Last updated: 20 July 2026
We use a small number of third-party providers to run Trouble Clef. Each subprocessor that could access personal data is bound by a Data Processing Agreement ("DPA") requiring them to handle it securely and only for the purpose we've engaged them for. This list doesn't include every internal tool we use — only those that could touch your personal data.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Railway Visit → | Backend hosting — runs the application server and stores your library (scores, setlists, lead sheets, account data) | United States (US West) | Standard Contractual Clauses |
| Vercel Visit → | Frontend hosting — serves the web application | United States (global edge network) | Standard Contractual Clauses |
| Google Visit → | “Log in with Google” — only if you choose this sign-in method | United States | Standard Contractual Clauses / EU-US Data Privacy Framework |
The following handle payments as independent data controllers, not as our subprocessors — they set their own privacy terms for the payment data they collect directly from you at checkout.
| Provider | Purpose |
|---|---|
| Stripe Visit → | Processes Pro subscription payments. See Stripe's Privacy Policy. |
Where a subprocessor is located outside the UK/EEA, transfers are protected by appropriate safeguards — typically the UK/EU Standard Contractual Clauses, an adequacy decision, or a recognised framework like the EU-US Data Privacy Framework — along with encryption in transit and at rest.
We review this list periodically. If we add a new subprocessor that materially changes how your personal data is processed, we'll update this page and, where required, notify you in advance.
Questions about our subprocessors: privacy@trouble-clef.com.