Sub-processor register

Every third party that touches your data.

Hand-curated. 10 providers today. You’ll see exactly what each one gets, where they process it, and the agreement we have with them.

Maintained by Abhishree Labs · DPDP Act 2023

Vercel Inc.

Standard DPA on file
Purpose

Frontend hosting + edge CDN for terracefarming.in.

Data shared

Request metadata (IP, user agent, URL). No body / form data leaves the function runtime.

Region

United States (global edge POPs)

Render Services Inc.

Standard DPA on file
Purpose

Backend API hosting (FastAPI) and the managed PostgreSQL database.

Data shared

All user-record fields — name, email, phone, address, plant photos, order history. The full application database lives here.

Region

Singapore (primary), US/EU regions for multi-region failover

Razorpay Software Pvt. Ltd.

Master Services Agreement covers
Purpose

Payment Aggregator under RBI PA Guidelines. Handles all card / UPI / net-banking checkout for orders, subscriptions, and consultations.

Data shared

Customer name, email, phone, billing address, transaction amount. No card data ever touches our servers — capture is on Razorpay's hosted checkout.

Region

India

ImageKit (Raznam Innovations Pvt. Ltd.)

Master Services Agreement covers
Purpose

Product image storage + on-the-fly transformation (resize, WebP/AVIF, watermark, label overlays).

Data shared

Product images, public asset URLs, user-uploaded plant-diagnosis photos. Photos uploaded for AI diagnosis pass through ImageKit before reaching our backend.

Region

India (Mumbai)

Sentry (Functional Software, Inc.)

Standard DPA on file
Purpose

Application error monitoring. Captures exceptions, stack traces, and a small slice of context (user ID, current URL, browser).

Data shared

User ID, email (when present in error context), IP. Sensitive bodies are scrubbed by Sentry's data-scrubbing rules before leaving the client.

Region

European Union (de.sentry.io). Configured this way so EU traffic stays in-region.

Anthropic, PBC

Standard DPA on file
Purpose

Generative AI (Claude) for the AI plant doctor and the in-app assistant. We only call Anthropic when a user voluntarily sends a question or photo.

Data shared

The user's question text, the photo (if attached), and a short conversation context. We do NOT send name, email, or other identifiers in the prompt.

Region

United States

OpenAI, L.L.C.

Standard DPA on file
Purpose

Fallback generative AI used by some assistant features when Anthropic is rate-limited or unavailable.

Data shared

Same scope as Anthropic — user question text and photo only, no identifiers.

Region

United States

Google LLC (Google Analytics 4)

Standard DPA on file
Purpose

Anonymous web analytics. Loaded only after the user accepts analytics cookies on the consent banner.

Data shared

Anonymised IP, page URL, click events, broad device/browser type. No name or email is sent. Demographic features are off.

Region

United States (with regional collection in EU/India)

Google LLC (Google Sign-In / OAuth)

Standard terms (no separate DPA)
Purpose

Optional federated login. Only invoked when a user clicks Sign in with Google.

Data shared

OAuth-returned name, email, and Google profile picture URL. We don't request additional Google scopes.

Region

United States

Twilio (SendGrid + Verify)

Standard DPA on file
Purpose

Transactional email (order confirmations, verification OTPs, password resets) and SMS OTP.

Data shared

Email address, phone number, the message body itself.

Region

United States

The shape of the register

Three things you’ll want to know.

Cross-border transfers

The DPDP Act, 2023 permits transfers of personal data outside India except to countries the Central Government places on a negative list. As of this page’s last review, no negative list has been notified.

Providers above sit in India, the United States, the European Union, and Singapore. For US/EU operations we require either Standard Contractual Clauses (where the provider has European users) or a Master Services Agreement that covers data protection equivalent to the DPDP Act’s standards.

What's not on this list

We do not share user data with advertising networks (we’re not in Google Ads’ user-data programmes), data brokers, or analytics-only companies beyond Google Analytics 4 — which we run in anonymised mode and only after consent.

When we display sponsored products, the targeting is computed server-side from data already on TerraceFarming and does not leave our infrastructure.

Notification of changes

When we add a sub-processor we update this page first — this page is the authoritative record. For users on our newsletter list, we also include a one-line note in the next monthly send describing the change.

Questions or objections

You can ask us to stop processing your data.

Under the DPDP Act, you can withdraw consent or ask us to stop processing. If you exercise that right, the sub-processors above stop receiving your data within the response window.

Last reviewed: . Next scheduled review: on each sub-processor change, and at minimum every 12 months.