Back
Home Apps and Plans App bundles Help Center Sign In
EN | ES
Zendrhax
Back Home Apps and Plans App bundles Help Center Sign In
Legal Center › Sub-processors

Sub-processors

Last reviewed: 2026-07-21 · Version: 2026-07-21.1

A "sub-processor" is any third party that processes personal data on our behalf to help us run the Service. Each one operates under a written contract that mirrors the obligations we owe you under the Data Processing Agreement and the Privacy Policy.

Below is the current list. We update this page at least 14 days before adding or replacing a sub-processor — see the notification clause in our DPA.

#Active sub-processors

ProviderServiceWhere data is processedCustomer data handled
Stripe, Inc.Payment processing for platform subscriptions and Invoices app payment linksUnited States (with EU/UK sub-processors per Stripe's own DPA)Billing identifiers, payment method tokens, charge amounts, invoice metadata. Card numbers and CVCs never touch our servers — they go directly to Stripe.
Hostinger International Ltd.Application hosting and outbound SMTP relay (smtp.hostinger.com)European Union and United States data centresAll hosted application data while at rest; outbound email message bodies and addresses while in transit.
Cloudflare, Inc. (Turnstile)Bot-challenge verification on /registerCloudflare's global network; see its Turnstile Privacy AddendumSignals used for challenge verification can include IP address, TLS fingerprint, user agent, sitekey, and originating site. Cloudflare processes those signals to provide Turnstile and acts independently for the limited purpose of improving its bot-detection systems, as described in its addendum.
Google LLC (Firebase Cloud Messaging)Push-notification delivery to the native mobile apps (Cleaning, Invoices)United States and global Google infrastructureThe device push token and the notification payload (title/body) at delivery time. Used only to route notifications to the user's own device.
Functional Software, Inc. dba Sentry (active only when the operator configures SENTRY_DSN)Application error trackingUnited States and GermanyStack traces, request metadata, the authenticated user id when an error occurs. Payload bodies are scrubbed before being sent.

#How we choose sub-processors

Before we add a sub-processor we check that they:

  • Publish a current SOC 2 Type II report, ISO 27001 certification, or an equivalent independent attestation.
  • Sign a written data-processing agreement aligned with GDPR Article 28 and the Standard Contractual Clauses where personal data leaves the EEA/UK.
  • Document their own sub-processors and notification practice.

#Notifications of changes

For Customers covered by the DPA, notices are sent by the operator to the registered account email at least 14 days before an addition or replacement, allowing time to object. Keep that account address current and contact legal@zendrhax.com with questions.

#What if I object to a sub-processor

Under the DPA, if you object in writing within the notice period and we cannot agree on a resolution, you may terminate the affected portion of the Service and receive a pro-rated refund of any prepaid fees for the unused remainder of the term.

#Historical changes

DateChange
Initial publicationStripe, Hostinger, Cloudflare Turnstile, and Sentry registered as sub-processors.
2026-07-07Google LLC (Firebase Cloud Messaging) added — powers push notifications for the native mobile apps.

We will append a line here every time the active list changes.

#Contact

  • Sub-processor questions and objection notices — legal@zendrhax.com
  • Privacy questions — privacy@zendrhax.com
← Back to Legal Center Need a signed counterpart or have a legal question? Reach us at Contact.
Privacy Policy · Terms of Service · Legal Center · Help Center
© 2026 Zendrhax · All rights reserved