← Home

Subprocessors

Last updated: 2026-06-03

MeterBox is a data processor under your Data Processing Agreement (DPA). The third parties below are the subprocessors we engage to deliver the service — what they touch depends on the integrations you enable. Material changes are notified at least 30 days in advance per Art. 28(2) GDPR.

Self-Managed tenants: Self-Managed tenants (running MeterBox on their own cluster) have NO subprocessors beyond what they configure themselves — MeterBox has no hosted services in the data path. The list above only applies to Cloud + Managed tiers where MeterBox SRE operates the cluster.

Billing + payments

Stripe, Inc.

Purpose
Payment processing, hosted checkout, subscription billing
Data processed
Customer email, name, payment method, invoice amounts, plan id
Jurisdiction
United States (SCCs in place)
Enabled when
Tenant configures Stripe as billing provider (default)

Zuora, Inc.

Purpose
Billing engine alternative to Stripe
Data processed
Same as Stripe — customer + invoice metadata
Jurisdiction
United States (SCCs in place)
Enabled when
Tenant configures Zuora as billing provider

Identity + authentication

Auth0, Inc.

Purpose
Optional OIDC SSO + token-claims splicing
Data processed
User email, entitlement state for token claims
Jurisdiction
United States (SCCs in place)
Enabled when
Tenant configures Auth0 SSO or token-claims endpoint

Transactional email

Resend, Inc.

Purpose
Signup verification, password reset, low-balance alerts, MFA, invites
Data processed
Recipient email, subject, body (no end-customer PII beyond what the tenant sends)
Jurisdiction
United States (SCCs in place)
Enabled when
Tenant sets RESEND_API_KEY

Cloud infrastructure (Managed-tier deployments only)

Amazon Web Services, Inc.

Purpose
Compute + storage + KMS (when tenant is on AWS GovCloud or US AWS)
Data processed
All tenant + end-customer data at rest, encrypted
Jurisdiction
Tenant-pinned region (e.g., us-east-1, eu-west-1, us-gov-west-1)
Enabled when
Managed tier deployed on AWS

Google LLC (Google Cloud)

Purpose
Compute + storage + KMS (when tenant is on GCP Assured Workloads)
Data processed
All tenant + end-customer data at rest, encrypted
Jurisdiction
Tenant-pinned region
Enabled when
Managed tier deployed on GCP

Microsoft Corporation (Azure)

Purpose
Compute + storage + Key Vault (when tenant is on Azure Government)
Data processed
All tenant + end-customer data at rest, encrypted
Jurisdiction
Tenant-pinned region
Enabled when
Managed tier deployed on Azure

Questions about a specific subprocessor or DPA? contact@meterbox.ai.