Sub-processors
Last updated: April 22, 2026
Mailkick engages a small number of trusted third-party service providers ("sub-processors") to operate our platform. Each sub-processor is bound by a data processing agreement and holds industry-standard security certifications. This page lists them with their purpose, region, and the type of data they may process on our behalf.
For more details on how we protect your data, see our Security page and our Privacy Policy.
Current sub-processors
Supabase Inc.
supabase.com/securityPurpose: Database (PostgreSQL), authentication, edge functions, and object storage
Region: EU — AWS eu-west-3 (Paris, France)
Certifications: SOC 2 Type II, HIPAA
Data processed: Account information, email templates, components, images, usage metadata
Vercel Inc.
vercel.com/securityPurpose: Application hosting, global edge CDN, serverless API routes
Region: Global edge network; serverless functions run in US (default region)
Certifications: SOC 2 Type II, ISO 27001, PCI DSS
Data processed: Application code, HTTP request metadata (no persistent customer data storage)
Cloudflare Inc.
www.cloudflare.com/trust-hubPurpose: R2 object storage for published email assets and images, CDN delivery
Region: EU region for R2 buckets
Certifications: SOC 2 Type II, ISO 27001, ISO 27018, PCI DSS
Data processed: Published email HTML, images, public assets
Purpose: Transactional email delivery (login links, team invites, notifications)
Region: United States
Certifications: SOC 2 Type II
Data processed: Recipient email addresses, transactional email content
OpenAI, L.L.C.
openai.com/securityPurpose: Spelling and grammar corrections on user-submitted text
Region: United States
Certifications: SOC 2 Type II
Data processed: Short text snippets submitted by users for correction. API data is not used for training (per OpenAI's API data usage policy).
PostHog
posthog.com/securityPurpose: Product analytics and feature flags
Region: EU cloud
Certifications: SOC 2 Type II, HIPAA, ISO 27001
Data processed: Pseudonymized product usage events, feature flag evaluation context
Sentry
sentry.io/securityPurpose: Application error monitoring and performance tracing
Region: United States
Certifications: SOC 2 Type II, ISO 27001
Data processed: Error stack traces, request metadata; PII is filtered before ingestion
Optional integrations
In addition to the sub-processors above, Mailkick offers optional integrations with Email Service Providers (ESPs) such as Klaviyo, Brevo, Braze, SendGrid, and others. These integrations are only activated when a customer explicitly connects their account via OAuth or API key.
When connected, Mailkick syncs email templates the customer has chosen to export. We do not access subscriber lists, campaign analytics, or any other data beyond what is strictly necessary for the sync.
Changes to this list
We update this page whenever we add, remove, or replace a sub-processor. Enterprise customers may subscribe to change notifications by contacting us at the address below.