Last updated: 11 September 2026
This page lists the third-party providers Basestack uses to operate the hosted service at https://www.basestack.co. It is the source of truth for sub-processors referenced by the Data Processing Addendum.
Basestack will give at least 30 days' notice before adding or replacing a sub-processor that processes customer personal data by updating this page and, where available, by email to customers subscribed to such notices.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Railway | Application hosting and managed PostgreSQL database. | Account data, projects, flags, forms, submissions, file metadata, usage data, logs, and related service data. | European Union / United States |
| Cloudflare | CDN, DNS, DDoS protection, and TLS termination. | Request metadata, IP address, user agent, URL, headers. | Global edge network |
| Railway Buckets | S3-compatible object storage for Forms file uploads. | Uploaded file content, filename, content type, and size. | European Union / United States |
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Polar | Merchant of record for checkout, subscriptions, billing, taxes, invoices, refunds, and usage metering. | Billing contact, email, billing address, payment method metadata, subscription data, tax data, and usage events. | European Union / United States |
| Resend | Transactional email delivery. | Recipient email, recipient name, and message body. | United States |
| OpenRouter | AI gateway for Forms spam classification. OpenRouter routes submission data to an underlying large language model provider (such as OpenAI or Google) to generate the classification. | Form submission field values and customer account identifier. Uploaded file bytes are not sent for spam classification. | United States / downstream model providers |
| Umami | Marketing-site analytics only. | Aggregated page views, referrer, country, browser, and device type. | European Union |
These providers process data when a user chooses third-party OAuth sign-in.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| GitHub OAuth | Optional sign-in with GitHub. | Account identifier, email, display name, avatar URL. | United States |
| Google OAuth | Optional sign-in with Google. | Account identifier, email, display name, avatar URL. | United States / Global |
Providers in this section receive data only when a customer enables the integration. They are listed for transparency. Unless Basestack has a separate processing relationship with the provider, they may also act under the customer's own relationship with that provider.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Google Sheets | Append Forms submissions to a customer spreadsheet. | Form submission field values selected by the customer; OAuth access and refresh tokens stored by Basestack. | United States / Global |
Basestack does not currently have group affiliates that process customer personal data.
Questions about this list:
[email protected]