# Subprocessors | Aglyn

> The third-party services Aglyn uses to provide the platform.

Legal

# Subprocessors

The third parties that help us run Aglyn, and what each one handles.

**Last updated: August 24, 2026**

Aglyn LLC uses the third-party subprocessors below to provide the Services. This list supports the **Data Processing Addendum** and **Privacy Policy**. We update this list and the change log below to reflect the subprocessors currently engaged. Section 7 of the DPA governs Aglyn's use of subprocessors.

## **Core infrastructure & platform subprocessors**

| Subprocessor | Provider entity | Purpose | Data processed | Location |
| :---- | :---- | :---- | :---- | :---- |
| **Google Firebase Authentication** | Google LLC | User authentication, sign-in, session, and auth emails (verification, password reset) | Account identifiers, email, auth tokens, OAuth identities | United States (Google operates a global service) |
| **Google Cloud Firestore** | Google LLC | Primary application database (multi-tenant) | Account, org, content, commerce, CRM, and configuration data | United States (nam5 US multi-region) |
| **Google Cloud / Firebase Storage** | Google LLC | Media and asset storage | Uploaded images, video, files | United States (US multi-region) |
| **Vercel Inc.** | Vercel Inc. | Application hosting, edge/CDN, custom-domain SSL and provisioning | Request/usage data, IP, content served | United States (primary compute), with a global edge network for cached content |
| **Stripe, Inc.** | Stripe, Inc. | Subscription billing and, via Stripe Connect, facilitation of Customer merchant sales | Billing contact, subscription/transaction metadata, payment data (processed by Stripe) | United States |
| **Resend** | Plus Five Five, Inc. (d/b/a Resend) | Transactional and app-generated email delivery (invites, receipts, usage summaries, campaigns) | Recipient email, message content/metadata | United States |
| **Google reCAPTCHA** | Google LLC | Bot protection / anti-abuse (via Firebase App Check) | IP, device/browser signals, interaction data | United States (Google operates a global service) |
| **Google Analytics** | Google LLC | Product and site analytics for aglyn.com, the console, and the documentation site (a single GA4 property). The property is linked to Aglyn's Google Ads account with personalized advertising enabled, and Google signals and ads personalization are allowed in every region, so analytics data may also be used to build and export advertising audiences. Data retention is 14 months. The same Google tag host also serves a Google Ads tag on those three surfaces, and a Google Tag Manager container where one is configured; what a container carries is configured in Google’s interface and is not enumerated here. | IP address, device/browser signals, page and event interaction data, a cookie-based pseudonymous identifier | United States (Google operates a global service) |
| **Google Fonts** | Google LLC | Serving web-font files to visitors of published sites whose theme selects a Google font, and to the console editor surfaces | Visitor IP address and browser user-agent, sent by the visitor's browser when it requests the font file | United States (Google operates a global service) |
| **Google Cloud Logging** | Google LLC | Collecting uncaught browser errors from the console and from published sites, for diagnosis and reliability | Error message and stack trace, source file, line number, and the origin and path of the page (query strings are removed before transmission) | United States (Google operates a global service) |
| **Anthropic** | Anthropic, PBC | AI-assisted features in the console and the site editor, including the Aglyn Assist helper and editor assistance (rewriting element copy, drafting blog bodies, generating a section layout) | The text the user submits to the feature — their question or instruction, and the content of the element, post, or page being worked on — together with the generated response. No account identifiers, email addresses, or authentication tokens are transmitted. | United States |
| **Linear** | Linear Orbit, Inc. | Filing and triage of issue reports submitted through the console's "Report an issue" dialog | The report text the reporter writes, their email address and account identifier, their organization's name and identifier, and technical context about the session (the console page, browser and viewport, and application build identifiers) | United States |
| **Meta Pixel** | Meta Platforms, Inc. | Advertising measurement and retargeting on Aglyn’s own marketing site, console and documentation site, and on a customer site where the site owner has enabled the advertising question and configured a pixel | Page views and conversion events from a visitor whose consent state permits advertising on a surface that asks about it, with the identifiers the pixel sets. On the console that visitor may be signed in, so the page views describe an identified account holder using the product, and the page addresses reported carry their organization’s identifier | United States |
| **LinkedIn Insight Tag** | LinkedIn Corporation | Advertising measurement and retargeting on Aglyn’s own marketing site, console and documentation site, and on a customer site where the site owner has enabled the advertising question and configured a partner id | Page views and conversion events from a visitor whose consent state permits advertising on a surface that asks about it, with the identifiers the tag sets. On the console that visitor may be signed in, and the point made in the Meta Pixel entry above applies here in the same way. LinkedIn additionally sets cookies on its own domain, which a page on our origin cannot read or clear | United States |
| **Google Ads** | Google LLC | Advertising measurement and retargeting on Aglyn’s own marketing site, console and documentation site, and on a customer site where the site owner has enabled the advertising question and configured a Google Ads id | Page views and conversion events from a visitor whose consent state permits advertising on a surface that asks about it, with the identifiers the tag sets, including the _gcl_au cookie that any Google tag on the page writes — a Google Tag Manager container included. On the console that visitor may be signed in, and the point made in the Meta Pixel entry above applies here in the same way. Advertising audiences built in the linked Google Analytics property are also exported to this account. | United States (Google operates a global service) |

## **Related services**

* **Google Workspace** (Google LLC) — inbound/human email for **@aglyn.com** (e.g., support, contact). May process email you send to us.
* **Google Cloud DNS** (Google LLC) — DNS management for aglyn.com domains.

## **Change log**

* **August 27, 2026** — Added Meta Platforms, Inc. (advertising measurement through the Meta Pixel) and LinkedIn Corporation (advertising measurement through the LinkedIn Insight Tag); the Meta Pixel was already in use when this entry was published. Updated the Google Analytics entry: the property is linked to Aglyn's Google Ads account with personalized advertising enabled, and Google signals and ads personalization are allowed in every region.
* **August 24, 2026** — Added Linear (filing and triage of issue reports submitted through the console's "Report an issue" dialog); this subprocessor was already in use when this entry was published. Removed the thirty-day advance-notice commitment for new subprocessors and the objection window that ran with it; Section 7.2 of the DPA is amended to match.
* **August 18, 2026** — Added Google Analytics (analytics for Aglyn's own properties), Google Fonts (web fonts on published sites), and Google Cloud Logging (browser error reports); added Anthropic for AI-assisted features, including the Aglyn Assist helper. Aligned this list with the DPA, the Privacy Policy, and the trust page. Stated the 30-day advance-notice period for new subprocessors and the objection route, matching DPA Section 7.2.
* **August 13, 2026** — Verified provider entities and processing locations; corrected the Resend entity name; reconciled this list with the trust page.
* **August 5, 2026** — Initial publication.

## **Notes**

* **Payment card data** is collected and processed directly by **Stripe** under its own terms; Aglyn does not store full card numbers.
* For **commerce features**, sales are processed through Aglyn's own **Stripe** account and the Customer merchant's share is transferred to a connected **Stripe Connect** account held in the merchant's name (Terms of Service Section 10.2). Stripe acts as an independent controller/processor for that payment processing under its own agreements with Aglyn and with the merchant.

*© 2026 Aglyn LLC. All rights reserved.*

---

Source: https://aglyn.com/legal/subprocessors
