Current Subprocessors
The following processors handle personal data on behalf of Moshi Inc. We will update this list before adding or replacing a subprocessor.
Cloudflare, Inc.
- Purpose: Image storage (R2), structured data (D1), edge compute (Workers), key-value cache (KV), CDN delivery, and background bot protection on sign-in and signup forms (Turnstile).
- Data: All categories of personal data we process — encrypted at rest and in transit. For bot protection, Turnstile evaluates request signals (IP address, TLS fingerprint, user agent) in the background without setting cross-site cookies; see Cloudflare's Turnstile Privacy Addendum.
- Region: Global edge network; primary data residency in the United States.
- Transfer mechanism (EU/UK): EU–U.S. Data Privacy Framework + Standard Contractual Clauses.
- DPA: Cloudflare Data Processing Addendum (v6.4, effective 3 April 2026).
Amazon Web Services, Inc.
- Purpose: Transactional email delivery (SES) and automated content-safety classification of uploaded images (Rekognition).
- Data: Recipient email address and message content for SES; downscaled image bytes for Rekognition (not retained for training).
- Region: us-east-1 (United States).
- Transfer mechanism (EU/UK): EU–U.S. Data Privacy Framework + Standard Contractual Clauses.
- DPA: AWS GDPR DPA + UK GDPR Addendum, auto-applied via the AWS Customer Agreement.
Stripe, Inc.
- Purpose: Payment processing for paid subscriptions; fraud screening; tax computation and collection (Stripe Tax) including EU VAT.
- Data: Billing name, address, and payment-method data — collected directly by Stripe; we never see card numbers.
- Region: United States and Ireland.
- Transfer mechanism (EU/UK): Standard Contractual Clauses.
- DPA: Stripe Data Processing Agreement (18 November 2025).
PostHog, Inc. (PostHog Cloud EU)
- Purpose: Product analytics, funnel and retention analysis, heatmaps, browser exception and performance monitoring, privacy-masked session replay, bounded server-side product outcomes, and Stripe-backed subscription/revenue analysis.
- Data: The custom event stream contains sanitized route templates and referrer origins; validated UTM source, medium, and campaign dimensions; page and interaction activity; device and coarse location information derived from browser network requests; sanitized exception frames; performance timing; masked replay data; opaque account/app/workspace identifiers; and categorical product outcomes. Inputs and visible text are masked, user media and private content are blocked, and console output, request/response bodies, filenames, captions, authorization data, raw URL queries, search terms, ad-click identifiers, internal numeric IDs, exception messages, account names, and account emails are excluded from that stream. Separately, the native Stripe source synchronizes selected Subscription, Invoice, payment/charge, Refund, Product, Price, and Customer/billing fields, which may include Stripe object identifiers, billing contact fields, amounts, taxes, plan details, and payment/refund state. Access to those source tables and revenue models is restricted to authorized operators. PostHog may use a browser request IP for coarse GeoIP enrichment, after which our project setting discards the source IP.
- Region: European Union (PostHog Cloud EU is hosted in Frankfurt, Germany), with limited support and subprocessor access governed by PostHog's DPA.
- Transfer mechanism (EU/UK): PostHog's Data Processing Agreement, Standard Contractual Clauses, and UK terms where applicable. We do not enable covered PostHog processing until those terms are accepted and archived. In strict or unknown geolocations, browser analytics remains off until the user opts in.
- DPA and security: PostHog Data Processing Agreement and PostHog Trust Center.
Flodesk (Flodesk, Inc.)
- Purpose: Lifecycle and product-update email (only with consent where required).
- Data: Recipient email address, name, and subscription state.
- Region: United States (and other locations where Flodesk or its sub-processors operate).
- Transfer mechanism (EU/UK): Standard Contractual Clauses.
- DPA: Flodesk Data Processing Addendum (version 27 May 2026). Contracting entity is Flodesk, Inc.
Reddit, Inc.
- Purpose: Server-side conversion measurement for paid acquisition (Reddit Conversions API).
- Data: SHA-256-hashed email (never plaintext), IP address, browser user agent, Reddit's ad-click identifier, and event metadata for users who arrived via Reddit ads.
- Region: United States.
- Transfer mechanism (EU/UK): Standard Contractual Clauses.
- DPA: Reddit Advertising Data Processing Agreement (effective 7 August 2025), auto-applied via the Reddit Advertising Services Agreement. Reddit's own subprocessor list: Reddit Ads Subprocessors.
Changes
We will update this page when a subprocessor is added or replaced. If you would like to be notified of changes (typical for enterprise customers), email privacy@img.pro.