We use cookies

We use analytics to see how CheckInOS is used and make it better. Nothing runs unless you accept — see our Cookie Policy for details.

SUBPROCESSOR LIST

Last updated September 7, 2026

This page lists third parties involved in delivering CheckInOS services. The Added column shows when a vendor was first engaged for the listed role. Status shows whether the vendor is currently used for that role. Material changes are reflected by updating this page and the date above. Material changes are also notified by email or in-product notice to organizers where practicable. Organizers may object to new subprocessors as described in our Data Processing Agreement.

Current vendor list

VendorRoleService functionData categoriesRegion / transfersSafeguardsAddedStatus
Supabase (PostgreSQL)SubprocessorPrimary application databaseAccount, organization, event, attendee, ticketing, check-in, billing referencesEU project region; limited operational access may involve transfersContractual transfer safeguards where required2024-06-01Active
Upstash (Redis)SubprocessorShort-lived cache and OAuth/API token stateTemporary tokens, session-related cache valuesEU region where configuredContractual transfer safeguards where required2024-09-01Active
ResendSubprocessorTransactional email (tickets, OTP, invitations, support)Email addresses, message content, attachmentsEU-oriented configuration; provider operations may involve transfersContractual transfer safeguards where required2024-06-01Active
StripeSubprocessor / independent controller (payments)Platform subscriptions, Stripe Connect ticketing payouts, webhooksPayment identifiers, checkout metadata, connected account KYC dataGlobal payment infrastructureStripe DPA and applicable transfer mechanisms2025-01-01Active
VercelSubprocessorApplication hosting and build/deploy pipelineRequest metadata, hosting and deployment diagnosticsEU region where configured; global operations possibleContractual transfer safeguards where required2024-06-01Active
Google Identity (OAuth)Independent controllerOptional sign-inName, email, provider identifiersProvider global infrastructureGoogle terms and transfer mechanisms2024-06-01Active
Microsoft Entra ID (OAuth)Independent controllerOptional sign-inName, email, provider identifiersProvider global infrastructureMicrosoft terms and transfer mechanisms2024-06-01Active
Apple (Sign in + Wallet)Independent controllerSign in with Apple; Apple Wallet passes when enabled for ticketsName, email (if shared), provider identifiers; pass metadata when Wallet is usedProvider global infrastructureApple terms and transfer mechanisms2024-11-01Active (Wallet when feature enabled)
PostHog (EU Cloud)SubprocessorOpt-in website and product analytics — page views and usage events only, no session replay or heatmapsPage URLs, event names, device/browser metadata, pseudonymous analytics identifierEU Cloud (eu.posthog.com / eu.i.posthog.com)Only loads after visitor consent; contractual transfer safeguards where required2026-09-07Active

Notes

Apple Wallet pass generation, when enabled, uses certificates configured by CheckInOS; pass delivery may involve Apple systems under Apple's terms.

For questions or subprocessor objections, contact events@checkinos.com.