Subprocessors
This page lists the providers to which our platform sends personal data through an integration confirmed in the code. A provider is not listed merely because it was discussed during development.
How this register is maintained
It is based on a code audit of the repository from 2026-09-16, last updated on 2026-09-23. The list is updated whenever a provider's integration changes.
Processing locations are stated where they are established.
Changes to this register are recorded in the change history. For the procedure towards PRO businesses (advance notice, right to object) see the Data Processing Agreement (DPA), section "Subprocessors".
| Provider | Purpose | Data | Role | Processing country / transfer |
|---|---|---|---|---|
| Infomaniak (Infomaniak Network SA, Genf) | Hosting of the platform on Infomaniak Public Cloud: application servers, database, cache/queue (Redis) and uploaded files (salon images, verification and claim documents) | All data stored by the platform: accounts, bookings, business, staff and customer data, and uploaded files | Processor (hosting on our behalf) | Switzerland — application servers, database, file storage and backups run on Infomaniak Public Cloud. Backups are encrypted before they leave the server and kept for 14 days on the server and 30 days in object storage |
| Resend | Transactional email delivery (login codes, account notices, booking confirmations/reminders/changes, PRO billing and team emails) | Recipient email address, subject and message content — e.g. one-time codes, name, salon name, appointment date/time and services, billing status | Processor (email delivery on our behalf), under Resend's data processing agreement | USA — Resend stores customer data, including message content and delivery logs, in the United States. Logs are kept for 30 days and backups for 7 days |
| Stripe | Payment processing — two separate flows: Stripe Billing (PRO subscription payment to Stylingcorner) and Stripe Connect direct charges (customer payment to the beauty business, incl. TWINT) | Billing: company name, billing email, internal company/plan identifiers; Stripe returns card brand/last 4 digits/expiry for display. Connect: amount, currency and internal booking identifiers (company, checkout session, appointment); card/TWINT details are entered directly in Stripe's payment form — Stylingcorner never receives full card data | Payment service provider acting partly as a processor and partly as an independent controller (for example for fraud prevention and its regulatory duties), as set out in Stripe's data processing agreement; for Connect payments the contractual relationship is primarily between Stripe and the business | Stripe processes data in the United States and other countries |
| Expo (Expo Push Service) | Relaying push notifications to the Stylingcorner mobile app; Expo forwards them to Apple (APNs, iOS) or Google (Firebase Cloud Messaging, Android) for delivery to the device | Device push token and the notification itself: title and text (e.g. salon name, appointment weekday/time) plus a data payload with the notification ID, notification type and the related appointment or review ID | Processor (push relay on our behalf). Only involved when you use the Stylingcorner app and allow notifications; Apple and Google operate their push services under their own terms | — |
| Google Maps Platform (Google Ireland Limited / Google LLC) | The salon-search map, the address autocomplete in Stylingcorner PRO, and turning a visitor's shared coordinates into a town name | Visitor IP address, browser user agent, the map area viewed, address search terms typed in PRO, and — only where the visitor has granted the browser's location permission — their approximate coordinates | Receives the browser's request directly, under Google's own Maps Platform terms | — |
Apple and Google platform services (mobile app)
Not processors engaged by Stylingcorner — details on the "International Data Transfers" page.
- Apple (iOS) / Google (Android) — push delivery
- Apple Maps (iOS) / Google Maps SDK (Android) — in-app map
- Apple / Google — reverse geocoding on the device
- Google Maps (link) — directions
Confirmed not in use
- Any SMS provider (one-time codes are delivered by email only, via Resend)
- Any external analytics or tracking SaaS (no Google Analytics, PostHog, Mixpanel, Meta Pixel, Hotjar, Segment or Plausible integration exists). Stylingcorner does run its own consent-based usage statistics on the website — see "Cookies & Tracking"
- Any separate cloud storage/CDN vendor for photos (uploaded files are stored on our own hosting at Infomaniak, listed above)
- Any monitoring, error-tracking or APM tool (no Sentry, Datadog, LogRocket or New Relic integration exists)
- Mapbox anywhere (the website map uses Google Maps Platform — see the subprocessor register; for the mobile app see the platform services)
