Subprocessors & Service Providers
Trusted third-party services we use to deliver StatusPage.me
We maintain this inventory of external providers and first-party services used to deliver StatusPage.me. Last updated: 4 September 2026
About This List
We review service providers for their role in delivering the service and publish the data flows we can verify. Contractual and data-protection terms are applied as appropriate to the provider and processing relationship.
Payment / Merchant of Record
DodoPayments
Purpose: Payment processing, subscription management, and billing
Data Processed: Payment card information, billing details, transaction records, customer email
Location: Processing locations are determined by DodoPayments and its payment partners
Note: DodoPayments acts as the Merchant of Record. Payment card data is sent directly to DodoPayments and never touches our servers.
External Infrastructure & Service Providers
Telegram Bot API
Purpose: Internal operational, support, registration, plan-limit, and billing-event notifications
Data Processed: Depending on the event, account name, email, account ID, plan or billing-event details, support context, and request or error metadata
Location: Processing locations are determined by Telegram and its infrastructure providers
Note: Used for internal notifications through a configured StatusPage.me bot and chat.
IP Guide
Purpose: Approximate geolocation used to suggest a nearby monitoring region
Data Processed: Public IP address resolved from a customer-configured monitor target
Location: Processing locations are determined by IP Guide and its infrastructure providers
Note: Results are cached in process for one hour. Private and loopback IP addresses are not sent.
Brevo
Purpose: Additional email delivery, including delivery-problem routing and delivery to Microsoft-hosted recipient domains where configured
Data Processed: Recipient email address, message content, and delivery metadata
Location: Processing locations are determined by Brevo and its infrastructure providers
Note: Brevo supplements the primary StatusPage.me-operated mail path; it is not the platform's sole mail system.
Contabo
Purpose: Current primary application and database hosting, first-party email infrastructure, and distributed monitoring infrastructure; after the transition, backup, disaster recovery, monitoring, and other infrastructure functions may continue
Data Processed: Primary platform data, customer accounts, databases, status pages, subscription data, monitor configuration and results at regional nodes, email addresses, message content and delivery logs on the mail server, and email addresses persistently stored by the mail API for deliverability checks
Location: Germany π©πͺ (European Union) for primary platform hosting and mail.statuspage.me; Chicago and Seattle, United States, and Portsmouth, United Kingdom, for monitoring nodes; Portsmouth, United Kingdom, for mail-api.brka.io
Note: The primary platform database and local database backups are currently stored in Germany, alongside StatusPage.me-operated email delivery (mail.statuspage.me). Contabo also hosts the Chicago and Seattle (United States) and Portsmouth (United Kingdom) monitoring nodes, and mail-api.brka.io in Portsmouth, United Kingdom β expected to move to Germany by 28 September 2026.
netcup GmbH
Purpose: Planned application and database hosting infrastructure, including production infrastructure redundancy and high availability
Data Processed: Primary platform data, customer accounts, databases, status pages, subscription data, monitor configuration and results, and operational metadata β from no earlier than 28 September 2026
Location: Nuremberg, Germany π©πͺ (European Union)
Note: Announced on 28 August 2026. netcup will begin processing personal data no earlier than 28 September 2026.
Kamatera Cloud
Purpose: Uptime monitoring node in Tokyo
Data Processed: Monitor targets and check configuration, including configured headers or query parameters; response data needed to evaluate the check; results, timings, errors, and operational metadata
Location: Tokyo, Japan π―π΅
Note: The node caches monitor configuration and may queue unsent results locally. It does not host the primary customer-account database.
Vultr
Purpose: Uptime monitoring nodes in Johannesburg and SΓ£o Paulo
Data Processed: Monitor targets and check configuration, including configured headers or query parameters; response data needed to evaluate the check; results, timings, errors, and operational metadata
Location: Johannesburg, South Africa πΏπ¦ and SΓ£o Paulo, Brazil π§π·
Note: The node caches monitor configuration and may queue unsent results locally. It does not host the primary customer-account database.
