Legal

Subprocessors & Transfers

Last updated: 4 September 2026

We name service providers here so Operators can understand who may process data and why. This transparency does not reveal credentials, internal addresses or security configuration. Availability and use depend on enabled features. Memberra uses UK adequacy regulations, the UK Addendum, the International Data Transfer Agreement or another lawful safeguard where required. Operators may email [email protected] with a reasoned objection to a material new subprocessor.

Cloudflare

Hosting, CDN, DNS, security and network delivery

Processing location: Configuration-dependent global infrastructure

Supabase

Database, authentication, storage and platform services

Processing location: Configured project region and approved support locations

Stripe

Payments, billing, fraud prevention and connected accounts

Processing location: UK/EEA, US and other disclosed locations

PayPal

Payments, merchant onboarding and fraud prevention

Processing location: Global locations described by PayPal

Resend / configured mail providers

Transactional and service communications

Processing location: Provider-dependent, including UK/EEA and US

Discord

Optional account and community integration

Processing location: Global locations described by Discord

NOWPayments / BTCPay deployment

Optional cryptocurrency invoicing

Processing location: Selected provider or deployment location

TMDB / configured IP geolocation provider

Optional artwork, metadata and approximate location enrichment

Processing location: Provider-dependent