Legal
Sub-processors
RiskGear uses the following providers to deliver, secure, monitor, communicate about, and bill for the Service.
Effective date: 5 September 2026
1. Infrastructure and application delivery
- Supabase — database, authentication, file storage, and supporting infrastructure. Data processed: account identifiers, workspace data, Customer Data, and technical metadata.
- Vercel — web application hosting, serverless execution, and content delivery. Data processed: requests, IP and device metadata, and application payloads required to serve the Service.
2. Communications and commerce
- Resend — transactional, invitation, and reminder email delivery. Data processed: email address, display name where available, message content, and delivery metadata.
- Telegram — delivery of support requests to RiskGear's private internal support chat. Data processed: contact details, workspace context, support message, and delivery metadata.
- Paddle — Merchant of Record for checkout, payment, tax, invoicing, and subscription administration. Data processed under Paddle's purchaser terms: billing identity, transaction, tax, and payment-related information.
3. Reliability and product analytics
- Sentry — application error monitoring and diagnostics. Data processed: error context, technical identifiers, stack traces, and request metadata configured to avoid Customer record content.
- PostHog — privacy-configured product analytics when enabled. Data processed: feature usage and device metadata; sensitive risk and incident content is excluded or masked.
4. Changes and questions
This list is updated before a new provider begins processing Customer Data. Customers with vendor-risk or data-location questions can contact hello@tryriskgear.com.