Subprocessors
Last updated
Rebase uses a small set of trusted third parties to help deliver our service. This page lists them, where they process data, and what each one processes. It supplements our Privacy Policy and DPA.
Subprocessors of Customer Data
These providers process Customer Data (the feedback, tickets, and diagnostic context captured through the widget) on our behalf under the Data Processing Addendum:
| Subprocessor | Location | Purpose | Data processed |
|---|---|---|---|
| DigitalOcean | United Kingdom (London) | Cloud hosting, managed database, and encrypted object storage for screenshots and uploads | All service data, including account, ticket, and feedback data |
| Cloudflare | Global edge network | DNS, CDN, and edge delivery for the website, API, and widget (cdn.rebase.dev); terminates TLS at its edge | Request metadata (IP, user agent) and, in transit, request content |
| Amazon SES (AWS) | Ireland (EU) | Email delivery — sign-in codes, invites, mentions, digests, and sales/careers enquiries | Recipient email address and message content |
| OpenAI | United States | AI triage of incoming tickets (classification, titles, summaries) — see the AI Policy | A minimized, scrubbed slice of ticket text (description, console/network metadata, code frames). Screenshots are never sent; data is not used for training |
| Sentry | United States | Error monitoring of our own service | Error reports and stack traces, which may include request context |
| Stripe | United States | Payment processing and subscription billing | Billing contact and payment data (card data is held by Stripe, not Rebase) |
Providers for our own operations
These providers support Rebase’s own website and business (with Rebase as controller); they do not receive Customer Data captured through the widget:
| Provider | Location | Purpose | Data processed |
|---|---|---|---|
| Google (Google Analytics) | United States | Aggregate website usage analytics on rebase.dev, loaded only with your consent | Website usage events and online identifiers (e.g. cookies, IP address) |
| HubSpot | United States | CRM for sales and customer relationships | Business contact details (name, email, company) and account lifecycle status |
Integrations you connect
The following are activated only when a customer chooses to connect them. When connected, the synced ticket content is shared with that provider under the provider’s own terms:
| Provider | Purpose | Data processed |
|---|---|---|
| GitHub, Linear, Jira, Asana | Creating and syncing issues from tickets | The full synced ticket: title, description, diagnostic context, and the screenshot (attached where the tracker supports it) |
| Slack | Ticket notifications to your workspace | Ticket title, page path, and reporter name |
| AI agents via MCP (e.g. Claude, Cursor) | Customer-initiated agent workflows you authorize | Ticket context you expose to the agent — see our AI Policy |
Changes & notice
We keep this list current, and give at least 14 days’ notice before a new subprocessor of Customer Data takes effect. To receive those notices, email [email protected] and ask to be added to our subprocessor-change notification list. Customers may object to a new subprocessor as described in the Data Processing Addendum.