LEGAL
Sub-processors
Last updated: 10 August 2026
Sprint Buddy uses a small number of vetted providers (sub-processors) to run the Service. Each one is bound by data protection terms no less protective than our DPA, and we remain fully responsible for their performance. This page always reflects the current list.
Infrastructure & data
| Provider | Purpose | Data processed | Processing location |
|---|---|---|---|
| Supabase | Managed database, storage and backend infrastructure | Account data, workspace and project data, encrypted integration tokens, logs | EU (Frankfurt, Germany) |
| Cloudflare | Application hosting, CDN delivery and DDoS protection | IP address, request metadata, technical logs | Global edge network (EU-first routing; SCCs) |
Supabase
- Purpose:
- Managed database, storage and backend infrastructure
- Data processed:
- Account data, workspace and project data, encrypted integration tokens, logs
- Processing location:
- EU (Frankfurt, Germany)
Cloudflare
- Purpose:
- Application hosting, CDN delivery and DDoS protection
- Data processed:
- IP address, request metadata, technical logs
- Processing location:
- Global edge network (EU-first routing; SCCs)
Authentication
| Provider | Purpose | Data processed | Processing location |
|---|---|---|---|
| Supabase Auth | Sign-in, sessions and identity management | Email address, user identifiers, session and security events | EU (Frankfurt, Germany) |
| Google (Sign in with Google) | Optional social sign-in, only if you choose it | Email address, name, profile picture, Google account identifier | United States (adequacy / SCCs) |
| Atlassian | Jira integration via OAuth 2.0, only where you connect it | OAuth tokens, Jira user identifier, issue and sprint data | EU / United States (SCCs) |
Supabase Auth
- Purpose:
- Sign-in, sessions and identity management
- Data processed:
- Email address, user identifiers, session and security events
- Processing location:
- EU (Frankfurt, Germany)
Google (Sign in with Google)
- Purpose:
- Optional social sign-in, only if you choose it
- Data processed:
- Email address, name, profile picture, Google account identifier
- Processing location:
- United States (adequacy / SCCs)
Atlassian
- Purpose:
- Jira integration via OAuth 2.0, only where you connect it
- Data processed:
- OAuth tokens, Jira user identifier, issue and sprint data
- Processing location:
- EU / United States (SCCs)
AI processing
| Provider | Purpose | Data processed | Processing location |
|---|---|---|---|
| Lovable AI Gateway (Google Gemini models) | AI-generated summaries, retrospectives, reports and story drafts | Prompt content you submit or sync: issue text, notes, transcripts | EU / United States (SCCs). Content is not used to train models. |
Lovable AI Gateway (Google Gemini models)
- Purpose:
- AI-generated summaries, retrospectives, reports and story drafts
- Data processed:
- Prompt content you submit or sync: issue text, notes, transcripts
- Processing location:
- EU / United States (SCCs). Content is not used to train models.
Billing & communication
| Provider | Purpose | Data processed | Processing location |
|---|---|---|---|
| Stripe | Payment and subscription processing | Billing email, subscription status, payment metadata (no card data reaches us) | EU / United States (SCCs) |
| Resend | Transactional and authentication emails | Email address, message content and delivery metadata | EU / United States (SCCs) |
Stripe
- Purpose:
- Payment and subscription processing
- Data processed:
- Billing email, subscription status, payment metadata (no card data reaches us)
- Processing location:
- EU / United States (SCCs)
Resend
- Purpose:
- Transactional and authentication emails
- Data processed:
- Email address, message content and delivery metadata
- Processing location:
- EU / United States (SCCs)
Changes to this list
We give reasonable notice before adding or replacing a sub-processor. Customers may object on reasonable data protection grounds; if we cannot resolve the objection, the affected subscription may be terminated. To receive notifications about changes, email privacy@sprintbuddy.app.
Questions about sub-processors: privacy@sprintbuddy.app