Subprocessors
Last updated: 5 May 2026 · Version 2.0
This page lists every third party ("subprocessor") that processes personal data on KiqIQ's behalf. We update this list whenever we add, remove, or change a service. Material changes are notified to registered users by email at least 14 days in advance.
Active subprocessors
Each of the following processors is bound by a Data Processing Agreement (DPA) with appropriate technical and organisational measures. Cross-border transfers rely on EU-US Data Privacy Framework certifications, EU Standard Contractual Clauses (2021), and the UK International Data Transfer Addendum where applicable.
Clerk
- Purpose
- User authentication, session management, account management, MFA
- Data categories
- Email, name, hashed password, IP, session tokens, social auth tokens
- Location
- USA (with EU data residency option)
- Transfer mechanism
- EU-US Data Privacy Framework / SCCs / UK IDTA
- DPA status
- Active — Clerk standard DPA executed
Supabase
- Purpose
- Postgres database, storage, real-time subscriptions, server-side auth verification
- Data categories
- Account data, bet tracker entries, AI prompt history, app metadata
- Location
- EU region (Frankfurt) for EU users; US for US users
- Transfer mechanism
- SCCs / UK IDTA / regional residency
- DPA status
- Active — Supabase standard DPA executed
Stripe
- Purpose
- Payment processing, subscription management, tax calculation, fraud detection
- Data categories
- Card details (tokenised — never seen by KiqIQ), billing address, country, transaction history, IP at checkout
- Location
- USA / Ireland (PCI-DSS Level 1)
- Transfer mechanism
- EU-US Data Privacy Framework / SCCs / UK IDTA
- DPA status
- Active — Stripe standard DPA executed
Vercel
- Purpose
- Website hosting, edge function execution, CDN, build pipeline
- Data categories
- IP address, request URLs, response codes, user agent, server logs
- Location
- Global edge network (USA / EU / Asia / Australia)
- Transfer mechanism
- EU-US Data Privacy Framework / SCCs / UK IDTA
- DPA status
- Active — Vercel standard DPA executed
PostHog
- Purpose
- Product analytics, feature flags, session replay (with consent)
- Data categories
- Anonymised user ID, page views, click events, device fingerprint, session recordings (when enabled)
- Location
- USA / EU (Frankfurt) — KiqIQ uses EU instance
- Transfer mechanism
- SCCs / UK IDTA / EU regional residency
- DPA status
- Active — PostHog standard DPA executed
OpenAI
- Purpose
- AI assistant inference (GPT-4o-mini / GPT-4o for AI prompts)
- Data categories
- Prompts you submit to the AI (zero-retention API mode — not used to train models)
- Location
- USA
- Transfer mechanism
- EU-US Data Privacy Framework / SCCs / UK IDTA — zero data retention enabled
- DPA status
- Active — OpenAI Enterprise / API DPA
Sentry
- Purpose
- Error monitoring, performance monitoring, release health
- Data categories
- Error stack traces, browser/device info, request metadata; PII scrubbed before transmission
- Location
- USA / EU (Frankfurt) — KiqIQ uses EU instance
- Transfer mechanism
- SCCs / UK IDTA / EU regional residency
- DPA status
- Active — Sentry standard DPA executed
Future subprocessors
These services are in scope for future phases of KiqIQ. They will be added to the active list with full DPA and transfer mechanism details before any production data is shared with them.
Email delivery provider (TBD — likely Resend or Postmark)
Transactional and marketing email delivery
Status: Phase 2 launch — final selection pending
API-Football
Football fixture, score, xG, lineup, odds, standings, head-to-head, predicted-lineup, and injury data ingestion
Status: Active — sole football-data provider as of 2026-05-10
Sanity CMS
Blog and academy content management
Status: Future — pending content workflow rollout
Algolia
Site search across guides, calculators, glossary, fixtures
Status: Future — activates once guide count exceeds search-by-navigation thresholds
StatsBomb (deep analytics)
Pro-grade event data for advanced statistics features
Status: Future — gated on revenue / commercial agreement
RevenueCat
Mobile subscription management for iOS / Android apps
Status: Future — activates with the React Native app launch
Notification of changes
KiqIQ commits to:
- Update this page within 7 days of adding, removing, or materially changing a subprocessor
- Email registered users at least 14 days before adding a subprocessor that processes account data
- Provide a public changelog of subprocessor changes (planned alongside the existing /changelog feed)
- Honour any user objection to a new subprocessor by allowing account deletion within the notification window
Contact
Questions about a specific processor or a request for additional documentation: privacy@kiqiq.com
Related documents: Privacy Policy · Cookie Policy · Terms of Service · Accessibility