RuleCue

Subprocessor List

Effective 2026-08-11 · Version 2026.08.11

How this list works

Cody Rasmussen (individual seller) uses the providers below to operate RuleCue for U.S. business customers. A provider receives only the information reasonably needed for the listed function. Questions and data-protection objections may be sent to info@rulecue.com.

The listed providers may process information in the United States and other locations where they operate under their contractual and legal safeguards. This page does not promise single-state or U.S.-only data localization.

Production subprocessors

ProviderService functionInformation involved
VercelApplication hosting, server execution, deployment, and operational logs.Account and workspace requests, session and request metadata, IP address, browser information, Customer Personal Data that transits an application function, and minimized error records.
SupabaseHosted PostgreSQL infrastructure and private object storage used by RuleCue.Business account, tenant, authentication, configuration, workflow, report, source-evidence, audit, and approved private-storage records.
CloudflareDomain, network delivery, traffic protection, and related security functions.Request IP address, browser and device request data, security events, public-site requests, and content transiting an enabled delivery or security function.
ResendRequested sign-in links and transactional access, security, account, billing, and service email; delivery and suppression handling.Recipient and sender email, message content, idempotency information, and minimized acceptance, delivery, bounce, complaint, and suppression events.
Google WorkspaceStaffed support, privacy, account, and necessary business communications for RuleCue.Business contact details and the content and attachments a person chooses to send or receive in those communications.

Payments provider

Stripe provides Checkout, subscriptions, invoices, payment processing, fraud prevention, and the customer billing portal. Stripe receives business contact, payment method, transaction, subscription, invoice, tax, fraud, dispute, and portal information. Full payment-card credentials go directly to Stripe and are not intentionally stored by RuleCue. Stripe acts as a processor for some functions and as an independent controller for its own payment-network, fraud, tax, identity, legal, and compliance purposes.

Services not used for Customer Personal Data

OpenAI and Anthropic do not receive Customer Personal Data in this release. Customer-document intake, customer-content AI processing, advertising technology, and outbound marketing email are disabled. A future activation that changes this boundary requires an updated Privacy Policy, DPA where applicable, and this list before Customer Personal Data is routed to the new function.

Changes and objections

Provider will update this list and, when reasonably practicable, give account administrators advance electronic notice before a material new subprocessor begins processing Customer Personal Data. Customer may object within 10 calendar days after notice on reasonable, documented data-protection grounds by emailing info@rulecue.com. Provider and Customer will work in good faith on a reasonable alternative under the DPA.