<!-- Markdown rendering of https://accountingkit.dev/subprocessors/ -->

> The complete list of third parties that process customer data for AccountingKit, what each one touches, and where it runs.

Legal

# Subprocessors

This is the whole list. AccountingKit runs a deliberately small processing chain, because every name here is a name your customers have to trust as well.

- **Version**: 1.0
- **Effective**: 1 September 2026
- **Questions**: privacy@accountingkit.dev

On this page

1.  [Current subprocessors](#list)
2.  [Your accounting provider](#providers)
3.  [Not currently engaged](#not-engaged)
4.  [Change notice and objection](#notice)

## Current subprocessors

Each subprocessor below is engaged under a written contract that binds it to data protection obligations no less protective than those in our [Data Processing Addendum](https://accountingkit.dev/dpa/). AccountingKit remains fully liable to you for their performance.

Subprocessor

Purpose

Data it can touch

Processing location

**Google Cloud**  
Google Cloud EMEA Limited

Application compute (Cloud Run), the primary PostgreSQL database (Cloud SQL), encryption key management (Cloud KMS), and secret storage (Secret Manager)

All customer data held by the service, including console accounts, connections, stored accounting records, and workflow state

Germany — europe-west3 (Frankfurt, Germany)

**Cloudflare**  
Cloudflare, Inc.

DNS, TLS termination, CDN, and static asset hosting for the marketing site and the developer console

Request metadata only — IP address, user agent, requested URL, timestamp. No accounting data is stored at the edge

Global edge network

**Resend**  
Plus Five Five, Inc.

Transactional email delivery — sign-in messages, team invitations, and operational notices

Recipient name and email address, and the content of that message

United States

**Vercel**  
Vercel, Inc.

Hosting for the documentation site at docs.accountingkit.dev

Request metadata for documentation pages only. The documentation site is static and holds no customer data

Global edge network

**Dodo Payments**  
Merchant of record

Subscription checkout, payment processing, invoicing, and sales tax handling. Dodo Payments is the seller of record on your receipt

Billing contact name and email, billing country, tax identifier, and transaction records. No accounting record data

Global

This list is complete and current as of the effective date at the top of this page.

## Your accounting provider is not our subprocessor

Xero, and any accounting platform you connect, is a third party **you** hold a relationship with and instruct us to reach on your behalf. It is not engaged by AccountingKit, and it processes your data under your agreement with it, not ours.

We mention this because procurement reviews frequently ask. The distinction matters: revoking AccountingKit's access does not affect your provider account, and our subprocessor commitments do not extend to a platform we do not engage.

## Not currently engaged

The platform supports several integrations that production does not use today. We list them so that reading the code, or a future release note, does not look like an undisclosed change:

-   **Object storage.** Disabled in production. No files are stored with a third-party object store.
-   **Third-party error monitoring.** Not enabled in production. Application errors are captured in the platform's own logs, which exclude secrets and payload bodies.
-   **Social sign-in.** No third-party identity provider is enabled for console sign-in.

Turning any of these on would be a subprocessor change and would follow the notice process below.

## Change notice and objection

We give at least 30 days' notice before adding or replacing a subprocessor. Notice goes by email to your account contacts and by updating this page and its effective date.

You may object on reasonable data protection grounds within that period by writing to [privacy@accountingkit.dev](mailto:privacy@accountingkit.dev). We will work with you to resolve it. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.

To be notified of changes here, email us and ask to be added to the subprocessor notice list.

Related

[**Terms of Service** The contract that governs access to the API, the console, and workflow execution.](https://accountingkit.dev/terms/) [**Privacy Policy** What personal data AccountingKit handles, why, where it lives, and for how long.](https://accountingkit.dev/privacy/) [**Data Processing Addendum** Article 28 processor terms, the processing record, security measures, and transfer safeguards.](https://accountingkit.dev/dpa/) [**Acceptable Use Policy** What you may not run through AccountingKit, and what happens if you do.](https://accountingkit.dev/acceptable-use/) [**Cookie Notice** The marketing site sets no cookies. The console sets one, and it is essential.](https://accountingkit.dev/cookies/) [**Security** The controls behind the platform, stated plainly, including the ones not yet certified.](https://accountingkit.dev/security/)
