Subprocessors

The third-party providers Codifiq LLC uses to operate Sartoria.

Version 2026-08-28 · Effective 28 August 2026

Current subprocessors

We keep this list short on purpose. These are the only third parties that process data on our behalf to deliver Sartoria.

Vercel Inc.
Application hosting and content delivery, United States. Processes requests and responses as they pass through the application, including uploads and generated images in transit, and holds operational logs containing IP addresses and timestamps. Serves the application from the US West region.
Supabase Inc.
Database, authentication and file storage, United States (US West). Processes all stored application data: account records, organisation and brand records, style and tech pack data, generation history, and uploaded and generated image files. Manages passwords as hashes and issues session tokens.
Google LLC
AI image generation and image analysis through the Gemini API, United States. Receives the source and reference images for a generation and the composed text prompt. Does not receive account identifiers. Under Google’s paid API terms it does not use this content to train its models, and retains it only briefly for abuse monitoring and legal compliance.
Resend Inc.
Delivery of authentication email — signup confirmation, password reset, and workspace invitations, United States. Receives the recipient’s email address and the contents of those messages. It is not used for marketing.
Stripe, Inc.
Payment processing for purchases of generation credit, United States. The checkout page is hosted by Stripe, so card details are entered on Stripe’s own pages and never reach the Service, which at no point holds a card number. Receives the amount, an identifier for the organisation being credited, the name and email address of the person paying, and whatever billing details it needs to take the payment. We keep only Stripe’s customer, session and event identifiers, recorded beside the credit they paid for. Its handling of that data is described at https://stripe.com/privacy.

What is deliberately absent

The following categories of vendor are not used at all, which is worth stating explicitly because most SaaS subprocessor lists are full of them:

  • No product analytics or session replay.
  • No advertising, attribution or marketing automation.
  • No third-party error tracking or log aggregation.
  • No card data of our own — payment details are entered on Stripe’s hosted checkout and never reach us.
  • No customer support widget or chat tool embedded in the product.

Changes to this list

We will give customers at least thirty (30) days’ notice by email before adding or replacing a subprocessor that will process customer personal data in the ordinary course of providing the Service — that is, one which begins receiving data because of a change we have made, without the customer doing anything.

A provider that receives data only because a customer chooses to use an optional part of the Service is published here before that part can be used, and takes effect for a customer when they first use it. Payment processing is the current example: our processor receives nothing about an organisation unless an administrator starts a purchase, and the payment details go to it directly from that person’s browser, on pages it hosts, rather than through us.

In either case a customer may object to a subprocessor on reasonable data protection grounds as described in our Data Processing Addendum. To be notified, or to ask a question about a provider, write to privacy@codifiq.com.