Subprocessor register.
The third parties that process data on MeetPi's behalf. Where one is offshore, it is named as such, not implied.
| Subprocessor | Purpose | Data processed | Location | DPA / terms |
|---|---|---|---|---|
| Fly.io | Runs the MeetPi application (compute) | Data in transit while serving requests | Australia (Sydney) | Provider terms (AU) |
| Supabase | Managed PostgreSQL, the primary data store | All club data at rest | Australia (Sydney) | Provider terms (AU) |
| Mobile Message | Sends and receives the SMS a club initiates | Recipient mobile numbers and message text | Australia | Provider terms (AU) |
| Resend | Delivers login and system emails | Recipient email address and email content | Offshore (United States) | DPA pending |
| Anthropic (Claude) | Drafts message text a human reviews and sends | The draft prompt only, minimised, never a bulk export | Offshore (United States) | DPA pending |
Object storage and backups stay in the Australian region. Off-provider encrypted backups, if used, are also Australian-region unless this register says otherwise.
A "DPA pending" entry marks an offshore processor whose data-processing agreement is being executed; it is updated to the signed date once in place. This register reflects MeetPi's current processors and is updated when one is added or changed. For a copy of a data-processing agreement, or a privacy question, contact privacy@meetpi.app.
Payments are not yet part of this register: card processing is planned, not built, so no payments subprocessor exists today. This page will be updated the day that changes.