Subprocessors
Last updated November 10, 2025Sagency International LLCabout 2 min readSee also: Data processing agreement, Trust centre, Security overview
Every third party that processes Blue Reacher customer data is named here, along with what it does, which data it sees and where it runs. Most vendors in this category answer this question on request; publishing it saves you a round trip.
What this covers
The current list of subprocessors with purpose, data category and region, how much notice you get before it changes, where processing physically happens, and how to raise an objection.
Current subprocessors
Blue Reacher engages the third parties below to deliver the service. Each one is reviewed before it touches customer data, carries data protection obligations no less protective than those in our own data processing agreement, and Sagency International LLC remains liable to you for its performance.
- Cloudflare
- Application hosting, edge compute and content delivery for the platform and the marketing site. Sees request metadata and any data in transit through the edge and application layers. Global edge network with United States origin.
- Supabase
- Primary database, authentication and serverless functions. Holds contact records, message content, delivery states and account data at rest, encrypted with AES-256. United States.
- Stripe
- Payment processing and subscription billing. Sees billing contact details and payment card data, which is entered on Stripe-hosted pages and never reaches Blue Reacher systems. PCI DSS Level 1 service provider. United States.
- PostHog
- Product and marketing analytics on our own web properties. Sees pseudonymous usage events and does not receive customer contact records or message content. United States.
- LeadConnector
- Scheduling for demo and onboarding calls booked through this site. Sees the name, email and phone number a prospect submits on the booking form, and no customer campaign data. United States.
- Google Workspace
- Business email, documents and calendars used for support correspondence. Sees whatever a customer chooses to put in an email to us. United States.
No artificial intelligence or machine learning subprocessor is currently engaged to process customer message content. If one is engaged, it will appear on this list with 30 days notice before it begins, under a contractual bar on training against the data it sees.
How changes are announced
Blue Reacher gives at least 30 days notice before adding or replacing a subprocessor. Notice goes to the billing and technical contacts on the account and this page is updated on the same day, so the published list and the notified list never diverge.
A customer with a reasonable, specific objection to a new subprocessor can raise it during the notice period. Where the objection cannot be resolved, the customer may terminate the affected service without penalty for the remainder of the term.
Where processing happens
All subprocessors above process customer data in United States infrastructure. Where data originates in the European Economic Area, the United Kingdom or Switzerland, the transfer is covered by the Standard Contractual Clauses incorporated into our data processing agreement, with the UK International Data Transfer Addendum applied where relevant.
Questions and objections
Send subprocessor questions, objections and requests for the underlying agreements to support@bluereacher.com. A completed security questionnaire, the SOC 2 control mapping and a countersigned data processing agreement are available on the same request.
This page is reviewed whenever the vendor stack changes and at least quarterly. If you spot something on it that no longer matches what you were told, that is a correction we want to hear about.