Legal

Sub-processors

Companies that process personal data on our behalf. This page is generated from the same registry the platform code uses, so it always reflects what is actually in use.

Last updated: 15 September 2026

Core sub-processors

Used for every account. We notify customers before adding to this list, so you have an opportunity to object.

SimpleWala (application hosting and database)

Runs the platform and stores its database.

Data shared
Everything stored by the platform, at rest.
Region
See hosting agreement
Transfer basis
Standard Contractual Clauses where applicable

Stripe

Subscription billing, checkout and invoicing.

Data shared
Email address, name, billing country, subscription tier. Card details go directly to Stripe and never reach our servers.
Region
United States / Ireland
Transfer basis
Standard Contractual Clauses

Twilio SendGrid

Sends transactional and lifecycle email.

Data shared
Email address, name, and the content of the email being sent.
Region
United States
Transfer basis
Standard Contractual Clauses

Google Analytics 4

Aggregate usage analytics.

Data shared
IP address, a pseudonymous client ID, pages viewed, device and browser.
Region
United States
Transfer basis
EU-US Data Privacy Framework

Google Fonts

Serves the two brand typefaces used across the site and app.

Data shared
IP address, user agent, and the referring page — sent by the browser on every page view when it fetches the font stylesheet and the font files.
Region
United States
Transfer basis
EU-US Data Privacy Framework

Sub-processors you choose

These receive data only if you connect them yourself. Nothing is sent to a platform you have not connected, and disconnecting stops it immediately.

Google (sign-in)

Lets you sign in with a Google account.

Data shared: Only for users who choose Google sign-in: name, email address, profile picture.

Meta (sign-in)

Lets you sign in with a Facebook account.

Data shared: Only for users who choose Facebook sign-in: name, email address, profile picture.

Meta (Conversions API)

Tells Meta which of your ad clicks turned into a signup or a sale, so your ad reporting shows what the spend produced and not only what it cost.

Data shared: For each conversion you choose to send: email address, phone number, first and last name, country and IP address — all SHA-256 hashed before they leave the platform — plus the event name, value and currency. Hashing lets Meta match the person without us sending readable details, but it is still personal data being disclosed for advertising.

Platforms you connect (analytics, ads, CRM, publishing, messaging)

Reads metrics into your dashboard and publishes on your behalf when you ask.

Data shared: Whatever the specific action needs — a post body, a metric query, a contact lookup. Nothing is sent to a platform you have not connected.

AI providers you connect (OpenAI, Anthropic, Google, ElevenLabs)

Generates drafts, images and speech at your request.

Data shared: Your prompt and the journey data relevant to it. Bring-your-own-key: the request runs on your account with your provider.

Contact enrichment services you connect

Fills in a lead’s job title, company and social profiles.

Data shared: A lead’s email address or company domain.

Changes to this list

We give notice before adding a core sub-processor. To be told when this page changes, or to object to an addition, email privacy@themarkplatform.com. You can see what we hold and control how it is used in your Privacy Centre, and the full policy is at /privacy.