Subprocessors

Version 1.4 — Effective 24 September 2026

TraitMatch Subprocessors
Version 1.4 — Effective 24 September 2026

We use carefully selected service providers (processors) to operate TraitMatch. Categories and current providers:

1. Application API / edge / CDN
• Cloudflare, Inc. — reverse proxy, TLS, CDN, and object storage (R2) for media
• Role: hosting & delivery of API and static assets; media object storage
• Transfers: may involve processing outside the EEA under Cloudflare’s DPA / SCCs

2. Database
• PostgreSQL hosted via our database provider (currently Supabase / managed Postgres)
• Role: account, profile, matching, chat metadata, economy, and related application data
• Transfers: depends on project region; prefer EU regions where configured

3. Authentication & push notifications
• Google LLC / Firebase — Firebase Authentication (e.g. Google Sign-In token verification) and Firebase Cloud Messaging (push)
• Role: auth verification and push delivery
• Transfers: may involve US processing under Google/Firebase DPA / SCCs

4. App distribution & payments (digital goods)
• Google Play (Google LLC) — distribution and billing for subscriptions / consumables
• Role: store distribution; payment processing (we receive purchase tokens / entitlements, not full card numbers)

5. Email / SMS (when enabled)
• Transactional email and SMS OTP providers (named here when live) — account security and support replies

6. Analytics / crash (future)
• Not currently shipped in the production app. If added, they will appear on this list and require cookie/SDK consent where required.

We update this list when processors change. Questions: privacy@traitmatch.app.
Privacy Policy: https://traitmatch.pages.dev/privacy