Back to PlanToCode

Legal document

Service Providers and Sub-processors

Last updated: July 25, 2026

Introduction

This page lists third-party services that PlanToCode can use for users in the EU/UK. A provider may act as a processor, sub-processor, independent controller, or separate service chosen by the customer, depending on the feature, account, and agreement.

The list describes supported integrations and links to current public provider documents. It does not establish that every provider is active for every user, that a particular processing region is selected, or that a particular contract or transfer mechanism applies. Websites, repositories, APIs, and other services that you direct a browser or tool to use are not PlanToCode providers merely because the requested action sends data to them.

Supported Providers

Provider use depends on the enabled feature, deployment, account, and customer-supplied configuration. Processing locations, data-use settings, and transfer mechanisms can change and must be verified in the provider documents and the agreement that applies to the account before relying on a particular EEA transfer safeguard.

Stripe

Purpose: Payment processing services

Apple

Purpose: iOS subscription processing and Apple Push Notification service delivery

Microsoft Store

Purpose: Windows desktop application distribution and updates

Google Play

Purpose: Android subscription processing and purchase-token verification

Firebase Cloud Messaging

Purpose: Android push-notification delivery

OpenAI

Purpose: AI model processing for features configured to use OpenAI

Anthropic

Purpose: AI model processing for features configured to use Anthropic

Google AI/Gemini

Purpose: AI model processing for features configured to use Google AI or Gemini

xAI

Purpose: AI model processing for features configured to use xAI

OpenRouter

Purpose: AI routing and model processing for features configured to use OpenRouter

Hetzner

Purpose: Website, API, database, and relay hosting for configured European infrastructure

InterServer

Purpose: Website, API, database, and relay hosting for configured United States infrastructure

Cloudflare

Purpose: Website and API reverse proxy, content delivery, traffic security, and coarse country routing; this can process IP addresses, request metadata, URLs, and content in transit

Amazon Web Services (AWS)

Purpose: Desktop installer, update, and media delivery through CloudFront or S3 where configured

Auth0

Purpose: Authentication and identity management services

Mailgun

Purpose: Transactional email delivery services

Featurebase

Purpose: Hosted help and feedback portal when a user opens a PlanToCode support or feedback link

Google Analytics

Purpose: Optional website measurement after cookie acceptance when configured

X

Purpose: Optional website advertising attribution after cookie acceptance when configured

Data Protection

Provider security, retention, processing locations, and legal roles depend on the service and agreement in effect. Review the provider links below and contact us for the configuration that applies to a particular PlanToCode account or deployment.

International Transfers: Any adequacy decision, Standard Contractual Clauses, UK addendum, or supplementary measure relied on for a transfer must be identified in the executed customer or provider agreement. This page does not itself execute those terms.

Updates and Changes

Under the general written authorization in an executed DPA, we will inform the Controller in writing of any intended addition or replacement of a sub-processor before the change takes effect and give the Controller a reasonable opportunity to object. We will also update this public list.

If you have questions about our sub-processor arrangements or data processing practices, please contact us at Email.

Data Processing Addendum

Business customers should review our published Data Processing Addendum (DPA) and contact us to execute or incorporate the applicable version. Opening the DPA page or continuing to use PlanToCode does not, by itself, execute it in the checked product flow.