chat2guest Sub-processors
Effective date: 30 May 2026 Last updated: 30 May 2026
The canonical, publicly accessible version of this list is published at https://chat2guest.com/legal/subprocessors. Read together with our Privacy Policy and Terms of Service.
1. What this list covers
A sub-processor is a third party that chat2guest ("chat2guest") engages to process personal data on Customers' behalf in the course of providing the chat2guest service. Independent third-party controllers (such as Meta, Google, Stripe, and Apple) act on their own account when restaurants connect those platforms and are addressed in our Privacy Policy; they are not sub-processors of chat2guest and are listed below for transparency only where they appear in the data flow.
2. Core infrastructure sub-processors
| Sub-processor | Role | Hosting / processing location | Transfer mechanism for transfers out of the EEA / Switzerland |
|---|---|---|---|
| Fly.io, Inc. | Application hosting (backend, bridge, admin), Postgres-managed database, internal networking | EU (Amsterdam ams region) by default; may use other regions if explicitly configured | EU Standard Contractual Clauses (Decision 2021/914) where US fallback applies; EU-US Data Privacy Framework where the recipient is self-certified |
| Cloudflare, Inc. | DNS, edge CDN, TLS termination, DDoS protection for public domains | Global edge network with EU presence | EU Standard Contractual Clauses; EU-US Data Privacy Framework where the recipient is self-certified |
| GitHub, Inc. (Microsoft) | Source code hosting, CI runners | United States | EU Standard Contractual Clauses; EU-US Data Privacy Framework |
3. Communications, messaging, and AI sub-processors
| Sub-processor | Role | Hosting / processing location | Transfer mechanism for transfers out of the EEA / Switzerland |
|---|---|---|---|
| OpenAI, L.L.C. | AI model inference for drafting replies, classification, and knowledge re-use; data is sent on a per-request basis under OpenAI's enterprise / API terms (zero-day retention for API traffic where enabled) | United States | EU Standard Contractual Clauses; EU-US Data Privacy Framework where the recipient is self-certified; supplementary measures documented in our transfer impact assessment |
| Anthropic PBC | Optional AI model inference (used where the relevant tenant / feature is configured to call Claude) | United States | EU Standard Contractual Clauses; EU-US Data Privacy Framework where the recipient is self-certified |
| Plus Five Five, Inc. (operating as Resend) | Transactional email delivery (booking confirmations, cancellation links, password resets, data-deletion confirmation links) | Account data, email metadata, and API logs stored in the United States; sending may be routed through Resend's EU region (Ireland) where the relevant account is configured for it | EU Standard Contractual Clauses; EU-US Data Privacy Framework and UK Extension (Plus Five Five, Inc. is DPF-certified) |
| Chatwoot, Inc. (vendored, self-hosted) | Multi-tenant inbox and messaging routing. Deployed by chat2guest as a self-hosted, vendored stack — no Customer Data is sent to Chatwoot, Inc. as a SaaS service. Listed here for transparency about the upstream software supply chain. | Self-hosted on Fly.io (see above) | Not applicable (no transfer to Chatwoot, Inc.) |
4. Independent third-party controllers (for transparency)
The following third parties are not sub-processors of chat2guest but appear in the data flow when restaurants enable the corresponding integrations. They process personal data as independent controllers for their own purposes under their own terms.
| Third party | Role | Where engaged |
|---|---|---|
| Meta Platforms, Inc. (Facebook, Instagram, Messenger) | Messaging-platform operator. Receives the messages, comments, and identifiers exchanged through Facebook Page, Instagram Business / Creator, or Messenger surfaces. | When a restaurant connects a Meta-platform account through chat2guest |
| WhatsApp LLC (Meta) | WhatsApp Business Cloud API operator. Receives the messages exchanged through the WhatsApp channel. | When a restaurant connects the WhatsApp Business Cloud API |
| Google LLC | Google Business Profile operator. Provides reviews data and posts owner replies. | When a restaurant connects a Google Business Profile |
| Stripe Payments Europe, Limited (SPEL, Ireland) | Payment processor for deposits and related payment events under Stripe Connect Express. Stripe acts as both processor and an independent controller (for fraud-prevention, AML, and financial-services purposes). EU operational data controller for chat2guest's European transactions. | When a restaurant connects Stripe Connect |
| Apple Inc. (APNs) and browser push providers | Delivery infrastructure for native and web push notifications, when enabled. | When the admin enables push notifications |
5. Observability and security sub-processors
| Sub-processor | Role | Hosting / processing location | Transfer mechanism for transfers out of the EEA / Switzerland |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Error and performance monitoring across backend, bridge, and admin. Configured to scrub message payloads and personal data; only stack traces, request metadata, and aggregated counts are retained. | United States | EU Standard Contractual Clauses; EU-US Data Privacy Framework where the recipient is self-certified |
6. International data transfer safeguards
Where any of the sub-processors above is established outside the EEA or Switzerland, or where personal data is otherwise transferred out of those areas, chat2guest relies on:
- an adequacy decision adopted by the European Commission (Article 45 GDPR) or recognised by the Swiss Federal Council (Article 16 revFADP), including the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework where the recipient is appropriately self-certified;
- the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the supplementary measures we consider necessary following the Schrems II line of case-law, including encryption in transit, encryption at rest of selected sensitive fields, strict access controls, and contractual restrictions on access by government authorities; and
- where applicable, the Swiss FDPIC-recognised version of the Standard Contractual Clauses.
A copy of the relevant transfer mechanism and the supplementary measures we apply is available on request to [email protected].
7. Changes to this list
We may add or replace sub-processors from time to time. When we do, we will update this page and the "Last updated" date above. Where a customer is subject to a data processing agreement that includes a sub-processor change-notification clause, we will follow the notice procedure in that DPA.
8. Contact
chat2guest (alpstudios GmbH, trading as chat2guest) Country of establishment: Switzerland Email (privacy and sub-processor questions): [email protected] Email (general): [email protected]