OVHcloud
Purpose: Uptime monitoring node in Limburg an der Lahn
Data Processed: Monitor targets and check configuration, including configured headers or query parameters; response data needed to evaluate the check; results, timings, errors, and operational metadata
Location: Limburg an der Lahn, Germany π©πͺ
Note: The node caches monitor configuration and may queue unsent results locally. It does not host the primary customer-account database.
DigitalOcean
Purpose: Uptime monitoring node in Singapore
Data Processed: Monitor targets and check configuration, including configured headers or query parameters; response data needed to evaluate the check; results, timings, errors, and operational metadata
Location: Singapore πΈπ¬
Note: The node caches monitor configuration and may queue unsent results locally. It does not host the primary customer-account database.
Self-Hosted First-Party Software
This software is operated by StatusPage.me rather than supplied as a third-party processing service.
Stalwart
Purpose: Primary transactional and notification email service at mail.statuspage.me
Data Processed: Recipient email address, message content, and delivery logs
Operation: Operated by StatusPage.me on Contabo infrastructure in Germany π©πͺ (European Union)
Note: Stalwart is first-party operated software, not an external subprocessor. Contabo is the underlying infrastructure provider. Migrated from a United States-hosted iRedMail instance in September 2026.
mail-api.brka.io
Purpose: Email deliverability and disposable-address checks
Data Processed: Complete account or invite email addresses, stored persistently by the service
Operation: Operated by the same owner as StatusPage.me on Contabo infrastructure in Portsmouth, United Kingdom
Note: mail-api.brka.io is a first-party service, not an external subprocessor. No fixed retention duration is stated here. Expected to move to Contabo infrastructure in Germany by 28 September 2026.
Sapat.chat
Purpose: Customer support, help desk, and knowledge base
Data Processed: Support messages, account ID, name, email, and conversation history
Operation: Operated by the same owner as StatusPage.me on the same Contabo infrastructure
Note: Sapat.chat is first-party software, not an external processor. Its underlying hosting is covered by the Contabo entry.
Plausible Community Edition
Purpose: Cookie-free analytics for the StatusPage.me public website
Data Processed: Page views and events generated on the StatusPage.me public website, plus referrer and browser or device context. Customer-configured analytics on customer status pages are separate and send data to the endpoint the customer configures.
Operation: Self-hosted by StatusPage.me at stats.brka.io
Note: Plausible Community Edition is not a third-party subprocessor. View our public stats at stats.brka.io/statuspage.me (source: community edition)
Optional User-Directed Services
These services receive data only when a user or customer selects or configures the relevant integration:
- Google OAuth, GitHub OAuth, and Stack Overflow OAuth for user-selected account sign-in when the provider is enabled
- Customer-configured OIDC providers for dashboard SSO
- Customer-configured analytics endpoints for customer status pages
- Customer-configured notification destinations and providers, including Slack, Discord, Microsoft Teams, Telegram, Google Chat, Mattermost, Rocket.Chat, Pushover, PagerDuty, ntfy, Matrix, ServiceNow, Twilio, Vonage, MessageBird, Esendex, and webhooks
- Customer-directed import providers used to import monitoring or status-page configuration when the customer supplies credentials and starts an import
Data Protection & Security
How We Protect Your Data
Provider Terms
We review applicable provider terms and data-protection documentation for the processing relationship.
Encryption in Transit
Public service traffic uses TLS. Provider-specific storage protections are not represented here as a blanket StatusPage.me encryption-at-rest guarantee.
Provider Review
We review providers' published security information and the technical data flow used by StatusPage.me.
International Transfers
When data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions).
Changes to This List
We may update this list as we add or remove service providers. Before a new or replacement subprocessor processes personal data, we will give at least 30 days' notice through:
- An update to this page with the effective date
- Email notification to the registered account email address
You may object in writing to a proposed subprocessor before the change takes effect by contacting hey@statuspage.me. We will consider the objection in good faith. If we cannot reasonably accommodate it, you may terminate the affected service before the new subprocessor begins processing your data.
Questions About Our Subprocessors?
If you have questions about our data processing practices or need additional information about our subprocessors, please contact us.