Umbrella engages the sub-processors listed below to help deliver the Services. Each sub-processor is bound by a data processing agreement that requires at least the same level of data protection as Umbrella's own Data Processing Addendum.
Under Section 6.2 of the DPA, Umbrella will give merchants at least 15 days' notice before adding or replacing a sub-processor. To receive notifications, email privacy@myumbrella.ai with "Sub-processor updates" in the subject line.
| Entity | Category | Purpose | Data processed | Location |
|---|---|---|---|---|
| Vercel Inc. | Cloud Infrastructure | Hosts and serves the Umbrella platform and marketing site — serverless compute, CDN delivery, and IP-based geolocation for locale detection. | IP addresses, request metadata, session data, application logs. | United States |
| Neon Inc. | Database | Serverless PostgreSQL database that stores all platform data, including merchant accounts, warranty policies, claims, and customer records. | All customer personal data, merchant data, warranty and claim records. | United States |
| Cloudflare Inc. | Cloud Storage | R2 object storage for file uploads, including claim photos, documents, and other attachments submitted during the warranty claim process. | Uploaded files and attachments (claim photos, receipts, supporting documents). | United States |
| Upstash Inc. | Cache & Message Queue | Serverless Redis for caching and session management; QStash for background job queuing and message processing. | Cached session data, queued job payloads (may include personal data in transit). | United States |
| Clerk Inc. | Authentication & Identity | Identity and access management for merchant and team member authentication, organization management, and session handling. | Email address, name, profile data, authentication events, organization membership. | United States |
| Mailgun (Sinch) | Transactional Email | Delivers transactional emails to end customers and merchants — policy confirmations, claim status updates, and support correspondence. | Email address, name, email content (claim and policy details). | United States |
| Klaviyo Inc. | Email Marketing | Manages email list subscriptions and marketing communications for merchants and prospects who opt in via platform forms. | Email address, first name, last name, company, opt-in status. | United States |
| Functional Software, Inc. (Sentry) | Error Monitoring | Application error tracking and performance monitoring to detect and diagnose platform issues. | Error stack traces, request context, user identifiers (may be included in error payloads). | United States |
| Better Stack, Inc. (Logtail) | Log Aggregation | Centralized log management and monitoring for platform infrastructure and application events. | Application logs, which may include request metadata and user identifiers. | United States |
| Google LLC | Analytics | Google Analytics 4 measures platform and marketing site usage — page views, conversion events, and user flows. | IP addresses (anonymized), device identifiers, browser type, pages visited, events. | United States |
| Google LLC | Font Delivery | Google Fonts delivers the Inter typeface used across the platform and marketing site. | IP address, browser/device information (via font CSS request). | United States |
| UploadThing (Ping Labs, Inc.) | File Upload | Manages secure file upload flows for claim attachments and other user-submitted documents. | Uploaded files and associated metadata. | United States |
| OpenAI LLC | AI / LLM | Powers AI-assisted features on the platform, including the Copilot and command interface. | Text inputs submitted to AI features, which may include claim descriptions or other user-provided content. | United States |
| Shopify Inc. | E-commerce Integration | Bi-directional integration for merchants on Shopify — order data, customer records, and warranty plan fulfilment. | Customer name, email, shipping address, order details, product information. | Canada |
International transfers
All sub-processors listed above are headquartered in the United States. Transfers of personal data from the EEA, UK, or Switzerland to these sub-processors are governed by the Standard Contractual Clauses (EU SCCs) or the UK International Data Transfer Addendum, as described in Section 7 of the DPA.
Questions
For questions about this list, notifications of changes, or to exercise rights under the DPA, email privacy@myumbrella.ai.


