Subprocessors
Last updated: September 1, 2026
These are the third parties Doable shares your data with to operate. Each has its own data-processing agreement linked below. We notify customers via email at least 14 days before adding a new subprocessor that touches customer data.
| Vendor | Purpose | Data shared | Region | DPA |
|---|---|---|---|---|
| Vultr | Compute and storage for the Doable platform and customer workloads | All customer data at rest (Postgres rows, build artifacts, application files) | United States | View |
| Stripe | Subscription billing for Doable plans, and the processor behind Doable Payments for merchants in the United States, Europe, and most other supported countries | Customer email, name, billing address, payment-card token (we never see the card itself). For Doable Payments: merchant account status, buyer email, amount, currency, order reference | United States, EU | View |
| Mercado Pago | The processor behind Doable Payments for merchants based in Chile, Argentina, Brazil, Colombia, Peru, and Uruguay. Merchants authorise Doable by OAuth; charges run on the merchant’s own Mercado Pago account. | Merchant account identifier and OAuth tokens (encrypted at rest); buyer email, amount, currency, order reference, payment status. Card details go to Mercado Pago’s hosted checkout, never through Doable. | Chile, Argentina, Brazil, Colombia, Peru, Uruguay; United States | View |
| Resend | Transactional email (deploy alerts, billing receipts, expiry notices) | Recipient email, message content (delivery metadata only retained beyond 7 days) | United States | View |
| Firebase Authentication (Google) | User sign-in, OAuth, and session token issuance | Email, hashed password, OAuth provider tokens | United States | View |
| Sentry | Error tracking for the dashboard, API, and worker | Stack traces, request paths, user ID (no PII bodies). 30-day retention. | United States | View |
| OpenAI | Doctor self-healing diagnostics on failed deploys | Failed-build log excerpts (no source code unless deliberately included by the user) | United States | View |
| Cloudflare | CDN, DDoS protection, TLS termination (when enabled) | Request metadata (IP, user agent, URL); cached static asset bytes | Global edge | View |
| Openprovider | Domain registrar. When you buy a domain through Doable, we send your registrant contact details (name, email, phone, postal address) to Openprovider, who registers it and is the registrar of record. ICANN requires this data to be accurate for as long as the domain exists. | Domain name, plus the registrant contact details you enter when buying: name, email, phone, and postal address. ICANN requires these to be accurate and kept current for as long as the domain is registered. | United States | View |
| Porkbun (legacy) | Domain registrar of record for domains purchased through Doable’s in-app flow prior to May 2026. New purchases no longer use Porkbun. | Domain name, registrant contact details (only for legacy in-app purchases). | United States | View |
When this list changes
We notify customers at least 14 days before adding a new subprocessor that processes personal data. Notification goes to the billing email on each account.
Customer-deployed code
When you deploy code through Doable, it runs in containers on our infrastructure (or on a server you connect via the BYO flow). The contents of those containers are your processing, not ours. Subprocessors above are the ones we use to operate the platform itself.
Data Processing Agreement
Doable’s standard Data Processing Agreement is offered to all paying customers. Email privacy@doable.do for a counter-signed copy.