Subprocessors
The providers Brandloop engages to process customer data on its behalf. This list is referenced by the Data Processing Addendum and is kept current with what the product actually runs.
How to read this list
Brandloop is operated by Meritocra LLC. Where Meritocra LLC processes customer data as a processor, the providers below are its sub-processors under Article 28 GDPR. Each entry states what the provider does and what personal data can reach it. Providers marked conditional only process data once that feature is enabled or configured.
Meritocra LLC is a United States entity and operates the product from the United States. Per-provider processing locations and each provider's own privacy and security documentation are available on request from legal@brandloop.app.
Current subprocessors
Supabase
Managed Postgres database, authentication, and object storage for workspace data.
Personal data: Account and user identifiers, email addresses, workspace content, uploaded sources, and generated assets.
Vercel
Application hosting and delivery for the web app and API.
Personal data: Request metadata (IP address, user agent) and any personal data contained in requests in transit.
Stripe
Payment processing, checkout, and subscription billing.
Personal data: Billing contact details, payment-method metadata, and transaction records.
Metronome
Usage metering, plan entitlements, and invoicing.
Personal data: Account identifiers, plan records, and usage event records.
fal.ai
Hosted media-generation endpoints used by Studio generation.
Personal data: Prompts, brand inputs, and reference images submitted for generation.
OpenAI
Model inference for studio suggestions, campaign directions, and per-network adaptation.
Personal data: Prompts and brand-source content submitted for analysis or generation.
Anthropic
Alternative model inference for copy generation.
Personal data: Prompts and brand-source content submitted for analysis or generation.
Conditional. Only when Brandloop is configured to use the Anthropic model provider; OpenAI is the default.
Zernio
Dispatching scheduled posts to connected social networks and returning publish results.
Personal data: Connected channel identifiers and credentials, post content, and publishing results.
Resend
Transactional email delivery (team invitations).
Personal data: Recipient email addresses and message content.
Sentry
Application error and performance monitoring.
Personal data: Error diagnostics, which can include account or user identifiers present in request context.
ImprovMX
Email alias forwarding for the privacy, legal, and support addresses.
Personal data: Contents of email sent to those addresses.
PostHog
Server-side product lifecycle analytics.
Personal data: Account and user identifiers and product event properties.
Conditional. Server-side capture ships disabled and runs only when the owner enables it. Browser analytics is not loaded.
Intercom
In-app support messenger for authenticated users, and server-side sync of account/plan state so Intercom Series can trigger lifecycle email (e.g. a trial-ending reminder) for users who are not currently in the app.
Personal data: Name, email address, support conversation content, and account/plan state used to trigger lifecycle email (Brandloop account identifier and the signed-in user's role on it, package and billing subscription status, trial end date, trial credits remaining, connected-account and brand counts, activation-milestone completion, and the timestamp of the last sync).
Conditional. Messenger loads only for signed-in users who accept the optional Preferences cookie category. Server-side sync only ever UPDATES a contact Intercom already has from that Messenger boot — it never creates one, so it never introduces a user to Intercom who has not already been introduced under that same, already-accepted basis. INTERCOM_ACCESS_TOKEN is set in production, scoped to read and update contacts only — it cannot read admins, conversations, or any other Intercom resource.
Firecrawl
Fetching and extracting content from customer-submitted URLs.
Personal data: Customer-submitted URLs and the public page content returned for them.
Conditional. Optional enrichment. The built-in HTML metadata extractor runs when it is not configured.
Brandfetch
Brand metadata lookup for a customer-submitted domain.
Personal data: Customer-submitted domains; where a returned logo or image URL is rendered in the app, your browser requests it directly and Brandfetch receives that request.
Conditional. Optional enrichment, and configured today. There is no fallback for it: brand colors, logo, and company profile are simply not populated when it is unset.
logo.dev
Logo lookup for a customer-submitted domain.
Personal data: Customer-submitted domains; the logo image is loaded by your browser, so logo.dev receives your IP address and user agent.
Conditional. Optional enrichment, and not configured today.
Object storage is Supabase, for every account. Alternative S3-compatible storage is planned but not built, so no other storage sub-processor holds your assets today; if that changes it will be listed here first.
Notice of changes
Under the Data Processing Addendum, customers give general written authorization for these sub-processors. Before a new sub-processor starts processing customer personal data, we update this page and, for customers who have subscribed to notice, email the change at least 30 days in advance. To subscribe, email legal@brandloop.app with the subject "Subprocessor notice" and your account email.
You may object to a new sub-processor on reasonable data-protection grounds within the notice period. If we cannot offer a workable alternative, you may terminate the affected subscription and receive a refund of prepaid fees for the unused remainder of the term.
Related
Data Processing Addendum, Privacy Policy, AI-Content Disclosure, and Trust center.