v1.4.0Triage that admits when there's nothing to find

Subprocessors

Last updated

Rebase uses a small set of trusted third parties to help deliver our service. This page lists them, where they process data, and what each one processes. It supplements our Privacy Policy and DPA.

Subprocessors of Customer Data

These providers process Customer Data (the feedback, tickets, and diagnostic context captured through the widget) on our behalf under the Data Processing Addendum:

SubprocessorLocationPurposeData processed
DigitalOceanUnited Kingdom (London)Cloud hosting, managed database, and encrypted object storage for screenshots and uploadsAll service data, including account, ticket, and feedback data
CloudflareGlobal edge networkDNS, CDN, and edge delivery for the website, API, and widget (cdn.rebase.dev); terminates TLS at its edgeRequest metadata (IP, user agent) and, in transit, request content
Amazon SES (AWS)Ireland (EU)Email delivery — sign-in codes, invites, mentions, digests, and sales/careers enquiriesRecipient email address and message content
OpenAIUnited StatesAI triage of incoming tickets (classification, titles, summaries) — see the AI PolicyA minimized, scrubbed slice of ticket text (description, console/network metadata, code frames). Screenshots are never sent; data is not used for training
SentryUnited StatesError monitoring of our own serviceError reports and stack traces, which may include request context
StripeUnited StatesPayment processing and subscription billingBilling contact and payment data (card data is held by Stripe, not Rebase)

Providers for our own operations

These providers support Rebase’s own website and business (with Rebase as controller); they do not receive Customer Data captured through the widget:

ProviderLocationPurposeData processed
Google (Google Analytics)United StatesAggregate website usage analytics on rebase.dev, loaded only with your consentWebsite usage events and online identifiers (e.g. cookies, IP address)
HubSpotUnited StatesCRM for sales and customer relationshipsBusiness contact details (name, email, company) and account lifecycle status

Integrations you connect

The following are activated only when a customer chooses to connect them. When connected, the synced ticket content is shared with that provider under the provider’s own terms:

ProviderPurposeData processed
GitHub, Linear, Jira, AsanaCreating and syncing issues from ticketsThe full synced ticket: title, description, diagnostic context, and the screenshot (attached where the tracker supports it)
SlackTicket notifications to your workspaceTicket title, page path, and reporter name
AI agents via MCP (e.g. Claude, Cursor)Customer-initiated agent workflows you authorizeTicket context you expose to the agent — see our AI Policy

Changes & notice

We keep this list current, and give at least 14 days’ notice before a new subprocessor of Customer Data takes effect. To receive those notices, email [email protected] and ask to be added to our subprocessor-change notification list. Customers may object to a new subprocessor as described in the Data Processing Addendum.