← Home
Subprocessors
Last updated: 2026-06-03
MeterBox is a data processor under your Data Processing Agreement (DPA). The third parties below are the subprocessors we engage to deliver the service — what they touch depends on the integrations you enable. Material changes are notified at least 30 days in advance per Art. 28(2) GDPR.
Self-Managed tenants: Self-Managed tenants (running MeterBox on their own cluster) have NO subprocessors beyond what they configure themselves — MeterBox has no hosted services in the data path. The list above only applies to Cloud + Managed tiers where MeterBox SRE operates the cluster.
Billing + payments
- Purpose
- Payment processing, hosted checkout, subscription billing
- Data processed
- Customer email, name, payment method, invoice amounts, plan id
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Stripe as billing provider (default)
- Purpose
- Billing engine alternative to Stripe
- Data processed
- Same as Stripe — customer + invoice metadata
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Zuora as billing provider
Identity + authentication
- Purpose
- Optional OIDC SSO + token-claims splicing
- Data processed
- User email, entitlement state for token claims
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant configures Auth0 SSO or token-claims endpoint
Transactional email
- Purpose
- Signup verification, password reset, low-balance alerts, MFA, invites
- Data processed
- Recipient email, subject, body (no end-customer PII beyond what the tenant sends)
- Jurisdiction
- United States (SCCs in place)
- Enabled when
- Tenant sets RESEND_API_KEY
Cloud infrastructure (Managed-tier deployments only)
- Purpose
- Compute + storage + KMS (when tenant is on AWS GovCloud or US AWS)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region (e.g., us-east-1, eu-west-1, us-gov-west-1)
- Enabled when
- Managed tier deployed on AWS
- Purpose
- Compute + storage + KMS (when tenant is on GCP Assured Workloads)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region
- Enabled when
- Managed tier deployed on GCP
- Purpose
- Compute + storage + Key Vault (when tenant is on Azure Government)
- Data processed
- All tenant + end-customer data at rest, encrypted
- Jurisdiction
- Tenant-pinned region
- Enabled when
- Managed tier deployed on Azure
Questions about a specific subprocessor or DPA? contact@meterbox.ai.