Canopy uses the following providers to run the product. This list is part of the draft DPA. Regions describe where Canopy currently configures the service, not every possible edge location of a global CDN.
- Railway — application hosting and PostgreSQL in EU West (EEA)
- Amazon S3 — member avatars, ID documents, receipts, product images in eu-south-2 (Spain)
- Amazon CloudFront — delivery of media (global CDN in front of the EU bucket; private ID files use short-lived signed URLs)
- Amazon SES — transactional email in eu-west-1 (Ireland)
- Amazon Route 53 — DNS for canopy-os.com
- OpenAI — optional ID-document scan, CSV mapping, product AI, in-app assistant (United States; international transfer; SCCs)
- Stripe — club subscription billing (see Stripe DPA)
- Niftipay — optional card and crypto POS payment processing if the club enables it (see Niftipay DPA)
- GitHub — source control and CI (no production member database; United States)
- Sentry — application error monitoring and performance traces (EU Frankfurt region; US-headquartered; SCCs). Events exclude names, emails, and request bodies.
Staff and Canopy operators may access tenant data for support, security, and maintenance under confidentiality.
To object to a new subprocessor, the club owner should write to privacy@canopy-os.com after we publish a change.