Last updated: · App not yet released
Sub-Processors
1. Introduction
A "sub-processor" is a third-party service provider that processes personal data on Cookrange's behalf (e.g. hosting or database providers). This page transparently lists which providers process your data, for what purpose, and where. For the general rules governing these transfers, see the "International Transfers" section of our Privacy Policy.
2. Current Sub-Processor List
| Provider | Service | Data Category Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Vercel Inc. | Website hosting, CDN, serverless/edge functions (e.g. waitlist form processing) | Technical usage data, form submission data | US / global edge network | Standard Contractual Clauses (to be confirmed) |
| Google LLC (Firebase / Google Cloud Platform) | Authentication, Firestore database, cloud functions, file storage (Storage), realtime database (presence and typing), push notifications (Cloud Messaging), crash reporting (Crashlytics), product analytics (Analytics), performance traces (Performance), remote configuration (Remote Config) and abuse protection (App Check) | Account data, health/nutrition data, waitlist records; photographs you upload — profile pictures, meal and progress photos, images sent in chat; your device’s push token; crash reports and performance timings, which include device model and app version but no health data; and online/typing status | Region selection to be confirmed (e.g. EU or US data center) | Standard Contractual Clauses (to be confirmed) |
| Google LLC (Google Analytics / Google Tag Manager) | Web analytics — only once you consent in the cookie notice (Google Consent Mode v2, see Cookie Policy §5) | Usage/interaction data, device/browser information, truncated IP | US (Google's standard infrastructure) | Standard Contractual Clauses (to be confirmed) |
| Microsoft Corporation (Clarity) | Heatmaps and session recording — only once you consent in the cookie notice | Anonymous session/click data, page interaction | US/EU (Microsoft's standard infrastructure) | Standard Contractual Clauses (to be confirmed) |
| OpenRouter, Inc. | AI generation — meal plans, recipe generation, chat, and coach progress reports are processed through this provider | In-app AI prompts: your body metrics, goals, allergies and dietary restrictions, and the meals you have logged; for meal-photo analysis, the photograph itself and any note you add to it; coach report generation additionally sends the member's name and streak data. Cookrange does not keep the prompt or the photo — only which model answered and what it cost. | US-based (region to be confirmed) | Standard Contractual Clauses (to be confirmed) |
| Apple Inc. (App Store) / Google LLC (Google Play) | Premium purchase processing — the payment itself runs through these stores; Cookrange never sees your card details | Purchase transaction record, subscription status (including the store's own identifier tied to your account) | The store's own global infrastructure | The respective store's own developer agreement/privacy terms |
| Open Food Facts (Open Food Facts Association) | Barcode product lookup — nutrition and product information for a scanned barcode | Device IP address at query time and the scanned barcode number. The query is made directly from the app and does not pass through Cookrange's servers; no identifier that could be linked to your account is sent | EU (association based in France) | Provider's own privacy policy (to be confirmed) |
| OpenStreetMap Foundation (OpenStreetMap + Nominatim) | Gym map display and reverse geocoding for a gym's address (location picked on the map) | Device IP address during map-tile and reverse-geocoding requests; the queried coordinate (only during gym setup, for the location the gym owner themself enters) | EU (OSMF is a UK-based foundation) | Provider's own privacy policy (to be confirmed) |
3. Categories Not Yet Selected
No provider has been chosen yet for the following categories; we do not invent a provider name here that hasn't actually been decided:
- Transactional/marketing email delivery provider: to be selected.
- Bot/abuse protection (e.g. Cloudflare Turnstile): decided in the architecture but not yet integrated — today the forms are protected only by server-side rate limiting, a honeypot and a timing check, and no data in this category reaches any third party.
- Ad-measurement pixel (e.g. Meta Pixel, Google Ads): whether it will be used, and which provider, is to be selected.
Once these are finalized, this table will be updated with the real provider name, location, and transfer mechanism.
4. Notice of Changes
When a new sub-processor is added or an existing one changes, this page is updated and the "Last updated" date at the top changes accordingly. Questions:contact@cookrangeapp.com.