Sub-processors
Every third party that touches your data on our behalf. Last updated 20 August 2026.
When you use Nilstock for your own employees’ data, you are the data controller and we are your processor. We are not allowed to hand that data to anyone else without telling you who and why. This is that list, and it is short on purpose.
Railway
Their privacy terms- What they do
- Hosting for the application and the PostgreSQL database. This is where your data actually lives.
- What they can see
- Everything in your account — the catalogue, the ledger, people, and account holders.
- Where
- EU (Amsterdam region)
Stripe
Their privacy terms- What they do
- Subscription billing, card processing, invoices and the customer billing portal.
- What they can see
- Billing email address, company name, and our internal company ID. Card details go directly to Stripe and never reach our servers. No stock, ledger or employee data is sent.
- Where
- EU and US (Stripe is certified under the EU–US Data Privacy Framework)
Resend
Their privacy terms- What they do
- Sending transactional email: password resets, team invitations, overdue-equipment chases and the low-stock digest.
- What they can see
- The recipient name and email address, and the content of the message — which for an overdue chase includes the names of the items that person is holding.
- Where
- EU and US
That is the whole list
There is no analytics provider, no advertising network, no session-recording tool, no chat widget and no CDN beyond the one Railway provides. If that changes, this page changes with it and we will give you notice before the new processor starts.
Objecting to a change
If we add a sub-processor and you object on reasonable data-protection grounds, tell us and we will either find another way or let you out of the contract without penalty for the remainder of the term. That is the commitment; if it ever comes up, it should be a conversation rather than a clause.
Related
Privacy policy — what data we hold and why. Data processing terms — the Article 28 obligations we take on. Security — how it is protected, and what we have not done yet.