Sub-processors
TapBerry · Effective 16 Aug 2026
These are the third parties that can touch data on our behalf. Each is bound to use it only to provide its service to us. The list is short because the stack is deliberately small.
1. Current sub-processors
| Provider | What it does | Data it can touch | Region |
|---|---|---|---|
| Vercel | Hosts and serves the web application | Request data in transit, server logs | Mumbai (bom1), with a global edge network |
| Railway | Runs the API and the database | All application data at rest | Asia-Pacific |
| Stripe | Takes subscription payments from shops | Shop owner billing contact and card details. No customer data | Global, per Stripe’s own terms |
| Apple (Wallet / APNs) | Stores the pass on the customer’s device and delivers card updates | Pass contents and the device push token | Apple’s global infrastructure |
| Google (Wallet) | Stores the pass on the customer’s device and delivers card updates | Pass contents and the device push token | Google’s global infrastructure |
| Google Places | Looks up shop addresses so nobody types one by hand | Business addresses only. No personal data | Google’s global infrastructure |
2. What is deliberately absent
No advertising network, no data broker, no third-party analytics on customer-facing pages, and no CRM that ingests your customer list. Every one of those would have to appear on this list, and none of them earns its place.
3. Changes to this list
We add a provider to this page on the day it reaches production, not afterwards. Shop owners get email notice at least thirty days before a new sub-processor starts handling customer data, and can object — in practice that means telling us, and us finding another way or parting company fairly.
To be notified of changes, write to support@tapberry.io. How the underlying data is handled is in the Privacy Policy.
Questions about this policy: support@tapberry.io. Something wrong with your card or your shop: support.