Overview
We engage sub-processors under written terms requiring confidentiality and data-protection obligations consistent with our Privacy Notice. A sub-processor is a third party that processes personal data on our behalf to deliver part of the service. This page names the sub-processors we currently rely on; it does not change the roles described in our Privacy Notice, where PageLantern acts as a controller for account and operational data and as a processor for the monitoring content a customer configures.
Some of the providers below are active only in specific circumstances — for example, Google Identity Services may offer an account-selection prompt on the public homepage, while PageLantern receives an identity assertion only after you choose to continue; other social sign-in providers are involved only when you choose them, and third-party object storage is used only when an operator enables it. Those conditions are stated in the Status column so the list stays truthful about what is actually processing data.
Current sub-processors
| Sub-processor | Purpose | Personal data | Region | Status |
|---|---|---|---|---|
| Mailgun | Transactional and alert email delivery: account verification and lifecycle emails, monitor and incident alerts, summaries, and feedback confirmations. | Recipient email addresses and the content of the emails we send. | United States | Active — primary email-delivery provider. An SMTP fallback may route through a third-party mail provider if configured. |
| “Sign in with Google” single sign-on; hosting of the mailbox that receives support and feedback correspondence; website and application usage measurement through Google Analytics 4; and Google Ads purchase conversion attribution. | Sign-in: provider identifier, email, display name, last-login time. Mailbox: the email, message, and screenshot a user submits through the feedback form. Analytics: page or screen viewed, referrer, approximate location derived from a truncated IP address, device and browser characteristics, and — only after you accept measurement cookies — a randomly generated analytics identifier. Ads measurement: Google ad-click attribution data and, after Stripe confirms a completed, paid purchase, the conversion label, USD 1 value, currency, and unique Stripe Checkout session identifier used as the transaction ID. | United States / global | Active for support/feedback mailbox hosting, Google Analytics, and consent-gated Google Ads conversion measurement. Google Identity Services may offer an account-selection prompt on the public homepage; PageLantern receives the identity assertion only after you choose to continue. Analytics and advertising storage default to denied and are granted only after acceptance. Ad personalization and enhanced conversions are not enabled. | |
| OpenAI | ChatGPT Ads attribution and conversion measurement: determining whether an ad click led to a completed PageLantern registration. | After consent: the ChatGPT ad click reference (oppref), page origin, registration event name and timestamp, event type, USD 0 value and currency, and browser/device and network metadata used by the pixel. PageLantern does not attach registration form fields or an email address to its explicit conversion event. | United States / global | Active only after the visitor accepts measurement cookies. The pixel receives a denied consent state before initialization; rejecting or ignoring the banner prevents measurement pings. |
| Microsoft | “Sign in with Microsoft” single sign-on. | Provider identifier, email, and display name from the identity assertion. | United States / global | Optional — used only when you choose to sign in with Microsoft and it is configured. |
| Apple | “Sign in with Apple” single sign-on. | Provider identifier, email (or relay address), and display name from the identity assertion. | United States / global | Optional — used only when you choose to sign in with Apple and it is configured. |
| Meta Platforms (Facebook) | “Sign in with Facebook” single sign-on. | Provider identifier, email, and display name from the identity assertion. | United States / global | Optional — used only when you choose to sign in with Facebook and it is configured. |
| Stripe | Payment processing and subscription management: checkout, card storage, renewals, plan changes, invoices, and refunds. | Billing name and email, payment-method details (handled by Stripe; PageLantern never receives or stores a full card number), subscription and invoice records, and billing address and tax identifiers where you supply them. | United States / global | Active — the payment provider for all paid plans. Not involved for Free-plan accounts. |
| Twilio | SMS delivery: monitor and incident alerts sent to the phone numbers you configure, and SMS-based multi-factor authentication codes. | Recipient phone numbers and the content of the message sent, plus delivery metadata returned by the carrier. | United States / global | Active where SMS is enabled. SMS alerting is included in limited monthly allowances on paid plans and is not available on the Free plan. |
| S3-compatible object storage (operator-configured) | Storage of browser-check artifacts (screenshots, HAR network captures, and console logs). | Browser-check artifacts, which may contain whatever appears on the monitored page or network. | Operator-configured | Optional — the default deployment stores these artifacts on the operator’s own filesystem, not third-party object storage. A specific storage vendor is named here if one is enabled. |
Customer-directed recipients (not sub-processors)
Chat and paging destinations — Slack, Microsoft Teams, Discord, PagerDuty, and generic webhooks — receive alert and incident content only when a customer configures them, at the customer’s direction.
