Sub-processors

Who else handles Helmspur data — and where it flows.

A public list of every third party that processes customer or user data on Helmspur's behalf — written so an infosec team can read it against the live data flow in this repo, not against a generic privacy page.

Working list

Helmspur — sub-processors

This page lists the sub-processors currently wired in — it is not an attestation.

The regions and data categories below reflect what is actually shipping in this repo today. Each row links to the vendor's own security page so the live posture can be verified against our record. If a row here does not match the data flow in this codebase, that is a bug — please flag it.

Sub-processors in scope

Sub-processors in scope

Two vendors touch customer or user data on Helmspur's behalf — the platform that hosts the app and the payment processor for one-time and subscription plans. Better-auth, the email proxy, and the analytics beacon are NOT separate vendors: they are in-process library code and platform egress living under the platform row.

ProviderPurposeData categoryProcessing regionVendor security pageLast reviewed
Polsia platformWeb hosting, edge, runtime, database hosting (Postgres provisioned by Polsia via rdbms), and the analytics beacon that ships as a same-origin pixel to polsia.com/api/beacon/pixel.All persisted app data: User / Session / Account / Verification (auth), Project / Revision / Clash (content), ContactMessage, WaitlistEntry, ApiKey (hashed).EU/EEC platform-default region. (polsia.com)polsia.com/security2026-08-23
Stripe, Inc. (via Polsia Connect)Payment processing for one-time and subscription plans. Invoked exclusively through the installed stripe-billing module (createCheckoutSession → Polsia proxy → Stripe Connect hosted checkout). Cardholder data NEVER enters this app — Stripe owns PAN / CVC.Payment metadata only: amount, currency, Stripe customer id, payment status. NO PAN, NO CVC, NO raw card data.Multiple — see Stripe's current sub-processor list (Stripe routes processing to its own published processors; the current list includes EU + US presences).stripe.com/legal/sub-processors·stripe.com/security2026-08-23

Vendor security cells open each provider's own live page in a new tab. The list is reviewed on every code change, and the Last reviewed column carries the date of that pass.

What this list does (and does not) show

What this list does (and does not) show

Three things reviewers often ask about are NOT separate sub-processors on this page. Better-auth is an in-process library that persists its own User / Session / Account / Verification tables on the platform Postgres — no third-party identity service is in scope. The Polsia email proxy is a platform egress: customer-facing and internal mail is sent through the same platform, never through a vendor SDK or a vendor API key in this repo. The analytics beacon is a same-origin pixel served by polsia.com — it is not a third-party tag manager. Listing any of the three as a separate vendor would misrepresent what the code actually does.

How to request the live DPA

How to request the live DPA

The same intake covers both DPA requests and sub-processor list pulls — pick the closest match when you file. Replies go out same-day from the engineering owner who maintains this page, and the request lands in the same priority-leaning inbox as a vulnerability disclosure.

Reader's checklist

Reader's checklist

Every row above is grounded in the actual data flow in this repo. The platform row is backed by polsia.toml (rdbms provisioning) and every schema file under prisma/schema/. The Stripe row is backed by src/lib/stripe-billing/client.ts and the stripe-billing module's verify route. If a vendor in this table is not referenced from one of those file paths, it should be removed — and if the data flow carries data to a vendor not listed here, it should be added.