List of sub processors
Last updated on October 31, 2023
Below is a list of all sub processors that we use to provide our websites and services to you. We have checked all subprocessors for compliance with data privacy regulations and have data processing agreements in place with all of them, unless mentioned otherwise.
If you have any questions, please contact us at privacy@getfrello.com.
Service providers
The following sub processors provide us with auxilliary services to help us communicate with our customers and team, and facilitate us in the management of our business.
Intercom
We use Intercom to provide support and to facilitate communication with our leads and customers, and to notify them of new or upcoming features.
Country United States
Data subjects Visitors, Leads, Customers, Admins
Data processed Name, email, avatar photo, and other information provided to us.
Data storage Indefinitely, removed upon request
Productboard
We use Productboard to track feature request and user insights, and to organise our development backlog.
Country United States
Data subjects Leads, Customers, Admins
Data processed Name, email, feature request and other relevant details provided to us.
Data storage Indefinitely, removed upon request
Hubspot
Hubspot is used to help us track leads and grow our customer base.
Country United States
Data subjects Leads, Customers
Data processed Name, email, phone number and other relevant details provided to us.
Data storage Indefinitely, removed upon request
Mailchimp
We occasionally use Mailchimp to communicate product news and announcements to our customers and interested parties.
Country United States
Data subjects Leads, Customers, Admins
Data processed Name and email address
Data storage Indefinitely, removed upon request
Slack
Slack is used for internal communication between our team and to receive various notifications, for example when new customers sign up or when errors are reported.
Country United States
Data subjects Leads, Customers, Members
Data processed Name, email address, and occasionally other relevant details provided to us.
Data storage Indefinitely, removed upon request
Stripe
We use Stripe for billing and invoicing purposes.
Country United States
Data subjects Customers
Data processed Organisation data, billing contact details, credit or debit card details
Data storage As long as needed
Google Workspace
Google Workspace is used to communicate with customers and organise our business. We may also use Google Workspace to store documents related to your organisation, for example quotes or customisation proposals.
Country United States
Data subjects Customers, Admins
Data processed Emails, quotes, customisation proposals
Data storage As long as needed
Google Analytics
We use Google Analytics to analyse the behaviour of visitors to our website. This information is aggregated and anonymised and does not allow us to track individual users or visitors.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed No personal data (anonymised IP address).
Data storage 14 months
Hotjar
We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed No personal data (anonymised IP address).
Data storage 365 days
Dropbox
We use Dropbox to occasionally transfer sensetive data (like member import files) between our customers and the team.
Country United States
Data subjects Customers, Admins, Members
Data processed Name, email and other personal information of members contained in import files.
Data storage 7 days
Notion
Notion is used to organise our teams and to keep track of notes and processes. We may occasionally use Notion to store notes or documents related to your organisation, for example when working on a quote or proposal.
Country United States
Data subjects Customers, Admins, Leads
Data processed Organisation data, name, email, quotes, customisation proposals
Data storage As long as needed
Xero
We use Xero internally for accounting and bookkeeping purposes.
Country New Zealand
Data subjects Customers
Data processed Organisation data, billing information, transactions and payment information.
Data storage 10 years
Infrastructure providers
The following sub processors provide services related to hosting and infrastructure.
Heroku
Heroku is used to host certain parts of our applications and websites.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed All user data (except credit card details)
Data storage Personal data is not stored
Netlify
Netlify is used to host certain parts of our applications and websites.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed Access logs, including IP addresses
Data storage Less than 30 days
Cloudflare
Cloudflare provides us with DNS services, security and protection against DDoS attacks.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed Access logs, including IP addresses
Data storage 4 hours
MongoDB
We use MongoDB to store our data.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed All user data (except credit card details)
Data storage For the life of the account + 3 months
Redis Labs
We use Redis Labs to store data temporarily.
Country United States
Data subjects Customers, Members
Data processed User ID’s
Data storage Generally no longer than several hours.
Sentry
Sentry is used to monitor and log errors that occur in our applications and websites.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed User ID, IP addresses, browser information
Data storage 90 days
LogDNA
We use LogDNA to track and process server and application logs.
Country United States
Data subjects Visitors, Leads, Customers, Members
Data processed Access logs, including IP addresses
Data storage 14 days
SparkPost
SparkPost is used to send transactional emails.
Country United States
Data subjects Customers, Members
Data processed Name, email, potentially other data contained within emails
Data storage 37 days for most data, random samples for security/fraud detection up to 61 days,
event data for recovery purposes up to a year
Imgix
We use Imgix for image optimisation and processing purposes.
Country United States (EU-US Privacy Shield)
Data subjects Customers, Members
Data processed Avatar photos, organisation logos and other images uploaded by customers or
members
Data storage As long as images are used
AWS
AWS is used for image and file storage.
Country United States
Data subjects Customers, Members
Data processed All uploaded files, which may contain personal data
Data storage For life of account or until files are removed by the customer or member
Integrations
The following sub processors are used when you connect to their services through our integrations. Note that we do not evaluate or attest to the GDPR qualifications of our integration partners. You are responsible for evaluating any third-party integration partner before creating or enabling an integration.
Stripe
Our Stripe integration can be used to process debit and credit card payments made by members.
Country United States
Data subjects Members
Data processed Name, email, card details, payment information
Data storage As long as needed
POLi
Our POLi integration can be used to process account to account payments made by members in New Zealand.
Country New Zealand
Data subjects Members
Data processed Name, email, card details, payment information
Data storage As long as needed
Mailchimp
Our Mailchimp integration can be used to send newsletters or marketing emails to your members.
Country United States
Data subjects Members
Data processed Name, email, and potentially other information you choose to synchronise
Data storage Controlled by customer
Campaign Monitor
Our Campaign Monitor integration can be used to send newsletters or marketing emails to your members.
Country United States
Data subjects Members
Data processed Name, email, and potentially other information you choose to synchronise
Data storage Controlled by customer
Xero
Our Xero integration can be used to synchronise payment data for accounting, bookkeeping and reconcilliation purposes.
Country New Zealand
Data subjects Members
Data processed Name, transaction and payment information
Data storage Controlled by customer