Subprocessors
Last updated: 21 August 2026
Deuce Creative Limited (trading as Grofomo) uses the providers below to run the platform. This page is the current, canonical list. It is referenced by our Data Processing Addendum as the record of subprocessors we have engaged, and by our Privacy Policy.
Where we process personal data on behalf of an event organiser, these providers are our subprocessors. Where we act as a controller in our own right, they are our processors. The distinction is set out in the Privacy Policy; either way, the list is the same and it is complete.
The three groups below are not interchangeable. Read the note under each heading before treating an entry as something we chose on your behalf.
Platform subprocessors
Engaged by us, and used for every customer. We give notice before adding to this list, and you may object. These are the entries our Data Processing Addendum commits us on.
Supabase
Supabase, Inc.
Primary database, authentication, and file storage. Every record the platform holds lives here.
- Data it can access
- Name, email address, phone number
- Order and ticket records
- Marketing consent records
- Uploaded images, video, and documents
- IP address, device and browser information
- Whose data
- Attendees and ticket buyers, Organiser users, Artists, Volunteers, Suppliers
- Where
- United Kingdom (AWS eu-west-2, London)
- Transfer safeguard
- Not required: processing stays in the UK.
- Their terms
- supabase.com
Data at rest stays in the United Kingdom.
Vercel
Vercel, Inc.
Application hosting. Serves every page, runs every API route, and runs the scheduled jobs.
- Data it can access
- Any personal data contained in a request or response
- IP address, device and browser information
- Request logs
- Whose data
- All categories
- Where
- Pages are served from the London edge. Server functions currently execute in the United States (Washington DC).
- Transfer safeguard
- EU-US Data Privacy Framework (UK Extension), and Standard Contractual Clauses with the UK Addendum
- Their terms
- vercel.com
Function execution is transient. Data is held in memory only for as long as it takes to serve one request, and is written back to the United Kingdom database.
Stripe
Stripe Payments Europe, Ltd. and Stripe, Inc.
Card payments, payment plans, payouts to organisers and artists, and card readers at the door.
- Data it can access
- Name, email address
- Billing address and payment card details
- Transaction amounts and history
- Bank and payout details for organisers and artists
- IP address, device and browser information
- Whose data
- Ticket buyers, Organiser users, Artists, Affiliates
- Where
- Ireland and the United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- stripe.com
Card numbers are captured by Stripe directly in the buyer browser and never reach our servers.
Resend
Resend, Inc.
Sends every email the platform sends: ticket confirmations, receipts, sign-in links, and marketing broadcasts. Also receives replies to platform addresses.
- Data it can access
- Name, email address
- Email content and attachments
- Delivery, bounce, open, and click events
- Whose data
- Attendees and ticket buyers, Organiser users, Artists, Mailing list subscribers
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- resend.com
Where an organiser connects a Resend audience, a contact list of name and email is held at Resend on an ongoing basis rather than only in transit.
Expo
650 Industries, Inc.
Delivers push notifications to the Grofomo mobile app, and builds and distributes app releases.
- Data it can access
- Push notification tokens
- Notification title and body
- App and device version
- Whose data
- Mobile app users
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- expo.dev
Expo issues a token scoped to our project. The underlying Apple or Google device token is never exposed to us.
Cloudflare
Cloudflare, Inc.
Turnstile bot protection on public forms, and content delivery in front of our database provider.
- Data it can access
- IP address, device and browser information
- Bot-detection signals
- Whose data
- Anyone submitting a public form
- Where
- Global edge network, processed at the location nearest the visitor
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- cloudflare.com
IP address is passed to Turnstile deliberately, as an additional signal for telling people apart from bots.
Amazon Web Services
Amazon Web Services EMEA SARL
Renders promotional video and artwork on demand, and stores the rendered output.
- Data it can access
- Artist names and likeness contained in supplied artwork
- Event names and campaign copy
- Whose data
- Artists, Organiser users
- Where
- United Kingdom (eu-west-2, London)
- Transfer safeguard
- Not required: processing stays in the UK.
- Their terms
- aws.amazon.com
Twilio
Twilio Inc.
Supplies a phone number to organisers who do not have a spare one, so they can receive the verification code needed to connect WhatsApp.
- Data it can access
- The phone number we supply to the organiser
- Verification codes sent by Meta to that number
- The forwarding number for voice calls
- Whose data
- Organiser users
- Where
- United States (US1 region)
- Transfer safeguard
- EU-US Data Privacy Framework, and Standard Contractual Clauses with the UK Addendum
- Their terms
- twilio.com
No attendee data reaches Twilio. Conversations with attendees run over WhatsApp through Meta, not over these numbers. If that ever changes, this entry and the DPA annex must be revised before it does.
Google Cloud and Google APIs
Google Ireland Limited
Sign in with Google, Google Wallet passes, Google Maps in the site-map editor, and web fonts on branded pages.
- Data it can access
- Name, email address
- Google account identifier
- Wallet pass contents
- IP address, device and browser information
- Whose data
- Organiser users, Ticket buyers who save a pass, Visitors to branded pages
- Where
- European Union and the United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- cloud.google.com
A Google Wallet pass contains the event name, venue, ticket type, and the ticket reference used as its barcode. It does not contain the holder name or email address.
Apple
Apple Distribution International Ltd.
Sign in with Apple, Apple Wallet passes, and push notification delivery to iOS devices.
