Subprocessors
Rib Creative uses subprocessors and connected service providers to operate the builder, hosted apps, exports, integrations, payments, analytics, storage, and support. Actual providers may vary by workspace, region, feature, deployment environment, and customer configuration.
Current and feature-dependent providers
| Provider | Purpose | Role | Data | Region | Safeguards | Retention |
|---|---|---|---|---|---|---|
| Stripe | Platform billing and project-owned payment configuration. | Subprocessor and independent payment provider | Billing records, Stripe IDs, invoices, configured-secret metadata, account status, and payment metadata. | United States and global Stripe infrastructure. | Stripe Privacy/DPA terms, payment processor controls, and contractual transfer safeguards. | Billing and risk records retained as required by Stripe, tax, fraud, and legal obligations. |
| OpenAI | AI-assisted generation, editing, reasoning, transcription, and model processing where configured. | AI subprocessor | AI prompts, messages, files, project context, generated code snippets, logs, and support context. | United States or other regions supported by provider infrastructure. | Provider Privacy/DPA terms, enterprise settings where enabled, and contractual transfer safeguards. | Provider retention depends on account settings and service terms. |
| Google / Gemini | AI model processing, OAuth, cloud services, storage, and advertising measurement where configured. | Subprocessor and connected service provider | AI prompts, OAuth metadata, storage metadata, analytics signals, ad event data, and operational logs. | United States, EU, and global Google infrastructure. | Google Privacy/DPA terms, SCCs or equivalent transfer safeguards, and product security controls. | Retained under Google service settings, customer configuration, and legal requirements. |
| Anthropic | AI-assisted planning, conversation, and execution flows where configured. | AI subprocessor | AI prompts, project context, generated outputs, files, logs, and support context. | United States or other provider-supported regions. | Provider Privacy/DPA terms and contractual transfer safeguards. | Provider retention depends on account settings and service terms. |
| Google Cloud Storage | Project files, assets, exports, thumbnails, build artifacts, and operational storage. | Cloud infrastructure subprocessor | Project files, generated assets, exports, thumbnails, logs, and storage metadata. | Configured cloud storage regions. | Cloud provider DPA, encryption controls, access controls, and transfer safeguards. | Retained while the project, workspace, backup, or legal requirement remains active. |
| Vercel | Web hosting, deployment, analytics, edge infrastructure, and platform delivery. | Hosting and delivery subprocessor | Deployment metadata, public assets, logs, analytics signals, IP addresses, and user agent data. | Global edge network and provider regions. | Vercel Privacy/DPA terms, access controls, and contractual transfer safeguards. | Operational logs and deployment records retained under provider settings and platform needs. |
| Resend | Transactional email, authentication email, leads, invitations, and support notifications. | Email delivery subprocessor | Email addresses, message metadata, delivery events, and email content needed for delivery. | United States and provider-supported regions. | Provider Privacy/DPA terms and transfer safeguards. | Delivery logs retained for abuse prevention, diagnostics, and legal obligations. |
| Supabase | Optional connected database, auth, storage, and project backend services. | Customer-controlled provider where connected; subprocessor for RIB-managed integrations. | Database metadata, auth records, storage metadata, project configuration, and operational logs. | Customer-selected or provider-supported regions. | Supabase Privacy/DPA terms, customer configuration, and transfer safeguards. | Controlled by customer configuration, provider terms, and project lifecycle. |
| GitHub | OAuth, repository import, repository creation, source sync, and package registry access. | Connected service provider | OAuth metadata, repository metadata, source files, commit metadata, sync logs, and package metadata. | United States and global GitHub infrastructure. | GitHub Privacy/DPA terms and customer-controlled repository permissions. | Controlled by repository settings, GitHub terms, and sync/audit requirements. |
| Neon or managed Postgres provider | Rib Cloud database clusters and managed project database infrastructure. | Database infrastructure subprocessor | Database records, schema metadata, connection metadata, logs, and backups. | Configured database regions. | Provider Privacy/DPA terms, encryption, access controls, and transfer safeguards. | Retained while databases, backups, billing, security, or legal records remain active. |
| Redis or queue provider | Background job queues, build orchestration, worker coordination, and rate limiting where configured. | Infrastructure subprocessor | Queue metadata, job identifiers, status events, limited operational payloads, and logs. | Configured infrastructure regions. | Provider Privacy/DPA terms, access controls, and transfer safeguards. | Usually short-lived operational data plus logs retained for diagnostics and security. |
Customer-controlled providers
Some projects use customer-selected providers after export or through bring-your-own integrations. Those providers are controlled by the customer's configuration and are not Rib Creative subprocessors for external hosting environments.
Updates
Rib Creative may update this list as providers, regions, products, or infrastructure change. Material changes that affect customer personal data will be reflected here or in the applicable customer agreement.
Subprocessor changes may be announced by updating this page or through another reasonable channel. Where required by applicable data protection law or a customer agreement, customers may object to material changes on reasonable data protection grounds.
