LinkStacked

Part 17 — Compliance Reference

Sub-processors & Data Transfers

A complete, up-to-date list of every third-party vendor that processes personal data on our behalf — their role, location, and transfer safeguard.

Last updated: June 6, 2026Effective: June 6, 2026Operator: Devpitch UG (haftungsbeschränkt)
01

What is a sub-processor?

A sub-processor is any third-party vendor that processes personal data on our behalf under our instruction — as opposed to vendors that process data for their own independent purposes (who act as independent data controllers).

Under GDPR Article 28, we are required to: (a) use only sub-processors that provide sufficient data protection guarantees, (b) bind them by contract to process data only on our documented instructions, and (c) notify you of any new sub-processors or material changes.

02

Sub-processor table

Complete sub-processor list
VendorPurposeLocationTransfer mechanism
Amazon Web Services (AWS)Cloud infrastructure, EC2/ECS hosting, S3 file storage (profile assets, digital product files)EU-West-1 (Ireland) · US-East-1 (Virginia)SCCs + DPA
MongoDB AtlasPrimary database (all user account, profile, product, and analytics data)EU-West-1 (Ireland) · Cluster replication may include USSCCs + DPA
Redis (Upstash / Redis Cloud)Session caching, rate-limiting counters, real-time analytics queueEU (Frankfurt or Ireland)SCCs + DPA
CloudflareCDN, DDoS protection, DNS, SSL/TLS termination, custom domain proxying, WorkersGlobal PoP network · Controller: San Francisco, USASCCs + DPA + EU–US DPF
StripePayment processing, Stripe Connect seller onboarding (KYC), payout settlement, fraud detectionIreland (EU entity) · US (parent)Stripe EU DPA + SCCs
Google — OAuthSign in with Google — OAuth identity providerUSASCCs + EU–US DPF
Google — Safe BrowsingReal-time URL safety check for all user-submitted links (malware / phishing detection)USASCCs + EU–US DPF
Google — Analytics (GA4)Aggregate website analytics — only active when user consents to analytics cookiesUSASCCs + EU–US DPF (consent required)
Google — Maps Places APIAddress autocomplete during Stripe Connect onboarding for sellersUSASCCs + EU–US DPF
Google — BigQueryOptional advanced analytics processing (used only when explicitly enabled on an account)EU (multi-region) or US (if selected)SCCs + DPA
Apple — Sign In with AppleOAuth sign-in via Apple IDUSASCCs
Google SMTP (via Nodemailer)Transactional email delivery — receipts, password resets, security alertsUSASCCs + EU–US DPF
Mailchimp (Intuit)Creator email audience sync — only when creator explicitly connects their Mailchimp accountUSASCCs + DPA (creator-controlled)
Meta (Facebook Pixel)Creator-configured retargeting pixel — only loaded with visitor marketing consent on opted-in profilesUSA / Ireland (Meta Platforms Ireland Ltd.)SCCs + EU–US DPF (consent required, creator-controlled)
TikTok PixelCreator-configured retargeting pixel — consent requiredUSA / SingaporeSCCs (consent required, creator-controlled)
Snap (Snapchat Pixel)Creator-configured retargeting pixel — consent requiredUSASCCs (consent required, creator-controlled)
Pinterest TagCreator-configured retargeting pixel — consent requiredUSASCCs (consent required, creator-controlled)
X Corp. (Twitter Pixel)Creator-configured retargeting pixel — consent requiredUSASCCs (consent required, creator-controlled)

SCCs = EU Standard Contractual Clauses · EU–US DPF = EU–US Data Privacy Framework · DPA = Data Processing Agreement

03

Creator-controlled processors

Some processors in the table above (advertising pixels, Mailchimp) are only activated when a creator explicitly enables them for their profile. In these cases:

  • The creator acts as a separate data controller for those processing activities
  • LinkStacked acts as a data processor executing the creator's instruction
  • Visitor marketing consent is required before any pixel data is collected
  • Creators are responsible for disclosing their use of these pixels to their audience
04

Transfer mechanisms

We safeguard transfers of personal data to third countries (primarily the United States) using:

  • Standard Contractual Clauses (SCCs) — Commission Implementing Decision (EU) 2021/914 (June 2021 version)
  • EU–US Data Privacy Framework (DPF) — where sub-processors are DPF-certified (Stripe, Google/Alphabet, Cloudflare, Amazon)
  • UK International Data Transfer Agreements (IDTA) — for transfers to the UK
  • Adequacy decisions — for transfers to countries with EU adequacy decisions

A copy of the applicable SCCs is available on request at privacy@linkstacked.com.

05

Changes & notification

We update this sub-processor list when we add, remove, or materially change a vendor. If you have subscribed to sub-processor change notifications — or if you are an enterprise customer with data processing agreements — we will notify you of changes at least 30 days before a new sub-processor begins processing your data.

To subscribe to sub-processor change notifications, email privacy@linkstacked.com with subject: "Sub-processor change notifications".

This list was last updated on June 6, 2026. The previous version is available on request.

Questions about this policy?

Contact our legal team at legal@linkstacked.com or privacy@linkstacked.com for data matters. We respond within 5 business days.

All policies