A "subprocessor" is a third-party vendor we use to provide the toSend Service. Under our Data Processing Agreement and applicable privacy laws (including GDPR Article 28), you have the right to know who they are, what they do, and where they process data.
We keep the list short on purpose. Every vendor below is bound by a written data-processing agreement and processes data only on our documented instructions.
Notice of new subprocessors
We notify active customers by email of any new subprocessor at least 7 days before it starts processing your data, giving you time to object. You can reach our team at support@tosend.com.
Current subprocessors
| Subprocessor | Location | Purpose | Data processed | Data-processing agreement |
|---|---|---|---|---|
| Amazon Web Services, Inc. | United States; Germany (European Union) for teams on the EU (Frankfurt) sending region | Email delivery via Amazon SES. | Email envelopes (from, to, subject), message bodies while being sent, sender reputation signals, bounce and complaint feedback. | https://aws.amazon.com/compliance/gdpr-center/ |
| Cloudflare, Inc. | European Union for the database and message-body storage (EU jurisdiction). Requests are handled at the edge location nearest the sender, and a short-lived cache of account settings and suppressed addresses is replicated worldwide. | Email data plane (Workers, D1 database, R2 object storage, KV cache, Queues, Analytics Engine) and hosting for the public marketing website (tosend.com) on Cloudflare Pages. | API request metadata, email logs, message bodies (encrypted at rest, deleted after 14 days), suppression entries, webhook delivery logs, IP addresses, user-agent strings, public website access logs. | https://www.cloudflare.com/cloudflare-customer-dpa/ |
| Fly.io, Inc. | United States | Routing for the SMTP relay (smtp.tosend.com). Used only when you send over the SMTP protocol; API and SDK sends never touch it. It passes each message straight to our Cloudflare data plane and stores nothing. | Messages submitted over SMTP, in transit only (envelope, headers, body and attachments, plus the API key used as the SMTP password), and connecting IP addresses. No message data is written to disk or retained after the handoff. | https://fly.io/docs/security/security-at-fly-io/#compliance-documents |
| Hetzner Online GmbH | Germany (European Union) | Hosting for the customer dashboard (dash.tosend.com) — the control-plane UI where customers manage their account, domains, API keys, webhooks, and billing. | Account identifiers (email, hashed password, session tokens), tenant and organization settings, domain verification records, API key metadata, webhook configuration, billing view data, IP addresses, user-agent strings, server logs, and any data submitted through dashboard forms. The email-sending data plane (message bodies, delivery metadata) and the public marketing website run on Cloudflare, not Hetzner. | https://www.hetzner.com/legal/data-processing/ |
| Stripe, Inc. | United States | Payment processing, subscription billing, and credit purchases. | Billing name and address, email address, last four of card and brand (full card numbers are handled by Stripe and never reach our systems), invoice and transaction history. | https://stripe.com/legal/dpa |
Internal subprocessing
Customer support, outbound product emails (onboarding, account notifications), and our application infrastructure run on toSend itself and on our self-hosted tools. No third party processes those communications on our behalf.
Questions
For a signed Data Processing Agreement, subprocessor audit reports, or questions about this page, write to support@tosend.com.