Sub-processors
Every company Piczel uses to run the service, what each one handles, where that data physically sits, and which country's law the company answers to. Kept current, and the source of truth referenced by our Data Processing Addendum.
1. How to read this page
These are the companies Piczel uses to run the service. Each one processes data on our instructions, under data-protection terms no less protective than our Data Processing Addendum.
Two separate facts are given for each, because they answer different questions. "Where the data sits" is the physical location we have confirmed. "Whose law the company answers to" is where the company itself is incorporated, which can differ. Where we cannot confirm a data location, we say so rather than guess.
2. Cloudflare: media storage and delivery
Holds every client photograph uploaded to Piczel and serves them to gallery visitors. This is the main store of customer content.
- Where the data sits: Western Europe.
- Company: Cloudflare, Inc., United States.
Cloudflare also offers a stricter setting that contractually confines a store to the European Union. It can only be set when a store is created, so switching to it would mean moving the photographs to new storage.
3. Cloudflare: network layer
A separate role at the same company. It sits in front of all our sites handling domain names, traffic routing, and attack filtering, and sees the IP address of every visitor. It is listed separately from the storage entry above because the two roles carry different exposure.
- Where the data sits: nothing is stored in this role, but traffic passes through Cloudflare's global network.
- Company: Cloudflare, Inc., United States.
4. Railway: application hosting and database
Runs the Piczel applications, the main database, and the job queue. The database holds account details, galleries, bookings, invoices, and client contact details.
- Where the data sits: EU West, which is Railway's Amsterdam, Netherlands region.
- Company: Railway Corporation, United States.
The database is backed up daily by Railway and each copy is kept for six days. Railway does not publish where it holds backup copies, so we cannot confirm they stay in the same region. Photograph backups are held separately, at section 9.
5. Resend: transactional email
Sends account emails, gallery invitations, and receipts. It receives the recipient's email address, name, and the message content.
- Where the data sits: two places, and the second matters. Emails are sent from Ireland, on Resend's eu-west-1 region. But everything Resend keeps, including message content, delivery logs, and account records, is stored in the United States, and no setting moves that to Europe.
- Company: Plus Five Five, Inc., United States, trading as Resend.
Resend's own published list of sub-processors is entirely United States companies.
6. Sentry: error monitoring
Records technical faults so we can fix them. A fault report contains the technical error detail, an internal account reference (a random code, not a name), and the web address of the page the person was on. Visitor IP addresses are switched off, and no names, email addresses, or photographs are sent.
- Where the data sits: European Union, in Frankfurt, Germany. We chose Sentry's EU region deliberately, and that choice cannot be changed later.
- Company: Functional Software, Inc., United States.
7. PostHog: product analytics
Measures how our own marketing site and dashboard are used: which pages are visited, what is clicked, the page that sent the visitor to us, and the browser and rough location derived from the request. A visitor is identified by a random code held in a cookie, which the sign-up flow can tie to an account so we can see which pages lead to a subscription. No photographs, no gallery content, and no activity by a photographer's clients inside a gallery are sent. Session recording is switched off.
- Where the data sits: United States, on PostHog's US cloud. PostHog also runs a European Union cloud; if we move to it, this entry will say so.
- Company: PostHog, Inc., United States.
8. Paystack: payments
Handles subscription payments from photographers to Piczel only. Payments from a photographer's own clients are currently arranged outside the platform, so no client card details reach us or Paystack through Piczel.
- Where the data sits: Ireland, on Amazon Web Services, according to Paystack's own published privacy answers. This is not a setting we can see or choose. Paystack also says it may move data between Paystack group companies under its own binding corporate rules.
- Company: Paystack Payments Limited, Nigeria (RC 1310682), owned by Stripe, Inc. of the United States.
9. Google: form delivery
The contact form on our marketing site and the feedback form inside the dashboard both deliver through a Google Apps Script that we wrote and deployed. Google receives whatever the sender typed, including their name and email address, together with the page they were on, their country, and their browser type, and holds it for us. This is the only place Google handles data on our instructions.
- Where the data sits: not something we select or are told, since the script runs inside a Google account rather than infrastructure we configure.
- Company: Google LLC, United States.
10. Tigris: backup copy of stored photographs
Holds a second copy of the photographs described at section 2, so a deletion or a fault in the main store is recoverable. It is reached through Railway's storage product, which runs on Tigris rather than on Railway's own hardware, which is why the two appear as separate entries.
- Where the data sits: Europe. The region is fixed when the storage is created and cannot be changed afterwards.
- Company: Tigris Data Inc., United States.
11. Where that leaves your data
No customer data is stored in Nigeria at all. Photographs and their backup, the database, error reports, and payment records all sit in Europe. Two exceptions sit in the United States: the copies Resend keeps of every email it sends from Ireland, and the usage analytics PostHog holds about our own site and dashboard. Google's location is the one we cannot state, because it is not ours to choose. Where data moves across borders we rely on appropriate safeguards, as described in our Data Processing Addendum.
12. Not on this list, deliberately
Three things involve outside companies but are not sub-processors, because they are not processing data on our instructions:
- Google sign-in and Google Drive import. A photographer may sign in with Google instead of a password, and may import photographs from their own Google Drive. In both, Google is handling that person's own account under its own terms, so it is a separate controller. Where a photographer grants Drive access we hold the access token so the import can run; that is our own processing, not Google's.
- Analytics and embeds a photographer adds themselves. Piczel's own analytics (PostHog, above) run only on our marketing site and dashboard, never inside a photographer's galleries or portfolio site. A photographer can connect their own analytics to their portfolio site and galleries, and can place outside content there: a YouTube or Vimeo video, a map, or any embed code they paste in. Where they do, the choice is theirs and the visitor's browser contacts that company directly. Our Cookie Policy covers what that means for visitors.
- Our search index, which runs on our own servers within the Railway hosting at section 4, so it is not a separate company.
13. Artificial intelligence
No AI provider is connected to the platform today. We expect to add AI-assisted features later, as something a photographer turns on for their own account. Any such provider will be listed here from the day it goes live, and a per-photographer opt-in does not change that. Our AI Statement sets out the line between performing an operation on a photograph and training a model on it.
14. Changes to this list
We will give notice before adding or replacing a sub-processor that touches your data, and the objection process is in our Data Processing Addendum. Questions, or a request to be told when this page changes, go to [email protected].
Last updated September 19, 2026.