Sub-processors

Last updated: 1 October 2026

Mailbase relies on the services below to run the product. This list is built from Mailbase's code: a service that processes personal data and is missing here is a mistake you should tell us about.

1. Services in use

The “When” column says whether a service is always involved, only after your consent (cookies), only if the operator switched it on, or only if you connect it yourself. When you connect your own account (mailbox, AI provider, sending provider), that provider acts for you and under your own terms with it.

ServicePurposeDataLocationWhen
Amazon Web Services (Amazon SES and SNS)Sending email through Mailbase's managed sending, receiving replies, and reporting deliveries, bounces and complaints back.Recipient and sender addresses, subject and content of each email, delivery events, replies received.eu-west-1 (Ireland) — set by the AWS_SES_REGION settingAlways
StripeSubscriptions, invoices and payment for plans and for domains bought through Mailbase. Card details are entered on Stripe and never reach Mailbase.Account owner's name and email, workspace and plan, payment and invoice records.Stripe Payments Europe, Ltd. (Ireland); transfers per Stripe's own termsAlways
Google (sign-in with Google, optional Gmail mailbox)Signing in with a Google account, and — only if the customer connects a Gmail mailbox — reading and sending mail from it.Name, email address and profile identifier returned by Google; for a connected mailbox, the mail itself and OAuth tokens (stored encrypted).Google's own infrastructureIf the customer connects it
Google (Analytics 4 and Google Ads measurement)Audience measurement and advertising conversion measurement on the public website. The tag runs in Google Consent Mode with every category denied until the visitor accepts the cookie banner.Pages viewed, device and browser information, approximate location, and identifiers — only once consent is given.Google's own infrastructureAfter consent
PostHogProduct analytics. Loaded in the browser only after the visitor accepts the cookie banner; server-side events carry hashed workspace identifiers and no email address or message content.Pages and features used, browser and device information, hashed workspace identifiers.As configured by NEXT_PUBLIC_POSTHOG_HOST; the example configuration points at us.i.posthog.com (United States). [À COMPLÉTER : région PostHog réellement utilisée en production]After consent
AI model endpoint (OpenRouter by default, optionally Cloudflare AI Gateway) and the model provider behind it (DeepSeek by default)The AI assistant, the drafting of prospecting emails, reply triage and the content check of outgoing mail, for workspaces that do not bring their own AI account.Only the content needed for the request: the user's instruction, and for prospecting the public facts about the company (name, activity, city, public contact and website excerpts) and the first name and role of the person addressed.Providers established outside the EEA in the default configuration (OpenRouter: United States; DeepSeek: China) — [À COMPLÉTER : garanties de transfert retenues (clauses contractuelles types, etc.)]Always
AI providers a customer connects itself (OpenAI / ChatGPT, DeepSeek, OpenRouter, MiniMax, Groq, Mistral, or any compatible endpoint)The same AI features, run on the customer's own account and at its own cost. The credential is stored encrypted.The content of the request, as above.Depends on the provider the customer choosesIf the customer connects it
TypeSafe (TypeSafe AI)Scam and phishing screening of outgoing email before it is sent, and a fit check of prospecting results against the target the customer described.Sender name and address, reply-to, subject, body, link domains and visible link text, and the number and domains of recipients (not their addresses); for the fit check, a company's register facts (name, activity code, legal form, city).Provider's own infrastructure — [À COMPLÉTER : région à confirmer auprès de TypeSafe]Always
PorkbunRegistering and renewing domain names a customer buys through Mailbase, and writing their DNS records.The domain name and the registrant contact details Mailbase is configured to give the registrar.United StatesIf the customer connects it
Serper (google.serper.dev)Prospecting: finding a company's website from its name and city. Used only when the operator has set a Serper key; a self-hosted search instance is the alternative.A search query made of a company's name and city.Provider's own infrastructure (not stated by the provider in the code)If configured
Browserless (headless Chrome rendering)Prospecting: rendering company websites whose content only appears with JavaScript, to read the legal notice and contact page. Used only when configured.The address of a public company web page; the page content comes back.As configured (browserless.io, or an instance run by the operator)If configured
[À COMPLÉTER : nom de l’hébergeur de l’application et de la base de données]Hosting of the application and of its PostgreSQL database.Everything stored in Mailbase.[À COMPLÉTER : pays / région d’hébergement]Always

2. Public sources (not sub-processors)

Prospecting reads these public sources. They do not receive personal data from Mailbase beyond search filters.

  • Recherche d’entreprises API (data.gouv.fr — INSEE SIRENE register and RNE). Public open data on French companies and their registered leaders. Mailbase reads it; nothing is sent to it but the search filters.
  • The company's own website and legal notice. Public pages the company published itself. Mailbase reads the contact email and the name of the person responsible from them.

3. Transfers outside the European Economic Area

Several services above are provided by companies established outside the European Union. Where a transfer takes place, it must rest on a mechanism the GDPR provides for (an adequacy decision or standard contractual clauses).

4. Changes and questions

This page is updated before a new service starts processing personal data. A question? contact@mailbase.studio or the contact form.