TourifikTourifik
TermsPrivacyRefundsUse policy

Legal

Sub-processors

The third-party services that help us run the platform, and what data each one touches.

Effective Date: July 29, 2026

Last Updated: September 26, 2026

A Sub-processor is a third-party service we use to operate the Platform, like Stripe for payments or Supabase for our database. We share with each Sub-processor only the data needed for its specific purpose, and we require each one by contract to protect your data, use it only for the purposes we authorize, and meet applicable data protection law. This page is the canonical list referenced by Section 9.2 of our Privacy Policy at /legal/privacy.

When we add or remove a Sub-processor we update this page, and we notify users in the European Economic Area, the United Kingdom, and Switzerland at least thirty (30) days before a new Sub-processor begins processing their data, with an explanation of the right to object.

Current Sub-processors

Sub-processor Purpose Data shared Location Privacy policy
Stripe, Inc. (including Stripe Identity)* Payments, Connect platform payouts, Identity verification Name, email, phone, payment instrument, government ID (for Identity), business info US, EU, India stripe.com/privacy
Supabase, Inc. Database, authentication, file storage All account and Platform data US (AWS us-east-1) supabase.com/privacy
Vercel, Inc. Hosting, edge functions, scheduled tasks Application logs, server-side request data Global edge with US storage vercel.com/legal/privacy-policy
Cloudflare, Inc. DNS, edge caching, DDoS protection IP addresses, request metadata Global edge, US headquarters cloudflare.com/privacypolicy
Mapbox, Inc. Map display, geocoding Venue addresses, IP for tile delivery US (AWS) mapbox.com/legal/privacy
Anthropic, PBC Ask AI feature, content analysis, and Market Check web research User queries to Ask AI, content submitted for AI analysis; for Market Check, a metro area and month only (never an artist name, venue or date being negotiated) US anthropic.com/legal/privacy
Google LLC (Gemini API) AI image generation for marketing assets Photos and prompts a workspace submits for asset generation Global policies.google.com/privacy
Resend, Inc. Transactional email Recipient email, message body and metadata US resend.com/legal/privacy-policy
Google LLC (Gmail SMTP) Transactional email fallback during migration Recipient email, message body and metadata Global policies.google.com/privacy
Twilio Inc. Text-message reminders (only after express opt-in at checkout; not active until our SMS program registration is approved) Phone number, message content, consent record US twilio.com/en-us/legal/privacy
Meta Platforms, Inc. Facebook Page admin OAuth for Artist verification; advertising measurement (Meta Pixel and Conversions API), always subject to the consent controls in Privacy Policy Section 11 OAuth token scoped to Page admin status; with consent: pixel cookie identifiers (_fbp/_fbc), and on ticket purchase a SHA-256-hashed email and phone plus order value US facebook.com/privacy/policy
PostHog, Inc. Product analytics, subject to the consent controls in Privacy Policy Section 11 Usage events, pages viewed, device and browser info, account id and email once signed in US posthog.com/privacy
Functional Software, Inc. (Sentry) Error monitoring Error reports with request metadata; personal fields are scrubbed before sending US sentry.io/privacy
Spotify AB Artist profile images and catalog lookups via the Spotify Web API Artist names we search; no user Personal Information EU (Sweden), US spotify.com/legal/privacy-policy
Ticketmaster (Live Nation Entertainment, Inc.) Public event listings used by Market Check to find concerts near a venue on a candidate date Venue coordinates and a date range only; no Personal Information and no user, artist or booking identifiers US privacy.ticketmaster.com
Firecrawl Fetching public web pages during partner onboarding Public URLs we are asked to import; no account data US firecrawl.dev/privacy-policy
Apple Inc. Sign in with Apple authentication Apple-provided email, name on first signup only US apple.com/legal/privacy

*Stripe Identity processes biometric data under Stripe's separate retention schedule (no longer than one year per Stripe Privacy Center, or upon revocation of your consent, whichever is earlier).

Questions or Objections

Email privacy@tourifik.com. Users in the European Economic Area, the United Kingdom, and Switzerland may object to a new Sub-processor within the thirty (30) day notice window; we will work with you in good faith on a resolution, which may include not applying the new Sub-processor to your data where technically feasible.

© 2026 Connect Live AI, Inc. · Franklin, TNTourifik™ is a trademark of Connect Live AI, Inc.
DMCASub-processorsAccessibilityDo Not Sellhello@tourifik.com