Effective date: Not yet in effect
nith Studio LLC uses the providers identified below to operate the applicable nith services. A provider receives information when the relevant service is enabled or used. Our role and the recipient's role depend on the processing: a provider can act as our processor for some activities and an independent controller for others. A customer's own integrations are distinguished from providers we engage to process customer information for us.
For questions, contact To be confirmed: privacy contact. Customers subject to our Data Processing Addendum receive notices of relevant subprocessor changes through To be confirmed: subprocessor notice method, with the authorization and objection process set out in their agreement.
Core and feature providers
| Provider or service | Processing purpose and information | Role and service scope | Location and contract details |
|---|---|---|---|
| Vercel | Application hosting, request handling, delivery and operational logs; relevant request/content data, IP and technical metadata; custom-domain configuration. | To be confirmed: vercel role and service scope. | To be confirmed: vercel contracting entity, To be confirmed: vercel locations, To be confirmed: vercel dpa and transfer details. |
| Railway | PostgreSQL hosting for platform records and separately configured first-party services such as Bug Center. | To be confirmed: railway role and service scope. | To be confirmed: railway contracting entity, To be confirmed: railway locations, To be confirmed: railway dpa and transfer details. |
| UploadThing and Tigris storage chain | S3-compatible object storage for uploaded media, documents, and related files. Bug evidence uses a separately configured private bucket. | To be confirmed: storage role and service scope. | To be confirmed: storage contracting entities, To be confirmed: storage locations, To be confirmed: storage dpa and transfer details. |
| Email delivery service configured through useSend | Account, support or operational messages, invitations, lead and transaction alerts, contract messages, and optional newsletters; recipient addresses, message content, sender identity, and delivery records. | To be confirmed: email role and service scope. | To be confirmed: email delivery entities, To be confirmed: email locations, To be confirmed: email dpa and transfer details. |
| OpenAI | Jot and other text/image assistance, selected context and attachments, generation, and certain screening/fallback requests. | To be confirmed: openai role and service scope. | To be confirmed: openai contracting entity, To be confirmed: openai locations, To be confirmed: openai dpa and transfer details, To be confirmed: openai retention and training settings. |
| Vercel AI Gateway and TypeSafe AI Jev | Configured classification and evaluation requests, including form free text, intent, proposed changes/designs, setup suggestions, and selected imagery descriptions. | To be confirmed: jev gateway role and service scope. | To be confirmed: jev gateway contracting entities, To be confirmed: jev locations, To be confirmed: jev dpa and transfer details, To be confirmed: jev retention and training settings. |
| Cloudflare Turnstile | Anti-abuse challenges, browser/request signals, token verification and visitor IP where provided. | To be confirmed: cloudflare role and service scope. | To be confirmed: cloudflare entity and role, To be confirmed: cloudflare locations, To be confirmed: cloudflare terms and transfer details. |
| Twilio Verify | Optional phone verification: phone number, verification request and status, and delivery-related information. | To be confirmed: twilio role and service scope. | To be confirmed: twilio entity and role, To be confirmed: twilio locations, To be confirmed: twilio terms and transfer details. |
| Stripe | nith subscriptions and billing, customer sellers' Connect onboarding, checkout and payment processing, and supported agency invoicing. Payment, identity, buyer/client, and transaction information varies by flow. | Activity-dependent independent controller and/or processor. Customer sellers may contract directly with Stripe. | To be confirmed: stripe contracting entity and roles, To be confirmed: stripe locations, To be confirmed: stripe terms and transfer details. |
| Hosting and database providers for self-hosted Umami | Page analytics: visited pages, referrer/campaign and device information, approximate geographic information and the technical data handled by the deployment. | To be confirmed: umami role and service scope. | To be confirmed: umami hosting entities, To be confirmed: umami locations, To be confirmed: umami retention and terms. |
| Hosting and storage providers for NodeBB and Bug Center components | Optional forum profiles and contributions; bug-report data and evidence; first-party session and moderation records. | To be confirmed: community and bugs role and service scope. | To be confirmed: community and bugs hosting entities, To be confirmed: community and bugs locations, To be confirmed: community and bugs terms. |
Other recipients and customer-selected services
| Recipient or service | When information is involved | Additional information |
|---|---|---|
| Google Maps and Places | Maps/address search can send browser requests and searched addresses to Google; server-side reviews retrieval requests business data, and externally hosted reviewer images can make browser requests. | To be confirmed: google maps role and terms. |
| Google Analytics and Tag Manager; Meta Pixel | A customer enables or configures the applicable script. Browser and interaction information can be sent directly to those services and to tags selected by the customer. | The customer's notice describes its configuration, recipients, and controls. Supporting an integration does not itself designate it as a nith Subprocessor. |
| YouTube, Vimeo, X, external image hosts, outside forms and other embeds | A page loads third-party resources or a visitor activates an embedded service. Some thumbnails load before playback. | Customer/provider notices and controls. Privacy-enhanced or do-not-track player settings do not establish no processing. |
| Customer webhook destinations and notification addresses | An authorized customer forwards lead or other supported data to a destination it selected. | Customer-selected recipient, purpose and authorization; nith's own transmission duties still apply. |
| Customer custom scripts and chat tools | A site owner installs or configures code; opening an embedded customer example can load that site's configured services. | The customer's notice describes its chosen recipients and processing. |
| Google APIs and public resolvers used in optional website audits | Website origin or URLs for speed/security checks, domain queries, and technical observations where the relevant feature and API credentials are enabled. OSV queries can include detected software names and versions. | To be confirmed: audit recipient roles and terms. |