Skip to content
checkredirects.io
Product API docs Integrations Pricing Sign in Start free
Home/Privacy/Sub-processors
PRIVACY

Sub-processors and other data recipients

Last updated: September 26, 2026

These providers support checkredirects.io. Customer-selected destinations are listed separately. For processing covered by a DPA, Annex III identifies the approved subprocessors, their tasks and processing locations.

Hosting, sign-in and error reporting

ProviderPurposeWhat it receives
Hetzner API hosting Inspection requests and results, request settings, network information, and authentication and account details.
Neon Database hosting Stored account, organization, inspection, integration, usage and billing records, including saved credentials, Terms acceptance, support, communications and security records.
Netlify Hosting for the web app and marketing site Page and file requests, including URLs, IP addresses, browser information and referring pages. Inspection inputs and results go to the separate inspection service.
Cloudflare Website routing, delivery and security Website and API traffic, including complete URLs, network and browser information, authentication details, inspection requests and results.
Clerk User sign-in and session management Email address, name, user identifier, and information about sign-ins, connected login providers and active sessions.
Sentry Error reporting and performance monitoring Error reports and performance information, including error messages, URL paths, request details and technical identifiers. Browser reports may also include account and organization details, including names and email addresses. Turning off data collection in Organization Settings removes that account information from browser reports but does not stop error reporting.

Billing, communications and website analytics

ProviderPurposeWhat it receivesWhen
Stripe Payments and subscription billing Billing contact and organization details, plan and purchase details, transaction identifiers and status, amounts, currency and receipts. Payment details are entered directly with Stripe; we do not receive card numbers. Subscription, credit-purchase and billing activity.
Mailgun Essential account emails Recipient email address and complete message contents, which may include organization details, balances, plan limits, invitation roles and time-limited invitation links. Account notices, invitations and usage warnings.
Loops.so Product emails Contact and organization details, roles, plan and billing information, limits, balances, usage and product activity, invitations, referrals and rewards, dates and product links. Account and product activity, unless your organization has turned off data collection.
Plausible Insights OÜ Public marketing-site analytics Page URLs (including query strings), referring pages, website activity, IP addresses and browser/device information. We do not attach account identifiers or inspection data to analytics reports. Plausible processes visitor data in the EU. Visits to the public website, not the signed-in application.

Destinations you choose

RecipientPurposeWhat it receivesWhen
Google Sheets Exporting results to a spreadsheet you control Connection credentials, spreadsheet and folder identifiers, and exported inspection results. Exports preserve complete stored URLs, including any credentials or other sensitive information they contain. When you connect Google or request or schedule an export.
Target websites and redirect destinations Performing the inspection you requested Requested URLs and request settings, including browser identity and supplied headers. Cookies and login credentials are restricted to the original website origin; redirect destinations receive the non-credential information needed to follow the redirects. When you request an inspection or a scheduled monitor runs.
Webhooks and other integrations you configure Inspection and monitoring updates The delivery address and updates containing identifiers, progress, dates and relevant inspection results. Depending on the feature, these can include complete URLs, errors and additional fields you supplied. An update is sent to a destination you selected.

Deleting your organization

Organization deletion does not automatically erase provider records or copies sent to destinations you select. We coordinate required deletion by our appointed subprocessors; requests to customer-selected destinations must be made directly to them. See the Privacy Policy for retention details and request contacts. Our obligations under applicable law and any DPA continue to apply.

Changes to this list

We update this page when providers or recipients change. For customers with a DPA, we provide notice and handle objections under its subprocessor-change provisions.

Contact

[email protected]

checkredirects.io

A URL inspection API for developers and SEO teams.

Product
Features Batch Monitors Agent compare MCP server
Developers
REST API OpenAPI spec HTTP status codes
Integrations
Sheets Zapier n8n Make GitHub Action
Company
Contact Privacy Terms Sub-processors
api.checkredirects.io · all systems normal © 2026 checkredirects.io