Subprocessors
Effective date: August 14, 2026
GradeThread (Pearson Media LLC) engages the third-party subprocessors below to provide the Service. Each processes personal data only as needed for its stated purpose and under contractual data-protection obligations. This list is referenced by our Privacy Policy and Data Processing Addendum.
1. Current subprocessors
Last updated: August 14, 2026.
| Subprocessor | Purpose | Data processed | Primary location |
|---|---|---|---|
| Supabase (self-hosted) | Database, auth, storage | Account data, grading photos, grades | United States |
| Cloudflare | CDN, Pages hosting, R2 object storage, WAF | Request metadata, served content, stored assets | Global (US-config) |
| Stripe | Payments & subscription billing | Billing details, payment tokens, email | United States |
| Anthropic | AI condition grading & listing generation (Claude) | Garment photos, listing text (no account PII) | United States |
| OpenAI | Listing/marketing image generation | Image prompts/inputs | United States |
| eBay | Marketplace listing, orders, payouts (FlipDesk) | Listing content, order/payout data | United States |
| Etsy | Marketplace listing & orders (FlipDesk) | Listing content, order data | United States |
| Depop | Marketplace listing & orders (FlipDesk) | Listing content, order data | United Kingdom / United States |
| Whatnot | Marketplace listing & orders (FlipDesk) | Listing content, order data | United States |
| Shopify | Storefront listing & orders (FlipDesk) | Listing content, order data | Canada / United States |
| Google (Alphabet) | Sign-in, Sheets sync into the seller's own Drive, Photos import, Android push (FCM), Google Play billing, Google Ads & Search Console reporting | Email address, inventory rows the seller syncs, selected photos, device push tokens, purchase receipts | United States |
| Apple | Sign in with Apple, iOS push (APNs), App Store in-app purchases | Email address (or Apple's private relay address), device push tokens, purchase receipts | United States |
| Intuit (QuickBooks Online) — only when connected | Accounting sync: the seller's own sales, fees, expenses and payouts pushed into their QuickBooks company file | Transaction amounts, dates, account names and receipt images the seller chooses to sync. No buyer PII and no garment photos. | United States |
| remove.bg (Kaleido AI) — only when enabled | Optional background removal on a listing photo | The single garment photo submitted for removal | Austria / European Union |
| Sentry | Error monitoring | Redacted error context, request metadata | United States |
| PostHog | Product analytics (consent-gated) | Usage events, pseudonymous identifiers | United States |
| Email/SMTP provider (e.g. Amazon SES) | Transactional & lifecycle email | Email address, message content | United States |
| Coolify host / VPS provider | Edge service + self-hosted Supabase hosting | All processed data in transit/at rest on the host | United States |
2. Changes & notification
We update this page when we add or replace a subprocessor and revise the “Last updated” date above. Customers with an active DPA may subscribe to change notifications by emailing [email protected]; we aim to provide reasonable advance notice of a new subprocessor so you can raise any objection.
3. Contact
Questions about our subprocessors or data processing: [email protected].
