This list distinguishes core Subprocessors that may process customer or end-user information on our behalf from customer-directed integrations or third-party services enabled by customer choice.
1. Core Subprocessors
| Vendor | Purpose | Typical Data Involved | Applies To |
|---|---|---|---|
| Vercel, Inc. | Application hosting, edge delivery, hosted website publishing, domains, deployment infrastructure | account identifiers, hosted site content, logs, visitor/request metadata, form traffic | platform and hosted websites |
| Neon, Inc. | Managed PostgreSQL database hosting | account records, subscriptions, site configuration, form submissions, analytics metadata, support-linked records | platform |
| Stripe, Inc. | Billing, subscription management, payment processing | billing contacts, subscription metadata, invoice and transaction records | billing |
| Brevo | Transactional and CRM-related email workflows | email address, name, auth-related and support-related communications, contact metadata | platform |
| Resend | Transactional email delivery and templated notifications | recipient details, email content, website lead notification content, report delivery metadata | platform and hosted website notifications |
| Anthropic, PBC | AI generation and analysis features | prompts, business context, generated drafts, assistant interactions | AI features if enabled |
| DataForSEO Ltd. | Search, ranking, SERP, map, keyword, and AI visibility data services | search terms, business/location queries, SEO task parameters, result metadata | SEO, public audit, and visibility features |
| Umami Software, Inc. or Umami Cloud provider | Hosted website analytics | page path, referrer, device/browser, region, event metadata, site identifiers | hosted website analytics if enabled |
| Microsoft Corporation | Product usage or session analytics on platform-owned pages if enabled | device/browser/session interaction data, page activity, IP-related metadata as processed by the vendor | platform-owned sites/apps if enabled |
| Meta Platforms, Inc. | Advertising attribution and conversion measurement if enabled | page activity, event metadata, browser/device identifiers, IP-related metadata as processed by the vendor | platform-owned marketing pages |
2. Customer-Directed Integrations and External Platforms
The following services may be connected or used at customer direction. They are not necessarily our Subprocessors in every context and may instead act as independent platforms or separate controllers/processors depending on the feature and data flow.
| Service | Typical Use |
|---|---|
| Google LLC | OAuth login, Google Business Profile, Search Console, Google Ads, Local Services Ads, maps, places, and related integrations |
| WordPress or Customer-Managed WordPress Hosts | content sync, publishing, site connection, and website management features |
| Customer-added website scripts or custom embeds | customer-directed analytics, pixels, widgets, chat, maps, or media embeds added to hosted websites |
3. How We Update This List
We may update this list from time to time as our service providers and infrastructure evolve.
Where required by contract or applicable law, we will provide notice of material changes to this list by:
- posting an updated list at nesta.so; or
- using another reasonable notice method.
4. Questions
Questions about this list may be sent to:
- Privacy: support@nesta.so
- Support: support@nesta.so