Legal
Sub-processors
Companies that process personal data on our behalf. This page is generated from the same registry the platform code uses, so it always reflects what is actually in use.
Last updated: 15 September 2026
Core sub-processors
Used for every account. We notify customers before adding to this list, so you have an opportunity to object.
SimpleWala (application hosting and database)
Runs the platform and stores its database.
- Data shared
- Everything stored by the platform, at rest.
- Region
- See hosting agreement
- Transfer basis
- Standard Contractual Clauses where applicable
Stripe
Subscription billing, checkout and invoicing.
- Data shared
- Email address, name, billing country, subscription tier. Card details go directly to Stripe and never reach our servers.
- Region
- United States / Ireland
- Transfer basis
- Standard Contractual Clauses
Twilio SendGrid
Sends transactional and lifecycle email.
- Data shared
- Email address, name, and the content of the email being sent.
- Region
- United States
- Transfer basis
- Standard Contractual Clauses
Google Analytics 4
Aggregate usage analytics.
- Data shared
- IP address, a pseudonymous client ID, pages viewed, device and browser.
- Region
- United States
- Transfer basis
- EU-US Data Privacy Framework
Google Fonts
Serves the two brand typefaces used across the site and app.
- Data shared
- IP address, user agent, and the referring page — sent by the browser on every page view when it fetches the font stylesheet and the font files.
- Region
- United States
- Transfer basis
- EU-US Data Privacy Framework
Sub-processors you choose
These receive data only if you connect them yourself. Nothing is sent to a platform you have not connected, and disconnecting stops it immediately.
Google (sign-in)
Lets you sign in with a Google account.
Data shared: Only for users who choose Google sign-in: name, email address, profile picture.
Meta (sign-in)
Lets you sign in with a Facebook account.
Data shared: Only for users who choose Facebook sign-in: name, email address, profile picture.
Meta (Conversions API)
Tells Meta which of your ad clicks turned into a signup or a sale, so your ad reporting shows what the spend produced and not only what it cost.
Data shared: For each conversion you choose to send: email address, phone number, first and last name, country and IP address — all SHA-256 hashed before they leave the platform — plus the event name, value and currency. Hashing lets Meta match the person without us sending readable details, but it is still personal data being disclosed for advertising.
Platforms you connect (analytics, ads, CRM, publishing, messaging)
Reads metrics into your dashboard and publishes on your behalf when you ask.
Data shared: Whatever the specific action needs — a post body, a metric query, a contact lookup. Nothing is sent to a platform you have not connected.
AI providers you connect (OpenAI, Anthropic, Google, ElevenLabs)
Generates drafts, images and speech at your request.
Data shared: Your prompt and the journey data relevant to it. Bring-your-own-key: the request runs on your account with your provider.
Contact enrichment services you connect
Fills in a lead’s job title, company and social profiles.
Data shared: A lead’s email address or company domain.
Changes to this list
We give notice before adding a core sub-processor. To be told when this page changes, or to object to an addition, email privacy@themarkplatform.com. You can see what we hold and control how it is used in your Privacy Centre, and the full policy is at /privacy.