GDPR Article 28

Subprocessors

Last updated May 15, 2026

Rule Guardian uses the third-party services below to operate. Each is bound by a Data Processing Agreement (or equivalent) and processes only the data needed for its function. We notify users by email at least 30 days before adding or replacing any subprocessor.

SubprocessorPurposeData sharedLocationDPA
SupabasePrimary database (Postgres) and authenticationAccount, brokerage metadata, encrypted OAuth tokens, trade historyUSAView DPA
StripePayment processing and subscription billingName, email, billing address, last 4 of card, charge historyUSAView DPA
LoopsTransactional and lifecycle emailEmail address, name, segmentation propertiesUSAView DPA
SentryError monitoringStack traces, user agent, IP address, redacted error contextUSAView DPA
BetterStackUptime and log monitoringService availability metrics, log lines (no PII by default)USAView DPA
VercelApplication hosting, edge network, bandwidthRequest logs (URL, status, IP), deployment artifactsUSA + global edgeView DPA
RithmicBrokerage integration (market data and order routing)Account credentials and trade activity for accounts you connectUSAOn request
TradovateBrokerage integration (market data and order routing)Account credentials and trade activity for accounts you connectUSAOn request
CloudflareDNS resolutionDNS lookups (no application payload)USAView DPA

Questions about this list, or want to be notified when it changes? Email privacy@ruleguardian.co. See also our Privacy Policy.