SourceFlag subprocessors

Subprocessors and Service Providers

SourceFlag uses managed providers to operate the website, dashboard, billing, storage, AI-assisted features, business email, and optional walkthrough video embeds.

Effective July 15, 2026 · Version sourceflag.subprocessors.2026-07-15.v1

This disclosure describes customer-facing provider purposes and data categories. It is not proof of an executed provider DPA, a fixed processing region, a special retention control, or provider deletion completion.

AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. When a customer turns on an AI feature for eligible material, SourceFlag sends the needed content to its disclosed AI provider under SourceFlag-controlled credentials. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. Provider handling follows the applicable endpoint, account configuration, provider terms, and evidenced controls. Authorized SourceFlag Team members and disclosed service providers may access information only when needed to operate, secure, support, or perform an authorized Human Review. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

OpenAI API

Purpose

SourceFlag-controlled OpenAI API processing for customer-authorized AI features and preparation checks.

Data categories

Authorized public or unclassified solicitation content, prompts, source excerpts, generated outputs, and limited request metadata. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Notes

Provider handling follows the applicable endpoint, account configuration, provider terms, and evidenced controls. SourceFlag does not claim universal zero retention or immediate provider deletion.

Supabase

Purpose

Authentication, database, private storage, and workspace records.

Data categories

Account data, auth/session data, workspace data, official-source review records, generated artifacts, and Ask/chat history.

Notes

Used for hosted dashboard identity, private file storage, and workspace persistence.

Stripe

Purpose

Checkout, billing, subscriptions, customer portal, invoices, payment processing, AI usage packs, and limited payment metadata.

Data categories

Billing metadata, customer records, subscription status, payment status, and limited payment method details.

Notes

SourceFlag does not intentionally store full payment card numbers.

Vercel

Purpose

Website and dashboard hosting.

Data categories

Website/dashboard delivery data, request metadata, and technical logs.

Notes

Used to host and deliver the public website and hosted dashboard.

Render

Purpose

Background worker compute.

Data categories

Job processing data, file-processing tasks, workflow metadata, and technical logs.

Notes

Used for background processing infrastructure.

Google Workspace

Purpose

Business email and administration.

Data categories

Email communications and administrative records.

Notes

Used for SourceFlag business communications.

Resend

Purpose

Transactional, billing, and product email delivery.

Data categories

Email addresses, delivery metadata, message content, and related event metadata.

Notes

Used to deliver operational SourceFlag emails.

YouTube privacy-enhanced embeds

Purpose

Optional marketing walkthrough video embeds.

Data categories

Video interaction data processed by YouTube/Google when users interact with embedded videos.

Notes

Optional only. When a privacy-enhanced walkthrough embed is configured, YouTube/Google may process interaction data. Current hosted use requires exact environment evidence.

A Data Processing Addendum applies only when it is expressly incorporated into a signed customer order or agreement.

SourceFlag may update subprocessors as the service evolves. SourceFlag will publish the current list here and, when an applicable signed DPA, order form, or law requires it, provide advance notice of a material new subprocessor through the agreed notice channel. An authorized customer may raise a documented data-protection objection at privacy@sourceflagworkspace.com. The governing DPA or order form controls the review, mitigation, and any termination right; no universal notice period or objection remedy is promised by this page.