- Data it can access
- Name, email address
- Apple account identifier
- Device push tokens
- Whose data
- Organiser users, Mobile app users, Ticket buyers who save a pass
- Where
- Ireland and the United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- apple.com
Apple Wallet passes are built on our own servers and handed to the device. Apple receives the push token used to signal that a pass changed, not the pass contents.
OpenRouter
OpenRouter, Inc.
Routes requests to large language models, used for drafting artist biographies, event copy, and campaign suggestions.
- Data it can access
- Artist name, real name, location, and biography text
- Organiser-authored event and campaign copy
- Whose data
- Artists, Organiser users
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- openrouter.ai
No attendee or ticket-buyer data is sent to any model.
Slack
Salesforce, Inc.
Receives internal operational alerts from the platform.
- Data it can access
- Alert text, which can incidentally contain a record identifier
- Whose data
- Not directed at any category; incidental only
- Where
- United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum
- Their terms
- salesforce.com
Subprocessors engaged by our subprocessors
Engaged by one of the providers above rather than by us. Listed so the whole chain is visible. Changes flow through that provider under its own agreement.
Google, reached through OpenRouter
Google LLC
Provides the model used for structured extraction of artist and event details.
- Data it can access
- Whatever the prompt contains: artist and event copy
- Whose data
- Artists, Organiser users
- Where
- United States
- Transfer safeguard
- Relied on through the OpenRouter agreement
- Their terms
- cloud.google.com
Perplexity, reached through OpenRouter
Perplexity AI, Inc.
Provides the model used to research artists against public web sources.
- Data it can access
- Artist name and the search context supplied with it
- Whose data
- Artists
- Where
- United States
- Transfer safeguard
- Relied on through the OpenRouter agreement
- Their terms
- perplexity.ai
Apple Push Notification service and Firebase Cloud Messaging, reached through Expo
Apple Distribution International Ltd. and Google Ireland Limited
The operating system push networks that carry a notification the last step to a phone.
- Data it can access
- Device push tokens
- Notification payload
- Whose data
- Mobile app users
- Where
- United States
- Transfer safeguard
- Relied on through the Expo agreement
- Their terms
- firebase.google.com
Services you switch on yourself
Reached only because you connected an account, entered a key, or nominated a destination. You control whether these are used at all and you hold the relationship with them, so they sit outside our notice commitment.
Meta WhatsApp Business Platform
Meta Platforms Ireland Limited
Delivers WhatsApp messages between an organiser and their audience, using that organiser own WhatsApp Business account.
- Data it can access
- Recipient phone numbers
- Message content, inbound and outbound
- Whose data
- Attendees who message, or are messaged by, an organiser
- Where
- Ireland and the United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum, held by the organiser with Meta
- Their terms
- whatsapp.com
The organiser owns the WhatsApp Business account and contracts with Meta directly. We act as their technology provider.
Meta Pixel
Meta Platforms Ireland Limited
Measures ticket sales for an organiser own advertising, where that organiser has added their pixel to an event.
- Data it can access
- IP address, device and browser information
- Pages viewed and purchase value
- Meta advertising cookies
- Whose data
- Visitors to that organiser ticket storefront
- Where
- Ireland and the United States
- Transfer safeguard
- Standard Contractual Clauses with the UK Addendum, held by the organiser with Meta
- Their terms
- facebook.com
Off unless the organiser supplies a pixel identifier, and it loads only for a visitor who has accepted analytics cookies.
Social publishing platforms
Meta Platforms Ireland Limited, TikTok Information Technologies UK Limited, X Corp., Google Ireland Limited, and Mixcloud Ltd.
Publishes posts, video, and audio to accounts an organiser has connected: Facebook, Instagram, Threads, TikTok, X, YouTube, and Mixcloud.
- Data it can access
- Post content and media
- The connected account identity and its access token
- Whose data
- Organiser users, Anyone appearing in the media they publish
- Where
- Ireland, the United States, and elsewhere depending on the platform
- Transfer safeguard
- Held by the organiser with each platform under its own terms
- Their terms
- facebook.com
Reaches a platform only where the organiser has explicitly connected their own account.
Webhook endpoints you nominate
Whichever party you nominate
Sends event notifications to a URL an organiser or artist enters, for example their own Slack workspace or internal system.
- Data it can access
- Whatever the notification carries, which can include buyer name and order details
- Whose data
- Attendees and ticket buyers
- Where
- Wherever the nominated endpoint is hosted
- Transfer safeguard
- Your responsibility, as the party choosing the destination
We deliver to the address given. We have no relationship with the recipient and are not in a position to assess it.
Changes to this list
Before we add a platform subprocessor, we will give at least 30 days notice to organisers who have accepted the Data Processing Addendum, by email to the billing address on the account. If you have a reasonable data protection objection, tell us within that period and we will work with you on it. If we cannot resolve it, you may stop using the affected feature or terminate the affected services without penalty.
We may add a subprocessor immediately where it is needed to keep the service running or secure, for example replacing a provider that has failed. We will tell you as soon as we reasonably can afterwards, and the objection right is unchanged.
We do not give notice for services you switch on yourself, because adding one is your decision rather than ours.
Questions
Email privacy@grofomo.com. If you need a countersigned copy of the Data Processing Addendum, or a completed security questionnaire, ask at the same address.