Sub-processors
Last Updated: August 6, 2026
Alter Labs, Inc. engages the vendors below to provide the Service. The Role column separates DPA Sub-processors that Process Customer Personal Data from service providers handling Alter’s controller-side account, billing, or analytics data. Each is bound, where applicable to its processing role, by data-protection obligations consistent with our Data Processing Agreement. This list is referenced by our Privacy Policy and DPA. We will update this page at least thirty (30) days before a new DPA Sub-processor begins processing Customer Personal Data, as described in the DPA; checking this page is the way to monitor sub-processor changes.
| Provider | Role | Legal/contact address and privacy contact | Processing description | Data processed | Processing location |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) (Alter’s contracting processor) and Amazon Data Services, Inc. (AWS regional infrastructure Sub-processor) | DPA Sub-processor and controller-side service provider | AWS: 410 Terry Avenue North, Seattle, WA 98109-5210, USA, Attn: AWS Legal; AWS privacy contact and current Sub-processor list | Core cloud infrastructure: application hosting and compute, managed metadata and first-party authentication databases, encrypted Credential storage, transactional email, and audit/log storage. AWS identifies Amazon Data Services, Inc. as the infrastructure entity for US East (Northern Virginia). | Service data hosted in the environment; encrypted Credentials; authentication, contact, configuration, Connected-Account, email, audit, and usage data | United States (US East, Northern Virginia) |
| Porter Technologies, Inc. | DPA Sub-processor (infrastructure control plane; classified conservatively because its deployment control plane can reach the hosting environment) | Registered-agent/service-of-process address: 80 State Street, Albany, NY 12207-2543, USA; contact@porter.run | Deployment and infrastructure-management control plane over the AWS hosting environment | Control-plane access to the hosting environment and configuration | United States |
| Stripe, LLC (for an Alter Stripe account located in the Americas) | Controller-side payment service provider | Registered office: Corporation Trust Center, 1209 Orange Street, Wilmington, DE 19801, USA; privacy@stripe.com | Payment processing and billing | Billing contact, payment-method metadata, and transaction data | United States; Stripe may process data globally as described in its DPA |
| Stripe Payments Europe, Limited (only if Alter’s Stripe account is located outside the Americas) | Controller-side payment service provider | One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland; privacy@stripe.com | Payment processing and billing | Billing contact, payment-method metadata, and transaction data | Ireland and other locations described in Stripe’s DPA |
| Functional Software, Inc. d/b/a Sentry | DPA Sub-processor on End User surfaces; controller-side service provider for operator diagnostics | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA; compliance@sentry.io | Error monitoring, performance diagnostics, and consent-gated sampled browser replay | Diagnostic and telemetry data, which may incidentally include identifiers | United States |
| PostHog, Inc. | Controller-side analytics service provider; DPA Sub-processor only where configured events contain Customer Personal Data | 2261 Market Street, #4008, San Francisco, CA 94114, USA; privacy@posthog.com | Consent-gated product and documentation analytics, including configured browser replay | Pseudonymous usage events, account/organization identifiers where configured, device/log data, and IP address | United States (US Cloud) |
| Cloudflare, Inc. | DPA Sub-processor and controller-side security service provider | 101 Townsend Street, San Francisco, CA 94107, USA; Data Protection Officer, legal@cloudflare.com | Edge network, DDoS protection, WAF, and Turnstile bot protection for portal authentication | Network/request metadata, IP addresses, and Turnstile challenge tokens | Global edge |
Note on account authentication. Email-and-password authentication for the developer portal (including account verification, password reset, and two-factor authentication) is performed by Alter on Alter’s infrastructure. Those authentication records (account name, email, password hash, two-factor secrets, session records) reside in Alter’s database within the AWS hosting environment listed above. If the developer portal offers Google or GitHub social sign-in and the user selects it, that provider authenticates the user under its own privacy notice.
Note on breached-password checking. At sign-up and password change, Alter checks candidate passwords against the Have I Been Pwned breached-password service (
api.pwnedpasswords.com) using its k-anonymity protocol. The application sends only the first five characters of a SHA-1 hash, never the password, full hash, account identifier, end-user IP address, or browser user agent. The request is made server-side, so HIBP may receive Alter’s infrastructure egress IP address, server HTTP-client metadata, request timing, and the partial hash prefix in its operational logs. Those operational metadata identify an Alter service request rather than the individual account holder. On that verified request shape, HIBP is treated as an independent security-data recipient rather than a Sub-processor of End User Personal Data for this flow.
Classification notes. The Porter row is classified conservatively as a Sub-processor because its deployment control plane can reach the AWS hosting environment, even though it does not process Customer Personal Data in the ordinary course. Stripe’s contracting entity is selected by Alter’s Stripe account location, not by an individual Alter customer’s jurisdiction. Alter reviews vendor legal-entity names and processing regions against each provider’s current sub-processor and data-processing terms as part of maintaining this register.
Note on Providers. Third-party Providers that you or your End Users choose to connect (e.g., Google, Slack, GitHub) are not Alter sub-processors. They are independent third parties you direct the Service to interact with; their handling of data is governed by their own terms and privacy policies. The same applies to any identity provider a customer configures for its own End Users (e.g., a customer’s own Auth0, Clerk, Okta, or WorkOS tenant): that processing is under the customer’s contract with its chosen provider, and Alter has no sub-processor relationship with it.
Branded web fonts on Connect pages are retrieved by Alter server-side and served from Alter’s own origin, so an End User’s browser does not connect to a third-party font service and discloses no browser request metadata to it.
Simple Icons CDN, jsDelivr, and Brandfetch may receive ordinary browser request metadata when a Provider logo is requested. They act as independent browser-asset recipients rather than DPA Sub-processors for that request.
To be notified of changes to this list, contact privacy@alterauth.com.