Subprocessors
Last updated: 2026-09-06
Zukeepr engages the third-party service providers listed below to operate the platform and deliver services to users. Each subprocessor is required to commit to data protection obligations consistent with Zukeepr's Data Processing Agreement and applicable privacy law.
This list is maintained in the Zukeepr source repository and is updated whenever a subprocessor is added, changed, or removed. For questions, contact privacy@zukeepr.com.
| Subprocessor | Purpose | Data Location | Data Categories | Last Updated |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and S3 file storage (daycare photos, documents, uploaded assets) | Canada (ca-central-1) | All platform data, uploaded files | 2026-05-13 |
| MongoDB Atlas | Database hosting for all application data | Canada Central | Account, application, enrollment, and message data | 2026-05-13 |
| Stripe | Payment processing and Stripe Connect payouts to daycare providers | United States | Parent name and email address, daycare business name and email address, payment method and bank account details, bank debit mandate records, transaction and invoice records, internal reference identifiers for the account, parent, child, daycare and enrollment | 2026-09-06 |
| Vercel | Web application hosting for the ZuKeepr Next.js frontend | United States / global edge | HTTP request data, session cookies | 2026-05-13 |
| Firebase Authentication (Google) | Account authentication and sign-in | United States | Authentication tokens and credentials, user and authentication-provider identifiers, email and permitted profile information, sign-in and account metadata, IP address and user-agent security data | 2026-08-12 |
| AWS Simple Email Service (SES) | Transactional email delivery (enrollment notifications, OTP, account emails) | United States | Recipient email address, message content | 2026-05-13 |
| Resend | Admin notification emails (internal platform alerts, MRR milestones, support ticket flags) | United States | Recipient email address, message content | 2026-05-13 |
| Microsoft Clarity | Anonymized usage analytics — session replays and heatmaps to improve usability (analytics consent required) | United States / global Azure regions | Aggregated session and interaction data; all form fields masked; sensitive pages fully excluded from recording | 2026-08-22 |
Amazon Web Services (AWS)
- Purpose
- Cloud infrastructure and S3 file storage (daycare photos, documents, uploaded assets)
- Data Location
- Canada (ca-central-1)
- Data Categories
- All platform data, uploaded files
- Last Updated
- 2026-05-13
MongoDB Atlas
- Purpose
- Database hosting for all application data
- Data Location
- Canada Central
- Data Categories
- Account, application, enrollment, and message data
- Last Updated
- 2026-05-13
Stripe
- Purpose
- Payment processing and Stripe Connect payouts to daycare providers
- Data Location
- United States
- Data Categories
- Parent name and email address, daycare business name and email address, payment method and bank account details, bank debit mandate records, transaction and invoice records, internal reference identifiers for the account, parent, child, daycare and enrollment
- Last Updated
- 2026-09-06
Vercel
- Purpose
- Web application hosting for the ZuKeepr Next.js frontend
- Data Location
- United States / global edge
- Data Categories
- HTTP request data, session cookies
- Last Updated
- 2026-05-13
Firebase Authentication (Google)
- Purpose
- Account authentication and sign-in
- Data Location
- United States
- Data Categories
- Authentication tokens and credentials, user and authentication-provider identifiers, email and permitted profile information, sign-in and account metadata, IP address and user-agent security data
- Last Updated
- 2026-08-12
AWS Simple Email Service (SES)
- Purpose
- Transactional email delivery (enrollment notifications, OTP, account emails)
- Data Location
- United States
- Data Categories
- Recipient email address, message content
- Last Updated
- 2026-05-13
Resend
- Purpose
- Admin notification emails (internal platform alerts, MRR milestones, support ticket flags)
- Data Location
- United States
- Data Categories
- Recipient email address, message content
- Last Updated
- 2026-05-13
Microsoft Clarity
- Purpose
- Anonymized usage analytics — session replays and heatmaps to improve usability (analytics consent required)
- Data Location
- United States / global Azure regions
- Data Categories
- Aggregated session and interaction data; all form fields masked; sensitive pages fully excluded from recording
- Last Updated
- 2026-08-22
See also: Privacy Policy §7 · Data Processing Agreement §6
