Skip to main content

Subprocessors

The providers Brandloop engages to process customer data on its behalf. This list is referenced by the Data Processing Addendum and is kept current with what the product actually runs.

How to read this list

Brandloop is operated by Meritocra LLC. Where Meritocra LLC processes customer data as a processor, the providers below are its sub-processors under Article 28 GDPR. Each entry states what the provider does and what personal data can reach it. Providers marked conditional only process data once that feature is enabled or configured.

Meritocra LLCis a United States entity and operates the product from the United States. Per-provider processing locations and each provider's own privacy and security documentation are available on request from legal@brandloop.app.

Current subprocessors

Supabase

Managed Postgres database, authentication, and object storage for workspace data.

Personal data: Account and user identifiers, email addresses, workspace content, uploaded sources, and generated assets.

Vercel

Application hosting and delivery for the web app and API.

Personal data: Request metadata (IP address, user agent) and any personal data contained in requests in transit.

Stripe

Payment processing, checkout, and subscription billing.

Personal data: Billing contact details, payment-method metadata, and transaction records.

Metronome

Usage metering, plan entitlements, and invoicing.

Personal data: Account identifiers, plan records, and usage event records.

fal.ai

Hosted media-generation endpoints used by Studio generation.

Personal data: Prompts, brand inputs, and reference images submitted for generation.

OpenAI

Model inference for brand analysis, campaign directions, and image generation.

Personal data: Prompts and brand-source content submitted for analysis or generation.

Anthropic

Alternative model inference for copy generation.

Personal data: Prompts and brand-source content submitted for analysis or generation.

Conditional. Only when Brandloop is configured to use the Anthropic model provider; OpenAI is the default.

Zernio

Dispatching scheduled posts to connected social networks and returning publish results.

Personal data: Connected channel identifiers and credentials, post content, and publishing results.

Resend

Transactional email delivery (sign-in and team invitations).

Personal data: Recipient email addresses and message content.

Sentry

Application error and performance monitoring.

Personal data: Error diagnostics, which can include account or user identifiers present in request context.

ImprovMX

Email alias forwarding for the privacy, legal, and support addresses.

Personal data: Contents of email sent to those addresses.

PostHog

Server-side product lifecycle analytics.

Personal data: Account and user identifiers and product event properties.

Conditional. Server-side capture ships disabled and runs only when the owner enables it. Browser analytics is not loaded.

Intercom

In-app support messenger for authenticated users.

Personal data: Name, email address, and support conversation content.

Conditional. Loads only for signed-in users who accept the optional Preferences cookie category.

Firecrawl

Fetching and extracting content from customer-submitted URLs.

Personal data: Customer-submitted URLs and the public page content returned for them.

Conditional. Optional enrichment. The built-in HTML metadata extractor runs when it is not configured.

Brandfetch

Brand metadata lookup for a customer-submitted domain.

Personal data: Customer-submitted domains.

Conditional. Optional enrichment.

logo.dev

Logo lookup for a customer-submitted domain.

Personal data: Customer-submitted domains.

Conditional. Optional enrichment.

Object storage defaults to Supabase. If a workspace is configured to use an S3-compatible bucket instead, that storage provider becomes a sub-processor for stored assets; ask us which one is in use for your account.

Notice of changes

Under the Data Processing Addendum, customers give general written authorization for these sub-processors. Before a new sub-processor starts processing customer personal data, we update this page and, for customers who have subscribed to notice, email the change at least 30 days in advance. To subscribe, email legal@brandloop.app with the subject "Subprocessor notice" and your account email.

You may object to a new sub-processor on reasonable data-protection grounds within the notice period. If we cannot offer a workable alternative, you may terminate the affected subscription and receive a refund of prepaid fees for the unused remainder of the term.

Related

Data Processing Addendum, Privacy Policy, AI-Content Disclosure, and Trust center.