doable.do

Subprocessors

Last updated: September 1, 2026

These are the third parties Doable shares your data with to operate. Each has its own data-processing agreement linked below. We notify customers via email at least 14 days before adding a new subprocessor that touches customer data.

VendorPurposeData sharedRegionDPA
VultrCompute and storage for the Doable platform and customer workloadsAll customer data at rest (Postgres rows, build artifacts, application files)United StatesView
StripeSubscription billing for Doable plans, and the processor behind Doable Payments for merchants in the United States, Europe, and most other supported countriesCustomer email, name, billing address, payment-card token (we never see the card itself). For Doable Payments: merchant account status, buyer email, amount, currency, order referenceUnited States, EUView
Mercado PagoThe processor behind Doable Payments for merchants based in Chile, Argentina, Brazil, Colombia, Peru, and Uruguay. Merchants authorise Doable by OAuth; charges run on the merchant’s own Mercado Pago account.Merchant account identifier and OAuth tokens (encrypted at rest); buyer email, amount, currency, order reference, payment status. Card details go to Mercado Pago’s hosted checkout, never through Doable.Chile, Argentina, Brazil, Colombia, Peru, Uruguay; United StatesView
ResendTransactional email (deploy alerts, billing receipts, expiry notices)Recipient email, message content (delivery metadata only retained beyond 7 days)United StatesView
Firebase Authentication (Google)User sign-in, OAuth, and session token issuanceEmail, hashed password, OAuth provider tokensUnited StatesView
SentryError tracking for the dashboard, API, and workerStack traces, request paths, user ID (no PII bodies). 30-day retention.United StatesView
OpenAIDoctor self-healing diagnostics on failed deploysFailed-build log excerpts (no source code unless deliberately included by the user)United StatesView
CloudflareCDN, DDoS protection, TLS termination (when enabled)Request metadata (IP, user agent, URL); cached static asset bytesGlobal edgeView
OpenproviderDomain registrar. When you buy a domain through Doable, we send your registrant contact details (name, email, phone, postal address) to Openprovider, who registers it and is the registrar of record. ICANN requires this data to be accurate for as long as the domain exists.Domain name, plus the registrant contact details you enter when buying: name, email, phone, and postal address. ICANN requires these to be accurate and kept current for as long as the domain is registered.United StatesView
Porkbun (legacy)Domain registrar of record for domains purchased through Doable’s in-app flow prior to May 2026. New purchases no longer use Porkbun.Domain name, registrant contact details (only for legacy in-app purchases).United StatesView

When this list changes

We notify customers at least 14 days before adding a new subprocessor that processes personal data. Notification goes to the billing email on each account.

Customer-deployed code

When you deploy code through Doable, it runs in containers on our infrastructure (or on a server you connect via the BYO flow). The contents of those containers are your processing, not ours. Subprocessors above are the ones we use to operate the platform itself.

Data Processing Agreement

Doable’s standard Data Processing Agreement is offered to all paying customers. Email privacy@doable.do for a counter-signed copy.

Subprocessors – doable.do