Legal
Subprocessors
Last updated July 28, 2026
SwiftSign uses the providers below to operate the service. They may process customer personal data only to provide their contracted services to SwiftSign.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting, edge delivery, and operational logs | Account, request, device, and service-usage data |
| Neon | Managed PostgreSQL database infrastructure | Account, envelope, recipient, signing-audit, and configuration data |
| Cloudflare | R2 document and generated-file storage | Uploaded documents, page images, signed documents, and certificates |
| Resend | Transactional email delivery | Sender and recipient email addresses, message content, and delivery events |
| Stripe | Subscription billing, checkout, invoices, and payment administration | Customer, billing, subscription, and payment-related data |
| Upstash | Rate limiting and service-abuse prevention | Network identifiers and request-rate metadata |
| Sentry | Error reporting, diagnostics, and service reliability | Error, request, device, and diagnostic data with secrets scrubbed |
Changes and objections
We may update this list as the service changes. Material changes will be posted here before the new provider begins processing customer personal data where reasonably practicable. Customers with a reasonable data-protection objection should email support@swiftsign.ca.
Contractual protections
We require subprocessors to protect personal data and process it only for the services they provide to us. The Data Processing Addendum explains the terms that apply when SwiftSign processes personal data for a customer.