Adsevon uses the third-party providers below to run the service. Each one processes customer data only for the purpose listed, under a contract with us. We do not sell data, and we do not share it with advertisers or data brokers.
This list changes as our providers change — the date above is the last time we updated it. If you are a business customer who needs a data processing agreement, see our DPA page.
Current subprocessors
Render
Render privacy policy- Purpose:
- Hosts the Adsevon application servers.
- Data:
- Account data, workspace data, campaign data, and technical logs pass through the application servers.
- Region:
- United States (Render data centers; exact region per our project configuration).
- Purpose:
- Managed Postgres database — the primary store for all Adsevon data.
- Data:
- Account data, workspace data, campaign datasets and metrics, billing metadata, audit logs.
- Region:
- Per our Neon project configuration (Neon offers US and EU regions).
Upstash
Upstash privacy policy- Purpose:
- Managed Redis — rate limiting, session support, and caching.
- Data:
- Technical metadata only (rate-limit counters, session references). No campaign data.
- Region:
- Per our Upstash configuration (Upstash offers global regions).
Resend
Resend privacy policy- Purpose:
- Sends transactional account emails (verification, password reset, notifications).
- Data:
- Email addresses and the content of the transactional emails we send you.
- Region:
- United States.
Paddle
Paddle privacy policy- Purpose:
- Merchant of record for billing — processes payments, handles tax, and manages subscriptions.
- Data:
- Billing metadata (plan, subscription status, trial dates) plus the payment details you give Paddle directly. We never receive your card numbers.
- Region:
- United States and EU (Paddle processes payments globally as merchant of record).
Cloudflare (Turnstile)
Cloudflare privacy policy- Purpose:
- Fraud-prevention checks on sign-up, sign-in, and password pages.
- Data:
- Browser signals needed to distinguish humans from bots during the check. Runs only on auth pages.
- Region:
- Global edge network.
Conditional processors
These only process your data if you choose to use the connected feature:
- Google — only if you choose “Sign in with Google”; receives the OAuth request and shares your name, email, and account identifier with us.
- Meta / Google Ads — only if you connect an ad account; receives OAuth requests to read your advertising data with the read-only scopes you grant.
- AI model provider — only when you use an AI feature and a provider is configured; receives your prompts and the data they reference. No provider is configured by default.
- haveibeenpwned — receives only a partial password hash (k-anonymity) when you set a new password, to check it against breach data.
Not subprocessors
GitHub hosts our source code but does not process production customer data — it is not a subprocessor. We list only providers that actually touch customer data.
Related
See the Privacy Policy for what we collect and your rights, and the DPA page if you need a data processing agreement.