Sub-processors

MyShift uses the following sub-processors to deliver the service. This list is published per revFADP Art 19 (Switzerland) and GDPR Art 28 (EU customers).

Last updated: 2026-05-10 (Pass 76g — DPF cross-check + indirect-sub-processor disclosure). Customers receive 30-day prior notice of material sub-processor changes via the email address on file (manual notification at v1; RSS feed planned for v1.5+).

VendorPurposeJurisdictionLegal basis / safeguard
Vercel (Phase A only)Web hostingUS/EUDPA + SCC
Supabase (Phase A only)Managed backend (Auth, DB, Storage, Realtime)US/EUDPA + SCC
Infomaniak (Phase B)Self-host platform (K8s + Postgres + S3)CHDPA
StripePayments (CHF Billing + Tax)US / IrelandDPA + SCC + EU-US/UK/Swiss-US DPF (active, participant 6436)
ResendTransactional + magic-link emailUSDPA + SCC + EU-US/UK DPF (active; Swiss-US not asserted by Resend, transfers covered by SCC)
SentryServer-side error tracking (browser SDK disabled at Phase A)USDPA (v5.1.0, 2024-05-29 — stale, re-verify before Sprint 8) + SCC + EU-US/UK/Swiss-US DPF (active, participant 5869)
Infomaniak Network SADomain registrar (my-shift.ch)CHDPA (already covers Phase B hosting per same vendor)
PlausibleAnalytics (cookieless, no PII; landing only)EE (EU)DPA
Expo (EAS)Mobile build infrastructureUSDPA + SCC
Bunny CDN (Phase B)Content delivery networkSI (EU)DPA, EU adequacy
TwilioSMS (manager invitations, no-show alerts, critical security only)USDPA + SCC
Apple Inc.Push notifications (APNs; mobile only)USRestricted-purpose token-only; no DPF certification (APNs is OS-level; no PII payload)
Google LLCPush notifications (FCM; mobile only)USRestricted-purpose token-only + EU-US/UK/Swiss-US DPF (active, participant 5780)
GitHub Inc.Source-code hosting + CI runners (commit metadata, build artefacts, repo secrets); no MyShift tenant PIIUSDPA + SCC + EU-US/UK/Swiss-US DPF (active per docs.github.com/en/site-policy/privacy-policies/global-privacy-practices, eff. 2026-04-27, fetched 2026-05-11); DPA at github.com/customer-terms/github-data-protection-agreement; tenant data does not flow through GitHub Actions

Indirect sub-processors (informational)

The vendors above contract their own infrastructure providers (sub-sub-processors). MyShift has no direct contractual relationship with these underlying providers, but data flows transitively. We disclose them here per revFADP Art 19 + GDPR Art 28(2) transparency principles.

Direct vendorUnderlying provider(s)Source
ResendAmazon Web Services Inc. (US) — primary email-sending hostresend.com/legal/subprocessors (fetched 2026-05-10)
SentryAmazon Web Services Inc. (US/EU), Google Cloud Platform (US/EU), Cloudflare Inc. (US) — cloud infrastructuresentry.io/legal/subprocessors/ (fetched 2026-05-10)
StripeAmazon Web Services Inc. (US) + Amazon Internet Services Pvt Ltd (India) — cloud infrastructurestripe.com/legal/service-providers (fetched 2026-05-10)
TwilioAmazon Web Services, Google Cloud, Microsoft Azure — cloud infrastructurewww.twilio.com/en-us/legal/sub-processors (fetched 2026-05-10)
VercelAmazon Web Services, Google Cloud, Microsoft Azure — cloud infrastructuresecurity.vercel.com (fetched 2026-05-10)
PlausibleHetzner Online GmbH (DE) — primary EU hosting; UpCloud Ltd (FI), Bunny.net (SI) — secondary EUplausible.io/privacy (fetched 2026-05-10)

Phase A vs Phase B

MyShift is currently in Phase A on Vercel + Supabase Cloud Frankfurt for pilot use. Phase B is the commercial-launch target on Infomaniak Geneva (Swiss data residency). At Phase B cutover, Vercel + Supabase Cloud rows are replaced by Infomaniak. All other sub-processors are unchanged across phases.

Contact

Questions about sub-processors or data-protection requests: privacy@my-shift.ch.

Privacy policyHome