Legal & Trust
Legal

Subprocessors

Third parties that process customer data on StorageFlo.io's behalf, plus our integration-partner posture.

EffectiveApril 25, 2026·v1.0·Last updatedApril 25, 2026
USCAEUUKAU

1. What is a subprocessor

A subprocessor is a third-party organization that processes Customer Data on StorageFlo's behalf in order to provide the Service. Under the GDPR and equivalent data protection laws, StorageFlo acts as a Processor with respect to tenant Personal Data and must ensure that any party we engage to help deliver the Service meets equivalent data protection standards.

This page lists every entity that qualifies as a subprocessor under our Data Processing Addendum. It is distinct from our broader list of technology vendors and tools that may support our internal operations but do not touch Customer Data.

When we add or replace a subprocessor, we update this page and give advance notice as described in Section 4 below. The timing and mechanics of that notice are governed by the DPA.

If you are a Customer seeking to review or object to a subprocessor addition as part of your GDPR compliance programme, please contact us at [email protected].

2. Current subprocessors

The table below lists all current subprocessors, the purpose for which each is engaged, the category of data involved, the region in which processing occurs, the applicable compliance certifications, and a link to the subprocessor's own compliance information.

ProviderPurposeDataRegionComplianceLink
Google Cloud PlatformHosting, compute, storage, networkingAll operator and tenant data at rest, encryptedUS (multi-region)SOC 2, ISO 27001, GDPRcloud.google.com
Firebase (Google)Authentication, Firestore, Hosting, Functions, StorageAuth tokens, application data, user contentUS (multi-region)SOC 2, ISO 27001, GDPRfirebase.google.com
StripePayment processing (gateway option)Cardholder data, payment metadataUS / EUPCI DSS Level 1stripe.com
SquarePayment processing (gateway option)Cardholder data, payment metadataUSPCI DSS Level 1squareup.com
SentryError monitoringError stack traces, redacted user IDsUS / EUSOC 2sentry.io
ResendTransactional email deliveryRecipient email addresses, message contentUSSOC 2resend.com
TwilioSMS delivery (when enabled)Phone numbers, message contentUSSOC 2twilio.com

A note on Stripe and Square as payment subprocessors. When StorageFlo facilitates a payment transaction on a Customer's behalf through our platform-level payment processing feature, Stripe or Square processes cardholder data as a subprocessor of StorageFlo. This is distinct from the operator-merchant relationship described in Section 3 below.

A note on Sentry. Error monitoring data is transmitted to Sentry at the moment an application error occurs. User identifiers are redacted or hashed before transmission. Sentry does not receive payment card data, tenant lease details, or full PII records under our data minimization policy.

A note on Twilio. SMS delivery is only engaged when the Customer has enabled SMS communications as a feature. If your workspace does not use the SMS feature, Twilio does not process any data in connection with your account.

All subprocessors are required, by contract, to process Customer Data only on StorageFlo's instructions, to maintain technical and organizational measures equivalent to those described in the DPA, and to notify StorageFlo promptly in the event of a security incident involving Customer Data.

3. Integration partners (not subprocessors)

Integration partners are third-party systems that the Customer independently chooses to connect to StorageFlo. When a Customer configures an integration, data flows between StorageFlo and the third-party system under the Customer's authority and at the Customer's direction. The Customer, not StorageFlo, determines the purpose and means of that data exchange.

Because StorageFlo processes data from these integrations solely as a conduit for the Customer's own instruction, the third-party systems themselves are not subprocessors of StorageFlo under applicable data protection law. The Customer's relationship with each integration partner is governed by that partner's own terms of service, privacy policy, and applicable data processing agreements.

Integration partners that Customers may connect to StorageFlo include:

  • SiteLink (storage management software).
  • storEDGE (storage management software).
  • Yardi Breeze (property management software).
  • Any other third-party storage management or business system the Customer connects using StorageFlo's integration framework.

Customers who connect these systems are responsible for ensuring they have the right to share that system's data with StorageFlo and for executing any data processing agreements that the integration partner requires.

Operator-merchant payment accounts. When an operator connects their own Stripe Connect account or Square seller account to StorageFlo, the resulting payment processing relationship is between the operator and that payment processor directly. The operator is the merchant of record. That arrangement does not constitute StorageFlo engaging Stripe or Square as a subprocessor for those transactions, because StorageFlo is not the party directing the payment processing on the operator's behalf. The operator's own Stripe or Square terms of service govern.

4. Notification of changes

StorageFlo updates this page whenever a subprocessor is added, replaced, or removed. The mechanics of advance notice are described in the DPA. In general:

  • Additions and replacements. We provide reasonable advance notice before a new subprocessor begins processing Customer Data. The specific notice period is stated in the DPA.
  • Removals. We update this page promptly when a subprocessor relationship ends. No advance notice is required for removals.

To subscribe to subprocessor change notifications, send an email to [email protected] with the subject line "Subprocessor change notifications." We will add you to the distribution list and email you each time this page is updated.

If you object to a subprocessor addition on data protection grounds, please contact us at [email protected] as soon as possible. We will work with you to find a resolution. Where resolution is not possible and the addition is essential to delivering the Service, the DPA sets out the process that applies.

5. Last updated

This page was last updated on 2026-04-25. The current version is 1.0.

For any questions about our subprocessor list or data protection practices, contact us at [email protected] or review our Privacy Policy and DPA.

Ready to evaluate?

Review the terms, then start the setup.

Once the operational, privacy, and payment boundaries make sense for your team, you can start shaping the booking path for your facility.

Clear policiesDefined boundariesOperator control