Subprocessors
Last updated . Questions: [email protected]
These are the service providers we intend to use to run Arrhis, and what each one processes on our behalf. We will update this page before adding or replacing a provider.
| Purpose | Provider | What it processes | Status |
|---|---|---|---|
| Hosting | Vercel | Web application and API requests, including account and room data in transit | Planned for launch |
| Database | Turso | Account data, room settings, NDA records, view analytics, synced data from connected sources, encrypted credentials | Planned for launch |
| Resend | Email addresses and message content for sign-in links, verification and room notices | Planned for launch | |
| E-signature | DocuSeal | Signer name, email, IP address, user agent and the signed NDA | Planned for launch |
| File storage | S3-compatible object storage (for example Cloudflare R2) | Files uploaded by sellers | Planned for launch |
| Identity checks (optional, buyers) | Stripe Identity | ID document and selfie, handled by Stripe; we receive the result, verified name, document type and issuing country | Planned for launch |
| Payments | Stripe | Purchaser name, email and payment details for room passes, extensions, Exit Packs and advisor plans | Planned for launch |
| Website analytics | Plausible | Aggregate page views and referrers on our marketing site, without cookies | Planned for launch |
Your own connected accounts are not subprocessors
When a seller connects Stripe, Mercury or Google Analytics, we read data from the seller's own account with read-only access. Those companies are the seller's providers, not ours, and their own terms apply to that account. Payments to Arrhis go through our own Stripe account, which is listed above.
How we use and protect the data these providers handle is described in our privacy policy. Questions: [email protected].