Subprocessors

Vendor Transparency

Subprocessor and service-provider disclosure.

This page identifies services used by the public website and explains why product vendors must be confirmed for each customer deployment.

Effective July 13, 2026 Website service list Product schedule is deployment-specific
Public Website Services

Services used by the website, forms, and checkout.

A service may be a processor, subprocessor, independent controller, or other recipient depending on the data, configuration, and applicable terms. Inclusion below does not assign a legal role beyond what the relevant agreement and law provide.

Stripe — hosted checkout

Purpose: Stripe-hosted Checkout Sessions, subscriptions, transaction verification, receipts when enabled, and customer billing tools.

Potential data: subscriber email, organization or reference information, selected plan and billing interval, transaction identifiers, payment status, and payment information entered directly into Stripe.

Status: checkout is created by the same-origin server only after plan and consent validation. Stripe may act in different legal roles for payment processing and fraud prevention under its own terms. This listing does not mean Stripe hosts or operates the Ledgewave product.

Cloudflare — website runtime and request storage

Purpose: serve website assets, run the same-origin request and checkout API, apply edge security controls, and store request, consent, and verification records in D1.

Potential data: network and request metadata, pseudonymized rate-limit identifiers, submitted business-contact fields, request references, checkout intent and consent records, and Stripe event identifiers.

Status: used by the hardened Sites deployment. Hosting region, provider terms, retention settings, and any customer-product use must be confirmed in the applicable deployment documents.

Google — analytics when lawfully enabled

Purpose: Google Analytics can measure page views, traffic sources, clicks, and submission events.

Potential data: device and browser information, IP-derived information, URL paths without query strings, referrers, event metadata, and timing. Form-field contents are not sent.

Status: analytics is disabled unless a measurement ID is deliberately configured after property review. If configured, the site loads it only after an affirmative choice, provides equal rejection and later withdrawal, disables advertising signals in the tag, and keeps analytics off by default when a supported browser privacy signal is detected. Property-level retention, links, regional controls, and sharing settings must remain aligned with those choices.

Google Apps Script and Google Sheets — authenticated form relay

Purpose: the same-origin form service first records a validated submission and can then relay it through an authenticated Google Apps Script workflow to a restricted Google Sheet.

Potential data: fields the visitor submits, such as name, business email, company, role, inquiry details, and communication records.

Status: public forms remain unavailable unless a monitored authenticated relay is configured. The relay validates allowed fields, neutralizes spreadsheet formulas, and deduplicates reference numbers. Workspace access and retention must remain consistent with the adopted operating schedule. The optimized site uses system fonts and does not request Google Fonts.

Production Product Vendors

Information required in a product subprocessor schedule.

Before a deployment processes regulated customer personal data, Ledgewave must identify each production provider that may process it and verify the following details in the applicable disclosure or contract schedule.

Vendor details

  • Legal provider name and service function
  • Categories of customer personal data involved
  • Processing and storage locations
  • Relevant privacy and security terms
  • Transfer mechanism, where required

Change process

The applicable order or signed DPA must state whether customers receive advance notice of a new product subprocessor, how notice is delivered, whether an objection is permitted, and what remedy applies. This public page does not create a notice period or objection right that has not been agreed.

Questions

Request deployment-specific information before submitting regulated data.

Use the Contact page and put Subprocessor Request at the start of the message. Identify the intended deployment, customer location, data categories, and any required hosting or transfer restrictions. Do not submit customer records or sensitive data through the public form.