Service providers and subprocessors
A vendor name is not enough; the processing role and production use must be verified.
The code points to the services below. Contracts, exact legal entities, production enablement, regions, transfer safeguards and retention terms still need to be checked before this becomes a final subprocessor register.
Updated 31 August 2026
Draft status. A review draft: not indexed, and not final until checked by qualified counsel.
01
Which providers are visible in the application?
- Clerk — authentication, account UI and user lifecycle webhooks.
- Vercel — application hosting and deployment; Vercel Blob is used for stored profile media.
- CapyDB-managed Postgres — application and directory database.
- Resend — conditional relay of a connect-request email when the production key is configured.
- Google favicon service — browser-loaded organization favicons, which can disclose the visitor IP and requested domain to Google.
02
Why is this not the final list?
Source-code references do not prove that a service is enabled in production or define its controller/processor role. The production environment, vendor contracts, data flows, hosting locations and international-transfer measures must be reconciled first.
03
How will changes be notified?
A change-notification subscription is not implemented. If FundDaddy relies on general authorization for subprocessors under a customer DPA, it must provide advance notice and a workable objection process before adding or replacing them.