Legal

Sub-processors

Effective 14 May 2026 · Version 1.0

htmldrop relies on a small set of third parties to run. Each one processes some category of customer data on our behalf, under a Data Processing Agreement we hold with them. This page lists every sub-processor in use, what they handle, and where they're based — so Business-plan customers can satisfy their own GDPR Article 28 obligations without an email back-and-forth.

The full processing terms are in our DPA. The Privacy Policy describes what categories of data we handle and why.

1. Infrastructure sub-processors

These run htmldrop itself — without them the Service can't function.

Sub-processor Purpose Data handled Location
Hetzner Online GmbH Application hosting (Kubernetes, Postgres, object storage) Account data, drop content, request logs Falkenstein, Germany (EU)
Cloudflare, Inc. CDN, TLS termination, Cloudflare Tunnel, Turnstile bot-check, Custom Hostnames for BYO domains Request metadata (IP, user-agent, URL), TLS handshakes, Turnstile signals Global edge; data processing primarily in EU regions per CF's UK GDPR addendum

2. Billing sub-processors

Sub-processor Purpose Data handled Location
Stripe Payments Europe Ltd Subscription billing, invoice generation, customer portal Email, billing address (when supplied), tax ID, last 4 digits of card. Full card numbers never reach htmldrop; they go directly to Stripe. Ireland (EU); some processing in US under Stripe's SCCs.

3. Transactional email sub-processors

Sub-processor Purpose Data handled Location
Resend (Resend.com, Inc.) Verification + password-reset + email-change confirmation messages Email address, link tokens US, with EU egress for EU recipients via Resend's regional routing

4. Analytics sub-processors

Sub-processor Purpose Data handled Location
PostHog, Inc. Aggregate product analytics (page views, feature usage) on the marketing site and dashboard. Anonymous device fingerprint, IP (truncated server-side), page URL, plan tier. No drop content; no viewer data. EU region (PostHog Cloud EU, Frankfurt)
Sentry, Functional Software Inc. Server-side + browser error reporting. Stack traces, browser metadata, user ID (hashed). No drop content. Scrubbed for emails/tokens before send. US, with DPA + SCCs

5. Changes

We update this page when a sub-processor is added or removed. Business customers under contract get 30 days' notice by email before a new sub-processor goes live, giving you the chance to object as set out in the DPA.

6. Contact

Middle East Software Solutions Limited
Privacy: [email protected]
Business / DPA: [email protected]