- CabDesign
- Sub-processors
Sub-processors
Running two design products takes a handful of other companies: somewhere to keep your account, somewhere to take a payment, somewhere to send an email from. Each of them processes some data on our behalf, and this is the whole list.
The Privacy Policy is the governing text. This page is the standing list, kept here so it has one address you can bookmark and check. What each company may do with what it holds, and the commitments we make about it, are set out in section 6 of the Privacy Policy. Where the two ever differ, the policy wins.
Changes. If we add a company that handles personal information, we update the policy before the change takes effect and tell account holders by email or by a notice inside the product. This page changes in the same commit as the policy, and an automated check in our build fails if the two lists stop matching.
| Sub-processor | What it handles for us |
|---|---|
| Supabase | Your account and sign-in, and the database holding your projects, materials, standards and customer records. |
| Stripe | Subscription payments and the card details entered at checkout. Card data goes to Stripe directly, so we never hold it. |
| Anthropic | Your AI Designer messages and the project context needed to answer them. It supplies the model the assistant uses by default. |
| The same kind of message and context, but only in a conversation one of our own administrators has switched to Gemini while testing. This is a separate matter from Sign in with Google. | |
| Vercel | Hosting, content delivery, and the server and function logs that come with running the site. It also counts page views and receives the page-speed measurements (Core Web Vitals) described in the Privacy Policy, section 6; neither sets a cookie or carries an account identifier. |
| Resend | The email we send you and the address it goes to: the welcome message, account and billing notices, support replies, and the newsletter if you asked for it. |
| Cloudflare | The security check on the pages where you create an account, sign in, or ask us to delete your account. It sees the connection and the IP address it came from, and never your email, your name or anything you typed. |
| Ahrefs Web Analytics | A count of page views: the page address, where the visit came from, browser and device type, and country or city. Ahrefs states it sets no cookies and keeps no raw IP address. |
| PostHog | Product analytics: which features get used and where people get stuck. It loads only if you accept the cookie banner. Autocapture and session recording are switched off, so it never records what you click, what you type, or what is on your screen. |
| Upstash | A short-lived counter kept against your IP address, one per endpoint you call, so one caller cannot flood an endpoint. It holds no name, no email and no account id, and each counter deletes itself within hours. |
| Jam | Bug recordings. Every page loads Jam's recorder so that a recording link we send you works on whichever page it opens, and Jam sees what any server sees when your browser fetches a file from it: your IP address, your browser, and our site's address. A recording starts only when you open one of our recording links and start it yourself. It then holds the screen, window or tab you choose to share, your voice if you narrate, and from our pages the console messages, the network requests and what came back, your clicks and key presses, the page you were on, and your account id and email address if you were signed in. Our own team also records problems on our pages with Jam's browser extension. |
| Sentry | Error reports. Our pages load one small script from Sentry, and Sentry sees what any server sees when your browser fetches a file from it: your IP address, your browser, and our site's address. When the code running a page hits an error that nothing caught, the page sends an error report holding the error message and which of our script files and lines were running, your browser and operating system, the page address without anything after a question mark or a # sign, and a short trail of what happened just before: console messages, clicked page elements, page changes and the addresses the page requested. It carries no account id and no email address, and screen recording and performance tracing are switched off. Sentry also works out your approximate location, the country and the city, from the connection the report arrives on, and adds it to the report. Sentry sets no cookie and stores nothing on your device. It keeps reports for up to 90 days and then deletes them, and it processes them in the United States. |
Questions a reviewer usually asks next
Where does the data sit
We operate from the United States, and these companies process data in the United States and, depending on the provider, in other countries where they operate. The route data takes and the protections that travel with it are set out on International Data Transfers.
Who is the controller
For the customer records you put into a project, you are the controller and we are the processor. We hold that information on your instructions so the product works for you, and we pass the same obligations down to every company on this list. The full statement is in the Privacy Policy.
Is there a written agreement
Yes, and you can read it before you ask for it. Our Data Processing Addendum is written to Article 28 of the General Data Protection Regulation, and its sub-processor annex points at this page, so the list you are reading is the list it covers. To put it in force, ask for a copy at support@cabdesign.app. You sign it, we countersign it, and you get the signed copy back.
How is any of this used for AI
Where AI is used, what it is given, and what it is not allowed to do are all set out on AI Transparency.
Related policies
- Privacy Policy - the governing text for everything on this page
- Security and your data - how the account and the database are protected
- International Data Transfers
- AI Transparency
- Cookie Policy - what loads in your browser, and what you can turn off
- Terms of Service
CabDesign and StackDesign are built by Bespoke Woodcraft Studio, a custom cabinet shop in Los Angeles.