Subprocessor List
These providers support BeeCNC’s service. A provider receives only the information reasonably necessary for its role, subject to applicable contracts and configuration.
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| OpenAI Sites | Application hosting orchestration and account identity | Account identifiers, application requests and operational metadata | United States and provider-supported locations |
| Cloudflare | Edge delivery, Workers runtime, D1 database and R2 object storage | Application, lead, account, security and file data | United States and global edge infrastructure |
| Stripe | Checkout, subscriptions, invoicing and billing portal | Customer and transaction data; payment credentials remain with Stripe | United States and Stripe-supported locations |
| Resend | Transactional email delivery | Recipient address and email content required for delivery | United States and provider-supported locations |
| PostHog, when enabled | Minimized server-side operational analytics | Pseudonymous business identifiers and allowed event properties; no lead contact details or messages | Configured U.S. endpoint |
| Sentry, when enabled | Redacted error monitoring | Error type, route and limited operational tags; exception messages are redacted | Provider-supported locations |
Changes
BeeCNC may replace or add providers needed to deliver the service. Business customers granting general authorization under the DPA may object to a new subprocessor on reasonable data-protection grounds by emailing privacy@beecnc.com. BeeCNC will provide notice of material changes through this page or another reasonable channel.
Legal review
These terms describe BeeCNC’s current product and operational practices. They are prepared for counsel review and are not a substitute for advice about a specific business, jurisdiction, or processing activity.