Because the customer selects and controls these destinations, they are customer-directed recipients rather than sub-processors PageLantern engages on its own behalf. The customer is responsible for the security and lawful use of every destination it configures.
Not yet engaged
- Hosting and managed-database providers — The hosting and managed-database providers for a paid public launch are being finalized and will be named here before launch.
Notice of changes and how to object
Named list. This page is the current named list of the sub-processors we engage. We keep it consistent with the Sub-Processors section of our Privacy Notice, which describes the categories of sub-processors and customer-directed recipients we use.
Advance notice of changes. When we plan to add or replace a sub-processor that processes personal data, we will update this page and give account owners at least 30 days’ advance notice by email before the new sub-processor begins processing personal data. Where a change is required on shorter notice for security or legal reasons, or to replace a provider quickly, we will provide notice as soon as reasonably practicable.
How to object. To object to a new sub-processor, or to ask a question about this list, email privacy@pagelantern.com. The contractual right to advance notice and to object is set out in Section 6 of our Data Processing Terms at pagelantern.com/dpa, which apply automatically to every customer. If we cannot reasonably accommodate an objection, we will work with you on alternatives, and your remedy is to terminate the affected part of the service as those terms describe.
- Object to a new sub-processor or ask a question
- privacy@pagelantern.com
- Related notice
- Privacy Notice — Sub-Processors
Change Log
- August 31, 2026: Extended the Google entry to cover consent-gated Google Ads purchase conversion attribution. The conversion fires only after Stripe confirms a completed, paid Checkout session, uses the session identifier for duplicate prevention, and does not enable ad personalization or enhanced-conversion identity matching.
- August 27, 2026: Added OpenAI as the consent-gated measurement provider for ChatGPT Ads. The pixel receives limited ad-attribution data and a registration_completed event only after the visitor accepts measurement cookies and PageLantern confirms the registration.
- August 4, 2026: Extended the Google entry to cover Google Analytics 4, which now measures usage of the PageLantern website and application. The tag loads with consent defaults denied, so it stores no analytics identifier on a visitor’s device until they accept in the cookie banner, and Google advertising features are not enabled. Privacy Notice section 16 was updated to describe this technology and the way to withdraw consent.
- August 3, 2026: Added Stripe (payment processing and subscription management) and Twilio (SMS alert and multi-factor delivery) as active sub-processors. Both had shipped in the product while this page still listed payment and SMS providers as "not yet engaged," which understated the processing actually taking place. Added the cross-reference to the new Data Processing Terms, which give the contractual sub-processor notice and objection rights this page describes.
- July 15, 2026: Initial publication of the named sub-processor list and the objection and change-notification process referenced in Privacy Notice section 13. Listed the confirmed and optional sub-processors (Mailgun email delivery; Google, Microsoft, Apple, and Meta social sign-in; a Google-hosted support/feedback mailbox; optional S3-compatible artifact storage), separated customer-directed alert recipients, and marked payment, SMS, hosting, and database providers as not yet engaged.
Important Note
This page describes the sub-processors the PageLantern service currently uses and is written to be accurate to the running product. Exact operating legal-entity names and processing regions for some providers, and the hosting and managed-database providers noted as not yet engaged, are still being finalized and will be named here before they process personal data. This page is informational and does not itself grant rights beyond those in the Privacy Notice, the applicable customer agreement, and any executed data processing agreement.
