Sub-processors & Data Processors
Last updated: 1 May 2026
CoolbyBeatShop uses the following third-party sub-processors to operate our services. All transfers of personal data to third countries (e.g. United States) are governed by appropriate safeguards as noted below, in accordance with GDPR Chapter V.
We will update this list within 30 days of adding or removing a sub-processor. If you object to a new sub-processor, please contact us at contact@coolbybeatshop.com.
Stripe, Inc.
United StatesPurpose: Payment processing, fraud prevention, invoicing.
Data transferred: Name, email, billing details, transaction data.
Safeguard: EU Standard Contractual Clauses (SCCs); PCI DSS Level 1.
Vercel, Inc.
United StatesPurpose: Website hosting, edge functions, analytics.
Data transferred: IP address, browser metadata, usage logs.
Safeguard: EU Standard Contractual Clauses (SCCs); SOC 2 Type II.
Neon, Inc. (Neon Tech)
United StatesPurpose: Serverless PostgreSQL database hosting.
Data transferred: All user profile and order data stored in the database.
Safeguard: EU Standard Contractual Clauses (SCCs); encrypted at rest.
Amazon Web Services (AWS)
United States (us-east-1)Purpose: S3 object storage for beat audio files and voice uploads.
Data transferred: Audio files, voice recording data.
Safeguard: EU Standard Contractual Clauses (SCCs); server-side AES-256 encryption; ISO 27001.
Resend, Inc.
United StatesPurpose: Transactional email delivery (welcome emails, purchase receipts).
Data transferred: Name, email address, order details.
Safeguard: EU Standard Contractual Clauses (SCCs).
Google LLC
United StatesPurpose: Google OAuth (sign-in), Google Fonts.
Data transferred: OAuth tokens, profile data (when using Google sign-in); font requests (IP address).
Safeguard: EU Standard Contractual Clauses (SCCs); Privacy Shield successor frameworks.