Sub-processors
Version 2026-06-24-gdpr-readiness · Last updated 24 June 2026
Last updated: 24 June 2026
This page lists the sub-processors that Perkstar Ltd ("Perkstar") engages to provide the Perkstar platform. It forms part of, and is incorporated by reference into, our Data Processing Agreement.
We engage two categories of third party. Sub-processors of Customer Personal Data process operator or cardholder personal data on Perkstar's behalf and are subject to written data processing terms no less protective than our DPA. Service providers support our internal operations and do not process Customer Personal Data; they are listed for transparency.
Some integrations are operator-enabled. If an Operator does not connect a POS, booking, delivery, marketplace, advertising or analytics integration, that integration partner does not receive Customer Personal Data for that Operator through Perkstar.
If you have any questions, email privacy@perkstar.co.uk.
1. Sub-processors of Customer Personal Data
Stored in the UK or EEA (no cross-border transfer mechanism required)
| Sub-processor | Purpose | Region | Data processed |
|---|---|---|---|
| Supabase (Supabase Inc.) | PostgreSQL database hosting, operator authentication | EU – Ireland (AWS eu-west-1) | Operator accounts, cardholder records, loyalty events, consent/audit records, integration configuration |
| Vercel (Vercel Inc.) | Platform hosting and server-side rendering | EU – Frankfurt (fra1) for SSR; global edge for static and image assets | Request metadata (IP, User-Agent, path), rendered pages, cached static assets |
| Resend (Resend, Inc.) | Transactional and marketing email delivery | EU – Ireland | Recipient email address, sender domain, message body, delivery metadata |
| Upstash (Upstash Inc.) | Redis-backed rate limiting on public endpoints | EU – Ireland | Requester IP addresses as part of short-TTL rate-limit keys |
Transferred outside the UK or EEA (covered by UK IDTA or EU SCCs + UK Addendum where required)
| Sub-processor | Purpose | Region | Data processed |
|---|---|---|---|
| Stripe (Stripe, Inc.) | Subscription billing; Stripe Connect operator checkouts; identity verification; cardholder payment checkouts where an Operator sells paid cards, memberships, gift cards, tickets or multipasses | United States / global infrastructure | Operator and cardholder name, email, billing address, payment metadata, identity verification metadata. Card numbers go directly to Stripe and are never seen by Perkstar. |
| Apple (Apple Inc.) | Apple Wallet pass distribution and push to iOS devices | United States / global infrastructure | Pass content (name, balance, dates, organisation name), pass serial numbers, device push tokens |
| Google (Google LLC) | Google Wallet pass distribution and push to Android devices; Google Places lookup for Operator locations; Google Analytics server-side measurement only where the Operator configures it and the Cardholder consents | United States / global infrastructure | Pass content, pass serial numbers, device push tokens, operator location search data, consented analytics event metadata |
| Telnyx (Telnyx LLC) | SMS delivery | United States / global telecom routing | Recipient phone number, sender ID, message body, delivery metadata |
| Inngest (Inngest Inc.) | Background job queue (wallet pass refresh, scheduled notifications, expiry reminders, sync jobs) | United States | Internal job payloads, system identifiers, and the minimum personal data needed for the queued task |
| Operator-enabled POS, booking, delivery and marketplace integration partners | Loyalty integration with the Operator's external systems, where the Operator opts in | Varies by partner — see list below | Customer reference IDs, transaction events, appointment or booking attendance, order and redemption metadata, loyalty redemptions |
Operator-enabled integration partners currently supported or surfaced in the product: Square, Shopify, Toast, Lightspeed, Clover, Acuity Scheduling, Mindbody, Deliveroo, Dojo, EPOS Now, Access EPoS, MX POS, Poynt and NCR Aloha Cloud. Additional partners are added from time to time and announced via the change-notification process in clause 5 of the DPA.
2. Service providers (no Customer Personal Data)
These vendors support Perkstar's operations but do not process Customer Personal Data as Perkstar sub-processors in the ordinary production flow described above.
| Service provider | Purpose | Region | Notes |
|---|---|---|---|
| Anthropic (Anthropic, PBC) | AI assistance for operator-facing copywriting (email subject and body, push notifications, card descriptions, signup wizard, copy rewriting, reward recommendations) | United States | Inputs are limited to operator-authored copy and business metadata (industry, card type, programme configuration). Customer merge tokens such as {firstName} are sent as literal placeholder strings and expanded by Perkstar's templating engine at send time, after Anthropic returns the template. No cardholder personal data is sent to Anthropic in production. |
| Sentry (Functional Software, Inc.) | Error monitoring and exception reporting | United States | Operator and cardholder personal data (email, phone, IP, postcode, date of birth, names, Stripe identifiers) is stripped from events by a beforeSend hook before any payload reaches Sentry's ingest. |
| Meta / TikTok / Google Analytics | Operator-configured advertising or analytics measurement | United States / global infrastructure | Not enabled by default. Used only when the Operator configures the relevant measurement and the Cardholder has given separate ad/analytics tracking consent. In that case the recipient acts on the Operator's measurement instructions, not as a default Perkstar sub-processor for every Operator. |
If Perkstar were to expand the use of any service provider in a way that would cause it to process Customer Personal Data as Perkstar's sub-processor, it would be added to Section 1 of this register, and operators would receive at least 30 days' prior notice in accordance with clause 5 of the DPA.
3. Changes to this list
When Perkstar adds, removes, or replaces a sub-processor in Section 1, we will:
- update this page;
- where the change is material (a new sub-processor or a change in category of data processed), publish an in-app announcement and, on request to privacy@perkstar.co.uk, send a copy by email; and
- give operators the right to object in accordance with clause 5 of the DPA.
For sub-processor change notifications by email, operators may subscribe at any time by emailing privacy@perkstar.co.uk. Operators should also review this page before enabling a new integration because operator-enabled partners only receive data for accounts that connect them.
Questions? Email hello@perkstar.co.uk.