Last Updated: November 3, 2025
RightsVault uses the following third-party service providers (subprocessors) to help deliver our services. All subprocessors have been carefully vetted and are bound by appropriate data protection agreements.
We will notify customers at least 30 days in advance before adding or replacing a subprocessor. See our Data Processing Agreement (DPA) for details.
Service: User authentication, identity management
Data Processed: Email addresses, names, authentication tokens
Location: United States (AWS)
Website: clerk.com
Service: Payment processing, subscription management
Data Processed: Payment information, billing addresses
Location: United States (PCI DSS Level 1)
Website: stripe.com
Service: Cloud file storage
Data Processed: Contract documents, uploaded files
Security: AES-256 encryption at rest
Location: United States (us-east-1)
Website: aws.amazon.com/s3
Service: Managed PostgreSQL database
Data Processed: All application data
Security: Encrypted at rest, SSL/TLS connections
Location: United States
Website: neon.tech
Service: Application hosting, edge network
Data Processed: Application code, static assets
Location: United States and global edge
Website: vercel.com
Service: Error monitoring, performance tracking
Data Processed: Error logs (PII scrubbed)
Location: United States
Website: sentry.io
Service: Product analytics
Data Processed: Usage analytics (anonymized)
Location: United States
Website: posthog.com
Service: Redis caching and rate limiting
Data Processed: Cache data, rate limit counters
Location: United States (AWS)
Website: upstash.com
For questions about subprocessors, contact privacy@rightsvault.studio