Sub-processors

Version 2026-06-24-gdpr-readiness · Last updated 24 June 2026

Last updated: 24 June 2026

This page lists the sub-processors that Perkstar Ltd ("Perkstar") engages to provide the Perkstar platform. It forms part of, and is incorporated by reference into, our Data Processing Agreement.

We engage two categories of third party. Sub-processors of Customer Personal Data process operator or cardholder personal data on Perkstar's behalf and are subject to written data processing terms no less protective than our DPA. Service providers support our internal operations and do not process Customer Personal Data; they are listed for transparency.

Some integrations are operator-enabled. If an Operator does not connect a POS, booking, delivery, marketplace, advertising or analytics integration, that integration partner does not receive Customer Personal Data for that Operator through Perkstar.

If you have any questions, email privacy@perkstar.co.uk.

1. Sub-processors of Customer Personal Data

Stored in the UK or EEA (no cross-border transfer mechanism required)

Sub-processorPurposeRegionData processed
Supabase (Supabase Inc.)PostgreSQL database hosting, operator authenticationEU – Ireland (AWS eu-west-1)Operator accounts, cardholder records, loyalty events, consent/audit records, integration configuration
Vercel (Vercel Inc.)Platform hosting and server-side renderingEU – Frankfurt (fra1) for SSR; global edge for static and image assetsRequest metadata (IP, User-Agent, path), rendered pages, cached static assets
Resend (Resend, Inc.)Transactional and marketing email deliveryEU – IrelandRecipient email address, sender domain, message body, delivery metadata
Upstash (Upstash Inc.)Redis-backed rate limiting on public endpointsEU – IrelandRequester IP addresses as part of short-TTL rate-limit keys

Transferred outside the UK or EEA (covered by UK IDTA or EU SCCs + UK Addendum where required)

Sub-processorPurposeRegionData processed
Stripe (Stripe, Inc.)Subscription billing; Stripe Connect operator checkouts; identity verification; cardholder payment checkouts where an Operator sells paid cards, memberships, gift cards, tickets or multipassesUnited States / global infrastructureOperator and cardholder name, email, billing address, payment metadata, identity verification metadata. Card numbers go directly to Stripe and are never seen by Perkstar.
Apple (Apple Inc.)Apple Wallet pass distribution and push to iOS devicesUnited States / global infrastructurePass content (name, balance, dates, organisation name), pass serial numbers, device push tokens
Google (Google LLC)Google Wallet pass distribution and push to Android devices; Google Places lookup for Operator locations; Google Analytics server-side measurement only where the Operator configures it and the Cardholder consentsUnited States / global infrastructurePass content, pass serial numbers, device push tokens, operator location search data, consented analytics event metadata
Telnyx (Telnyx LLC)SMS deliveryUnited States / global telecom routingRecipient phone number, sender ID, message body, delivery metadata
Inngest (Inngest Inc.)Background job queue (wallet pass refresh, scheduled notifications, expiry reminders, sync jobs)United StatesInternal job payloads, system identifiers, and the minimum personal data needed for the queued task
Operator-enabled POS, booking, delivery and marketplace integration partnersLoyalty integration with the Operator's external systems, where the Operator opts inVaries by partner — see list belowCustomer reference IDs, transaction events, appointment or booking attendance, order and redemption metadata, loyalty redemptions

Operator-enabled integration partners currently supported or surfaced in the product: Square, Shopify, Toast, Lightspeed, Clover, Acuity Scheduling, Mindbody, Deliveroo, Dojo, EPOS Now, Access EPoS, MX POS, Poynt and NCR Aloha Cloud. Additional partners are added from time to time and announced via the change-notification process in clause 5 of the DPA.


2. Service providers (no Customer Personal Data)

These vendors support Perkstar's operations but do not process Customer Personal Data as Perkstar sub-processors in the ordinary production flow described above.

Service providerPurposeRegionNotes
Anthropic (Anthropic, PBC)AI assistance for operator-facing copywriting (email subject and body, push notifications, card descriptions, signup wizard, copy rewriting, reward recommendations)United StatesInputs are limited to operator-authored copy and business metadata (industry, card type, programme configuration). Customer merge tokens such as {firstName} are sent as literal placeholder strings and expanded by Perkstar's templating engine at send time, after Anthropic returns the template. No cardholder personal data is sent to Anthropic in production.
Sentry (Functional Software, Inc.)Error monitoring and exception reportingUnited StatesOperator and cardholder personal data (email, phone, IP, postcode, date of birth, names, Stripe identifiers) is stripped from events by a beforeSend hook before any payload reaches Sentry's ingest.
Meta / TikTok / Google AnalyticsOperator-configured advertising or analytics measurementUnited States / global infrastructureNot enabled by default. Used only when the Operator configures the relevant measurement and the Cardholder has given separate ad/analytics tracking consent. In that case the recipient acts on the Operator's measurement instructions, not as a default Perkstar sub-processor for every Operator.

If Perkstar were to expand the use of any service provider in a way that would cause it to process Customer Personal Data as Perkstar's sub-processor, it would be added to Section 1 of this register, and operators would receive at least 30 days' prior notice in accordance with clause 5 of the DPA.


3. Changes to this list

When Perkstar adds, removes, or replaces a sub-processor in Section 1, we will:

  • update this page;
  • where the change is material (a new sub-processor or a change in category of data processed), publish an in-app announcement and, on request to privacy@perkstar.co.uk, send a copy by email; and
  • give operators the right to object in accordance with clause 5 of the DPA.

For sub-processor change notifications by email, operators may subscribe at any time by emailing privacy@perkstar.co.uk. Operators should also review this page before enabling a new integration because operator-enabled partners only receive data for accounts that connect them.

Questions? Email hello@perkstar.co.uk.