Archived version
Subprocessors
Version 1.1 · Effective 2026-07-26 · jamcrew-subprocessors-v1.1
SHA-256 30c5e05b3b5f00163edce60bf8b1dadd85082106f0f4891fd7738c9f4ad93819
This page is a permanent record. Its words are frozen at the hash above and will never change. Later revisions are published as new versions at their own addresses.
For the version in force today, read Subprocessors.
Subprocessors
Version 1.1 · Effective July 26, 2026
A subprocessor is a company we use to run JamCrew that touches your workspace data along the way. Hosting, the database, email, SMS, payments, and so on. This page is the whole list. It is the list referred to by the Data Processing Addendum (/dpa), and it is what you approve when you agree to the Terms.
We publish it because enterprise buyers ask for it and because you deserve to know who else is in the room. If a vendor is not on this page, it does not get your data.
Core platform
These run for every workspace. Some only see data when you use the feature they power, which the purpose column says.
Optional integrations
These receive nothing until one of your workspace admins connects them. Connecting one is your instruction to send data to it. Disconnecting it stops the flow going forward, though whatever was already sent lives under that vendor's terms with you.
The one to read twice: travel documents
If your workspace books flights through JamCrew, the passenger record we send to Duffel includes date of birth, gender, and passport number, along with passport expiry, issuing country, and known traveler number where the crew member has provided them. Airlines require it to issue a ticket. It is the most sensitive data we hand to any vendor, so it gets its own heading instead of a row in a table nobody reads to the bottom.
About the location column
Location is the vendor's principal place of business, and where we know the processing region we have said so. It is not a promise about every data center a vendor operates. Where it says Not confirmed, we have not verified the answer to a standard we are willing to publish. Ask us and we will get it for you in writing rather than guess on a public page.
JamCrew is operated from the United States, and data is transferred to the United States. The mechanism that covers transfers out of the EEA, the UK, and Switzerland, including the Standard Contractual Clauses, is in the Data Processing Addendum (/dpa).
When this list changes
- We update this page and notify subscribers at least 30 days before a new subprocessor starts processing customer data.
- You have 30 days from that notice to object in writing on reasonable data protection grounds. The objection process, and what happens if we cannot resolve it, is section 10 of the Data Processing Addendum (/dpa).
- If we ever have to swap a vendor urgently to keep the service up or to close a security problem, we make the change and tell you as soon as we reasonably can, with the reason. Your objection right still applies afterward.
- Removing a subprocessor is not a change you need warning about, so we simply take it off the list.
Get notified
Email legal@jamcrew.io (mailto:legal@jamcrew.io?subject=Subprocessor%20updates) with the subject line Subprocessor updates and the address you want notices sent to. Any address works: a person, a security alias, a ticketing inbox. We add it to the notice list and use it for nothing else. Reply to any notice to come off the list.
Questions about a specific vendor, or a request for the documentation behind one, go to the same address. See also the Privacy Policy (/privacy) for what we collect and why, and Your Privacy Choices (/privacy#your-choices) for opting out.
Version 1.1 · Last updated: July 26, 2026
Clerk Authentication, sessions, and sign-in with Google, Apple, or Microsoft. United States
Convex The application database and backend. Nearly all workspace data lives here. United States
Vercel Hosting and content delivery for the site and the app, plus Vercel Analytics and Speed Insights, which set no cookies. United States
Stripe Subscription billing for workspaces, and crew payouts through Stripe Connect. Receives payment and payout details. United States
Resend Transactional and marketing email delivery. United States
Twilio SMS delivery. Receives phone numbers and the content of the messages we send on your behalf. United States
Sentry Error monitoring. Receives sanitized diagnostic payloads, and records a session replay when an error occurs. United States
Google Google Analytics 4 for measurement, in service-provider mode with advertising signals switched off in every region. Google is also one of the sign-in providers. United States
PostHog Product analytics, session replay, and feature flags. Runs on the PostHog US cloud region. United States
Duffel Flight search and booking, when your workspace books travel through JamCrew. Receives passenger date of birth, gender, and passport number, along with the rest of the passenger record. United Kingdom
AviationStack Flight status lookups for booked travel. Receives flight numbers and dates rather than passenger identity documents. Not confirmed
Browser push services Delivery of web push notifications through Apple, Google, or Mozilla, depending on the browser the person uses. Receives the push subscription endpoint and the encrypted payload, sent using VAPID. United States
Slack Workspace notifications in your Slack channels. Receives only the notification content you configure. United States
QuickBooks Accounting sync. Receives the financial records you choose to sync, which can include crew names and pay amounts. United States
Xero Accounting sync. Receives the financial records you choose to sync, which can include crew names and pay amounts. New Zealand
name Subprocessor
purpose What it does for you
location Primary location