Sub-Processors
Last updated: August 11, 2026
About this list
OpenBoxes Solutions LLC engages the third-party service providers listed below ("Sub-Processors") to process Customer Personal Data in connection with the operation of OpenBoxes Lift. This list is incorporated by reference into our Data Processing Agreement and is referenced in our Privacy Policy.
We commit to providing at least 30 days' advance notice of any new Sub-Processor that processes Customer Personal Data. Notice is provided by updating this page and, for Customers who have subscribed to notifications, by email.
Each Sub-Processor is bound by a written data-processing agreement imposing data-protection obligations substantially equivalent to those in our DPA. We remain accountable for each Sub-Processor's processing of Customer Personal Data.
Current sub-processor list
| Sub-Processor | Purpose | Data categories | Location |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure: compute, managed Kubernetes, storage, networking, container registry. Hosts the entire OpenBoxes Lift production environment. | All Customer Personal Data and Customer Tenant Data (encrypted at rest). | United States — us-east1 region |
| Stripe, Inc. | Payment processing: subscription billing, payment method tokenization, invoice generation, tax calculation (Stripe Tax for US + CA jurisdictions), dunning. | Account holder name, email, billing address, payment card or bank account details (Stripe stores card numbers in their PCI-DSS Level 1 vault; bank account and routing numbers are entered in Stripe-hosted frames, including the Financial Connections bank-login modal; OpenBoxes only stores tokenized references, the institution name, and last-4 digits), billing history. | United States |
| Sentry (Functional Software, Inc.) | Application error tracking and performance monitoring. Captures unhandled exceptions and selected log events for debugging. | Account holder email and user ID (in error context), browser and OS information, IP address (scrubbed where feasible), stack traces. We configure Sentry to scrub personal data fields where practical. | United States |
| FullStory, Inc. | Session replay and product analytics: records how visitors use the marketing website (consent-gated) and how signed-in customers use the customer portal, so we can find and fix usability problems. | Session recordings (pages viewed, mouse movement, clicks, scrolling, form interactions), device and browser information, IP address, account identifier for portal sessions (never email address). Payment card and bank account fields are entered in Stripe-hosted frames (including the Financial Connections bank-login modal) FullStory cannot see. | United States — na1 data center |
| Mailpit / SMTP relay (transactional email) | Delivery of transactional email: account verification, billing notifications, password reset, security alerts, lifecycle emails (trial reminders, payment receipts, dunning notices, renewal notices). | Recipient email address, recipient name, message content (typically includes account-related context such as tenant subdomain, invoice amount, trial end date). | United States |
| GitHub, Inc. | Source code hosting, container registry, and CI/CD execution. No production Customer Personal Data is stored in source repositories; build logs may include redacted error excerpts. | No Customer Personal Data is intentionally processed. Build logs may incidentally include redacted snippets in case of build-time errors. | United States |
| Keycloak (self-hosted) | Identity provider for customer portal authentication. Hosted on the same Google Cloud infrastructure listed above; included here for transparency about the role and the data it holds. | Account holder name, email, password hash, multi-factor authentication credentials (TOTP secrets), session tokens. | United States — us-east1 region (same as primary infrastructure) |
How we notify of changes
When we engage a new Sub-Processor that processes Customer Personal Data, we update this page with the change at least 30 days before the new Sub-Processor begins processing. The date at the top of this page reflects the most recent update.
Customers may subscribe to notifications about Sub-Processor changes by emailing privacy@openboxes.cloud with the subject line "Subscribe: sub-processor changes".
Customer objections
As described in Section 4.4 of our DPA, Customers may object to a new Sub-Processor on data-protection grounds within 30 days of notice. If we cannot resolve an objection in good faith, the Customer may terminate the affected Service with a pro-rata refund.
Contact
For questions about this list, contact privacy@openboxes.cloud.