Last updated: August 13, 2026
MCPFeedback uses the third-party providers below to deliver the service. Each one is bound by a data processing agreement no less protective than our own DPA, and we remain responsible to our customers for their performance.
We update this page at least 30 days before a new subprocessor begins processing customer data. To receive those notices by email, write to support@mcpfeedback.com and ask to be added to the subprocessor notification list.
| Subprocessor | Purpose | Data processed | Processing location | Privacy terms |
|---|---|---|---|---|
| Supabase | PostgreSQL database, authentication, and file storage | All account data, feedback, screenshots, recordings, session replays, and crash reports | United States or European Union (per-project region) | supabase.com/privacy |
| Vercel | Application hosting, edge delivery, and request logging | Data in transit to and from the dashboard, API and widget endpoints; request metadata and logs | United States (global edge network) | vercel.com/legal/privacy-policy |
| Stripe | Subscription billing and payment processing | Customer billing contact, billing address, tax identifiers, and card data (collected and stored by Stripe, never by us) | United States and European Union | stripe.com/privacy |
| Resend | Transactional email delivery | Recipient email addresses and the contents of transactional emails (verifications, invitations, notifications, digests, billing notices) | United States | resend.com/legal/privacy-policy |
| Google Analytics | Usage analytics on the marketing site and dashboard — optional, loaded only after cookie consent is granted | Pseudonymous usage events, device and browser metadata, truncated IP address | United States | policies.google.com/privacy |
Several subprocessors process data in the United States. Transfers of personal data from the EEA, the United Kingdom or Switzerland are covered by the European Commission’s Standard Contractual Clauses (with the UK Addendum and the Swiss adaptations where applicable), as incorporated into our Data Processing Addendum.
Destinations you connect — outbound webhook endpoints, GitHub for issue forwarding, and the MCP clients you authorise — receive feedback data because you instructed us to send it there. Those are your own processors, not ours, and are not listed above.
Questions about this list? Contact us at support@mcpfeedback.com