Subprocessors
Last updated: 2026-06-03
Meterbox is a data processor under your Data Processing Agreement (DPA). The third parties below are the subprocessors we engage to deliver the service. What they touch depends on the integrations you enable. Material changes are notified at least 30 days in advance per Art. 28(2) GDPR.
Self-Managed tenants: Self-Managed tenants (running Meterbox on their own cluster) have NO subprocessors beyond what they configure themselves. Meterbox has no hosted services in the data path. The list above only applies to Cloud + Managed tiers where Meterbox SRE operates the cluster.
Billing + payments
Stripe, Inc.
- Purpose
- Payment processing, hosted checkout, subscription billing
- Data processed
- Customer email, name, payment method, invoice amounts, plan id
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Stripe as billing provider (default)
Zuora, Inc.
- Purpose
- Billing engine alternative to Stripe
- Data processed
- Same as Stripe: customer + invoice metadata
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Zuora as billing provider
Identity + authentication
Auth0, Inc.
- Purpose
- Optional OIDC SSO + token-claims splicing
- Data processed
- User email, entitlement state for token claims
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Auth0 SSO or token-claims endpoint
Transactional email
Resend, Inc.
- Purpose
- Signup verification, password reset, low-balance alerts, MFA, invites
- Data processed
- Recipient email, subject, body (no end-customer PII beyond what the tenant sends)
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant sets RESEND_API_KEY
Cloud infrastructure (Managed-tier deployments only)
Amazon Web Services, Inc.
- Purpose
- Compute + storage + KMS (when tenant is on AWS GovCloud or US AWS)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region (e.g., us-east-1, eu-west-1, us-gov-west-1)
- Enabled when
- Managed tier deployed on AWS
Google LLC (Google Cloud)
- Purpose
- Compute + storage + KMS (when tenant is on GCP Assured Workloads)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region
- Enabled when
- Managed tier deployed on GCP
Microsoft Corporation (Azure)
- Purpose
- Compute + storage + Key Vault (when tenant is on Azure Government)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region
- Enabled when
- Managed tier deployed on Azure
Questions about a specific subprocessor or DPA? contact@meterbox.ai.