Subprocessors
Last updated 2026-10-05
CredScape Market Intelligence Inc. uses a small number of third-party service providers, called subprocessors, to operate the CredScape platform. This page lists each provider that handles customer or personal information, its service, the data it handles, and where it processes that data.
We share only the information each provider needs to deliver its service.
Current subprocessors
| Subprocessor | Purpose | Data handled | Location of processing | DPA in place |
|---|---|---|---|---|
| Supabase | Database, authentication and storage of the program corpus | Account data (name, email, organization, role, seat assignment), product events (saved searches, comparable sets, exports) and consent records | Canada (AWS ca-central-1) |
Yes |
| Cloudflare | Application hosting, content delivery, DNS and edge network | IP addresses, device identifiers, request metadata and the data delivered through the application | Global edge network | Yes |
| OVH | Our own server for semantic search and session replay | Search query text and related metadata. Session replay recordings are masked and deleted after 30 days. No customer records and no program data are stored on this server | Beauharnois, Quebec, Canada | Yes |
| Resend | Transactional email delivery | Email addresses, recipient names and message contents | United States | Yes |
| Google Workspace | Company email | Correspondence with us, including sender and recipient addresses and message contents | As determined by Google | Yes |
| Google Analytics 4 | Product analytics on our website. Loads only after you accept analytics cookies | Cookie identifiers, device parameters and IP addresses | United States | Yes (Google) |
| PostHog | Product analytics: which pages and features are used. Loads only after you accept analytics cookies. Requests go through our own domain | Pseudonymous usage events (page paths, feature use counts) and your account identifier. No names, email addresses, search text or session recordings | European Union (Frankfurt) | Yes. Privacy policy |
| Sentry | Error monitoring for the website and product | Error message and stack trace, page path, browser and operating system. IP address storage is turned off | European Union (Germany) | Yes |
| Stripe | Billing | Billing contacts, invoices and subscription records | As determined by Stripe | Yes |
| Zendesk | Customer support by email and chat | Name, email address and the content of your support messages. For signed-in users, nothing is sent automatically | United States | Yes |
Customers can request signed data processing agreements (DPAs) with one week's notice. Write to privacy@credscape.io.
Services that process public program data
These services process public web content about education programs to build the program corpus. They do not receive customer account data.
| Service | Purpose |
|---|---|
| OpenRouter | Routes requests to the model provider that extracts program fields from public pages |
| Google Gemini | Classifies and extracts fields from public program pages |
| Tavily | Discovers institution and program pages |
| Exa | Discovers institution and program pages |
| ValueSERP | Discovers institution and program pages |
Other services
Instatus hosts our status page at credscape.instatus.com. It stores an email address only if you choose to subscribe to status updates.
Where your data is stored
Customer account records, the program corpus, and the vector indexes that power search are stored in Canada.
The semantic search server in Quebec performs ranking computation only. It receives a query, returns a ranked list of identifiers, and stores no customer records.
Email, analytics, error monitoring, billing, customer support and application delivery involve processing outside Canada, as shown in the table above. Our content delivery network operates globally, so our residency commitment covers stored data only.
Categories of data
Account data. Name, email address, organization, role, and seat assignment. We hold this data in Supabase and use it to authenticate users and administer subscriptions.
Product events. Saved searches and comparable sets. We use these to operate the product and administer your organization's subscription.
Marketing data. Contact details submitted through demo requests, access requests, and the launch notification list.
Analytics data. Cookie identifiers, device parameters, and IP addresses collected on our public website after you accept analytics cookies. Google Analytics 4 is the only tracker we run on the website.
Personal information in the program corpus
The program corpus contains institution-level and program-level information published by post-secondary institutions. It is not personal information.
We do not retain instructor names and contact details. We removed personal information of that kind from the corpus in July 2026, and our ingestion process excludes it.
If you believe personal information appears in our corpus, our data requests page explains how to have it corrected or removed.
Adding or changing a subprocessor
Our subprocessors may change as the service develops. When they do:
Advance notice. We give affected customers at least thirty days written notice by email before a new subprocessor begins processing personal information. We send the notice to the customer's designated privacy contact. We may also post a notice in the product, but this does not replace the email.
Objecting. Customers may object to a new subprocessor within thirty days of our notice, on reasonable grounds relating to data protection. Send objections to privacy@credscape.io and explain the specific security or privacy concern. We will work with you in good faith. If we cannot reach agreement, we will discuss alternative configurations or termination.
Administrative changes. We update this page without separate notice for changes that do not affect a subprocessor's identity, the categories of data it processes, or the location of processing, such as a corporate name change, unless a customer's agreement requires otherwise.
Subscribing to notices. To receive email notifications of subprocessor changes, write to privacy@credscape.io with the subject line "Subscribe to subprocessor updates".
Contractual protection
Every subprocessor with access to personal information is bound by a written data processing agreement with obligations no less protective than those in our own customer agreements. We follow this practice regardless of which privacy statute applies to a customer.
Questions
Write to privacy@credscape.io. Our full privacy policy explains how we handle personal information generally.