Monitor names and target URLs, response times, status codes, error messages | Nuremberg, Germany |
| Fly.io | Probe workers that perform the checks | Monitor target URLs and the results of checking them | Ashburn Virginia, San Jose, Stockholm, and Tokyo |
| Resend | Transactional and alert email delivery | Recipient email addresses, monitor names, incident details | Ireland, with administrative access from the United States |
| PostHog | Product analytics inside the app | Account ID, email, name, and in-app product events | European Union |
| Sentry | Error and performance monitoring | Scrubbed error events and stack traces; personal data is not sent by default | United States |
| Google Analytics | Marketing-site traffic measurement | Pseudonymous visitor identifiers and page views on public pages | United States |
Vendors only used if you connect them
These receive data because you configured an integration pointing at them. If you connect none of them, none of your data reaches them.
| Vendor | What it does | Data it can see | Where |
|---|---|---|---|
| PagerDuty | On-call paging, when you connect a PagerDuty integration | Monitor names and incident details routed to your PagerDuty service | Determined by your PagerDuty account |
| Slack | Channel alerts, when you connect a Slack integration | Monitor names and incident details posted to your channel | Determined by your Slack workspace |
| Your webhook endpoints | Custom alert delivery, when you configure a webhook | Whatever the alert payload contains, sent to the URL you supply | Wherever you host the endpoint |
Changes to this list
We will update this page before a new sub-processor starts handling customer data, and we will email account holders when the change is material — a new vendor holding account or monitor data, or an existing one moving to a different region. Swapping a vendor for one that sees strictly less is not material, but it will still show up here.
If a new sub-processor is a problem for you, tell us at getpulsecheck@gmail.com and we will work out what to do, including closing your account and deleting your data if that is what you want.