Skip to main content
Railyard
DocsAPI reference

Sub-processors

Every provider that processes data on our behalf. Last reviewed 2 October 2026.

The list

These are the providers we use to run Railyard. Each is bound by a written contract, may use personal data only to provide its service to us, and is held to obligations no less protective than those we owe you under our Data Processing Agreement. This page is Annex III to that agreement.

Some rows are not yet confirmed. 2 entries are marked "to be confirmed" below: the role is accurate, but the provider's identity is being verified against the running deployment before we assert it. Ask [email protected] for the current position before relying on this page in a procurement assessment.

ProviderRoleWhat it does for usData involvedWhereTransfer safeguard
Hosting and managed database provider — to be confirmedProcessorApplication hosting, the PostgreSQL database that stores your account and designs, and encrypted backups of itAll account data and Customer Data stored by the ServiceUnited KingdomNo transfer out of the UK: processing and backups stay in the United Kingdom.
Cloudflare, Inc.ProcessorAuthoritative DNS, TLS termination at the edge, denial-of-service protection, and inbound email routing for our published addressesIP address, request metadata and traffic in transit; inbound email addressed to usGlobal edge network, United States parentUK International Data Transfer Addendum and EU Standard Contractual Clauses under Cloudflare's data processing addendum. Requests from the UK and EU are normally served from a UK or EU edge location.
Resend (Plus Five Five, Inc.) — to be confirmedProcessorSending transactional email: sign-in codes, organisation invitations, security and account notices, billing and dunning notices, trial and plan notices, review and merge-request notifications, and email-change confirmationsRecipient email address and the content of the messageUnited StatesUK International Data Transfer Addendum and EU Standard Contractual Clauses under the provider's data processing agreement.
Stripe Payments Europe, Ltd. and Stripe, Inc.Processor and independent controllerTaking payment, running subscriptions and issuing invoices — only if you choose a paid plan. Stripe is also an independent controller when it uses payment data for its own fraud prevention, anti-money-laundering and regulatory obligations, which we do not direct and cannot switch offBilling contact email and name, card details you enter directly with Stripe (we never receive them), plan and subscription status, invoices and payment recordsIreland, with group processing in the United StatesEU Standard Contractual Clauses and the UK Addendum under Stripe's data processing agreement. For Stripe's own controller processing, see Stripe's privacy policy.

Where the Service runs

Railyard is hosted in the United Kingdom. Your account data and designs — the database and its encrypted backups — are stored there. We publish the hosting jurisdiction so you can assess it for your own compliance, including under Article 28 of the EU Data Act.

Stripe is also an independent controller

Stripe processes subscription data on our instructions, but it is additionally an independent controller when it uses payment data for its own fraud prevention, anti-money-laundering and regulatory obligations. We do not direct that processing and cannot switch it off. Stripe's own privacy policy governs it. We say so here because describing Stripe as "our processor" alone would misdescribe the relationship.

Identity providers are not sub-processors

When you sign in with Google, GitHub, Okta or another supported provider, that provider is not processing data on our instructions. It is your provider, acting as its own controller, and it releases to us only the verified profile you allow — your email address, and your name and avatar where available. It may log the sign-in under its own policy, which we neither control nor see. Single sign-on is open to any user whose provider we support; it is not something an organisation has to enable for you.

Clients and AI assistants you connect

If you connect an AI assistant or another client through our connector interface, or use a personal access token in a script or plugin, that client reads and writes your data with your access. Anything it sends onward goes to a provider you chose, under your agreement with them — we are not a processor for that onward processing, and it is not listed above. You can review and revoke connected clients and tokens in account settings.

How we tell you about changes

We publish any new or replacement sub-processor here at least 30 days before it starts processing personal data, except where a shorter period is unavoidable to keep the Service secure or available — in which case we say why.

To be emailed when this page changes, write to [email protected] and ask to join the sub-processor notice list. Customers may object to a change on reasonable data-protection grounds; clause 7 of the DPA explains what happens then, including your right to terminate without penalty if we cannot resolve it.

Private deployments

Where a private deployment is agreed with your organisation, the operator of that deployment chooses its own hosting, email and network providers. Those are named in that agreement, not here.

RailyardRack layouts, topologies, cabling and capacity — in one place.
DocsAPI referenceFeedbackRoadmapTermsPrivacyDPASecurityAccessibilityContact
© 2026 Railyard · Operated from England and Wales; registered company details to be published — see Terms §1