TTimastra CollectOpen workspace →
SUBPROCESSORS & DATA LOCATIONS

Know where Timastra Collect depends on others

This disclosure identifies the providers that can process Timastra Collect customer data, why they are used, and what is currently known about processing location.

Effective September 8, 2026 · Version 2026-09-08 · Pilot service

How to read this disclosure

Core providers support every hosted workspace. Conditional providers receive data only when the related commercial service is configured and used. Timastra Collect does not sell customer data, and source-code or development providers must not receive production customer records.

Current provider register

ProviderPurpose and dataProcessing location
VPS provider (deployment-specific)coreDedicated application hosting, network delivery, compute, and persistent block storage administered by the Timastra Collect operator.Account identity, organization records, financial-operating records, audit evidence, and service telemetry entered or generated in Timastra Collect.The operator must select and disclose the contracted VPS provider, legal entity, processing region, DPA, subprocessors, and transfer mechanism before commercial use.Timastra Collect hosting disclosure
StripeconditionalHosted subscription checkout, billing portal, invoices, payment collection, refunds, credits, tax totals, and signed lifecycle events.Billing-contact details, organization and plan references, subscription and invoice information, and payment data supplied directly to Stripe-hosted pages.Stripe may process personal data globally, including transfers to the United States and to affiliates and subprocessors in other jurisdictions.Stripe data processing agreement
PolarconditionalMerchant-of-record checkout and subscription billing, customer portal, receipts, tax handling, refunds, and signed lifecycle events.Billing-contact email and name, organization and checkout references, selected product, and subscription and invoice records. Payment details are entered directly on provider-hosted pages.Provider-managed processing. Contracting entity, locations, retention, DPA and international-transfer terms must be confirmed before live activation; no local data-residency commitment is asserted.Provider privacy policy
Lemon SqueezyconditionalMerchant-of-record checkout and subscription billing, customer portal, receipts, tax handling, refunds, and signed lifecycle events.Billing-contact email and name, organization and checkout references, selected product, and subscription and invoice records. Payment details are entered directly on provider-hosted pages.Provider-managed processing. Contracting entity, locations, retention, DPA and international-transfer terms must be confirmed before live activation; no local data-residency commitment is asserted.Provider privacy policy
ResendconditionalTransactional email delivery and signed delivery, bounce, complaint, and suppression events.Recipient address, organization and user display names needed by a template, message content, delivery metadata, and provider event identifiers.Resend states that account data, email metadata, logs, and API records are stored in the United States; the configured sending region controls dispatch, not account-data residency.Resend regions and data residency
BrankasconditionalProvider-hosted bank authorization and read-only Statement account, balance, and transaction data retrieval.Consent and connection references, bank and account identifiers, masked account details, balances, transaction dates, amounts, directions, descriptions, and status metadata.Provider-managed processing. Timastra Collect has not published contractually confirmed Brankas processing or storage locations; the applicable entity, DPA, subprocessors, retention, and transfer mechanism must be approved before live use.Brankas privacy notice

Conditional-provider boundary

Stripe, Polar, Lemon Squeezy, Resend, and regional bank-data providers remain conditional until their hosted credentials and approved configuration are installed. Every bank-data provider requires explicit customer consent, market coverage, and approved live access before data is retrieved. Enabling another accounting, banking, analytics, observability, support, AI, or communication provider requires a security and privacy review and an update to this register before production customer data is sent.

Location and transfer limits

A sending region, edge location, or latency hint is not necessarily a data-residency commitment. The contracting entity, provider terms, DPA, subprocessor list, storage configuration, backup locations, international-transfer mechanism, and legally required notices must be confirmed for the customer and market before commercial launch.

Changes and questions

Material provider or location changes are reviewed before activation and reflected by a new version and effective date. Open a DPA or Privacy request through Help & legal to request the current contractual schedule, object to a proposed provider where applicable, or ask how a provider applies to your workspace.