Last updated:
Sub-Processors
1. Introduction
A "sub-processor" is a third-party service provider that processes personal data on Cookrange's behalf (e.g. hosting or database providers). This page transparently lists which providers process your data, for what purpose, and where. For the general rules governing these transfers, see the "International Transfers" section of our Privacy Policy.
2. Current Sub-Processor List
| Provider | Service | Data Category Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Vercel Inc. | Website hosting, CDN, serverless/edge functions (e.g. waitlist form processing) | Technical usage data, form submission data | US / global edge network | Standard Contractual Clauses (to be confirmed) |
| Google LLC (Firebase / Google Cloud Platform) | Authentication, Firestore database, cloud functions | Account data, health/nutrition data, waitlist records | Region selection to be confirmed (e.g. EU or US data center) | Standard Contractual Clauses (to be confirmed) |
| Google LLC (Google Analytics / Google Tag Manager) | Web analytics — only once you consent in the cookie notice (Google Consent Mode v2, see Cookie Policy §5) | Usage/interaction data, device/browser information, truncated IP | US (Google's standard infrastructure) | Standard Contractual Clauses (to be confirmed) |
| Microsoft Corporation (Clarity) | Heatmaps and session recording — only once you consent in the cookie notice | Anonymous session/click data, page interaction | US/EU (Microsoft's standard infrastructure) | Standard Contractual Clauses (to be confirmed) |
| OpenRouter, Inc. | AI generation — meal plans, recipe generation, chat, and coach progress reports are processed through this provider | In-app AI prompts (meal/goal/restriction data); coach report generation additionally sends the member's name and streak data | US-based (region to be confirmed) | Standard Contractual Clauses (to be confirmed) |
| Apple Inc. (App Store) / Google LLC (Google Play) | Premium purchase processing — the payment itself runs through these stores; Cookrange never sees your card details | Purchase transaction record, subscription status (including the store's own identifier tied to your account) | The store's own global infrastructure | The respective store's own developer agreement/privacy terms |
| OpenStreetMap Foundation (OpenStreetMap + Nominatim) | Gym map display and reverse geocoding for a gym's address (location picked on the map) | Device IP address during map-tile and reverse-geocoding requests; the queried coordinate (only during gym setup, for the location the gym owner themself enters) | EU (OSMF is a UK-based foundation) | Provider's own privacy policy (to be confirmed) |
3. Categories Not Yet Selected
No provider has been chosen yet for the following categories; we do not invent a provider name here that hasn't actually been decided:
- Transactional/marketing email delivery provider: to be selected.
- Bot/abuse protection (e.g. Cloudflare Turnstile): decided in the architecture but not yet integrated — today the forms are protected only by server-side rate limiting, a honeypot and a timing check, and no data in this category reaches any third party.
- Ad-measurement pixel (e.g. Meta Pixel, Google Ads): whether it will be used, and which provider, is to be selected.
Once these are finalized, this table will be updated with the real provider name, location, and transfer mechanism.
4. Notice of Changes
When a new sub-processor is added or an existing one changes, this page is updated and the "Last updated" date at the top changes accordingly. Questions:contact@cookrangeapp.com.