Subprocessors
Overview
Leakeo uses a small number of third-party services ("subprocessors") to deliver the platform. This page lists each subprocessor, their role, and the location where they process data.
We review our subprocessors regularly and update this page when changes are made. You may object to the addition of a new subprocessor within 30 days of this page being updated, by contacting us via the in-app support form.
Current subprocessors
| Subprocessor | Purpose | Data processed | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Google Firebase (Google LLC) | Authentication, database (Firestore), and App Check request verification | Account data, session data, behavioral and transactional event data, billing references | United States (primary), EU/UK regional options available | Google Cloud DPA with SCCs |
| Vercel Inc. | Serverless compute and hosting for the Leakeo application | Request headers, IP addresses (transient), application code execution | United States and edge locations globally | Vercel DPA with SCCs |
| Stripe Inc. | Subscription billing and payment processing for Leakeo customers' own accounts | Billing contact name, email, payment method metadata, subscription status | United States | Stripe DPA with SCCs |
| Google reCAPTCHA (Google LLC) | Bot detection and abuse prevention via Firebase App Check | Browser fingerprint signals, interaction patterns (no personal identifiers stored by Leakeo) | United States | Google Cloud DPA with SCCs |
Services not considered subprocessors
The following services are used by Leakeo but do not process personal data on your behalf in their capacity as our subprocessors:
- Google Fonts — font delivery via CDN. Requests are made from users' browsers directly to Google's CDN. Leakeo does not pass personal data to Google for this purpose.
- Font Awesome — icon font delivery. Same as above.
Third-party integrations you connect
When you connect Stripe or Shopify to Leakeo via webhooks, those services send data to Leakeo on your behalf. Stripe webhooks handle payments, refunds, chargebacks, subscription lifecycle events (creation, conversion, upgrade, downgrade, cancellation), and recurring payment failures. Shopify webhooks handle orders, refunds, order cancellations, and new customer creation. In this context, Stripe and Shopify are acting under your instructions as your service providers — not as Leakeo's subprocessors. You remain the data controller for the data they transmit.
Notification of changes
We will update this page at least 30 days before adding a new subprocessor that processes personal data. If you have concerns about a proposed change, contact us via the in-app support form.