← Slidesfly

Service Providers and Subprocessors

Last reviewed: 2026-08-01

This list explains which third-party services may process data for Slidesfly. “Core” means the provider is part of the normal production path. “Conditional” means it is used only when that feature, integration, consent, or customer billing relationship applies.

Current provider list

Vercel — Application hosting and edge delivery

  • Use: Core
  • Purpose: Serve slidesfly.com and run the web application and APIs.
  • Data: Request metadata, IP address, user agent, application responses, and operational logs.
  • Location and transfer: Provider infrastructure; international processing may apply.
  • Provider privacy information

Supabase — Database and authentication

  • Use: Core
  • Purpose: Store accounts, deck metadata, access policy, analytics aggregates, and auth state.
  • Data: Account email, product records, authorization data, and service metadata.
  • Location and transfer: Project-region and provider infrastructure; international support access may apply.
  • Provider privacy information

Cloudflare — DNS, private object storage, and content gateway

  • Use: Core
  • Purpose: Store deck assets in R2 and deliver approved reader content through policy controls.
  • Data: Deck files, object metadata, request metadata, IP address, and security signals.
  • Location and transfer: Provider infrastructure; international processing may apply.
  • Provider privacy information

Resend — Transactional email delivery

  • Use: Conditional
  • Purpose: Send account, access, and service notifications when email delivery is configured.
  • Data: Recipient email, message content, and delivery metadata.
  • Location and transfer: Provider infrastructure; international processing may apply.
  • Provider privacy information

Upstash — Rate limiting

  • Use: Conditional
  • Purpose: Protect publish, authentication, and other abuse-sensitive request paths.
  • Data: Pseudonymous request keys, rate-limit counters, and expiry metadata.
  • Location and transfer: Configured service region and provider infrastructure.
  • Provider privacy information

PostHog — Optional product analytics

  • Use: Conditional
  • Purpose: Measure consented product usage and acquisition flows.
  • Data: Event metadata, page path, pseudonymous identifiers, and consented acquisition IDs.
  • Location and transfer: Configured analytics region and provider infrastructure.
  • Provider privacy information

Sentry — Optional error monitoring

  • Use: Conditional
  • Purpose: Detect and diagnose application failures when monitoring is configured.
  • Data: Scrubbed error, stack, runtime, and request metadata; secrets and deck content are excluded.
  • Location and transfer: Configured Sentry region and provider infrastructure.
  • Provider privacy information

Waffo Pancake — Payment processing and merchant of record

  • Use: Conditional
  • Purpose: Operate paid checkout, tax, fraud, billing, refunds, and chargebacks when selected.
  • Data: Checkout identity, billing, tax, fraud, and transaction data submitted to Waffo.
  • Location and transfer: Waffo Group infrastructure and payment partners; international processing may apply.
  • Provider privacy information

Clink — Supported payment processor and merchant of record

  • Use: Conditional
  • Purpose: Operate checkout, tax, fraud, billing, refunds, and chargebacks when selected.
  • Data: Checkout identity, billing, tax, fraud, and transaction data submitted to Clink.
  • Location and transfer: Clink infrastructure and payment partners; international processing may apply.
  • Provider privacy information

Stripe — Supported or historical payment provider

  • Use: Conditional
  • Purpose: Operate checkout or subscription management when Stripe is the applicable provider.
  • Data: Checkout identity, billing, fraud, and transaction data submitted to Stripe.
  • Location and transfer: Stripe infrastructure and payment partners; international processing may apply.
  • Provider privacy information

Important boundaries

  • The provider presented at checkout controls the payment data submitted there.
  • Optional analytics run only after the applicable consent and configuration gates.
  • Provider regions and international transfers depend on the active project, contract, customer location, and provider infrastructure; this page does not claim one fixed processing region for every user.
  • This transparency list does not replace a provider contract or Data Processing Addendum.

Questions and change notices

Request current configuration or data-transfer details at privacy@slidesfly.com. Material provider changes will update the review date on this page.

See also our Privacy Policy, Security architecture, and Terms of Service.