Skip to main content

Subprocessors

Version 1.1 · Effective July 26, 2026

A subprocessor is a company we use to run JamCrew that touches your workspace data along the way. Hosting, the database, email, SMS, payments, and so on. This page is the whole list. It is the list referred to by the Data Processing Addendum, and it is what you approve when you agree to the Terms.

We publish it because enterprise buyers ask for it and because you deserve to know who else is in the room. If a vendor is not on this page, it does not get your data.

Core platform

These run for every workspace. Some only see data when you use the feature they power, which the purpose column says.

SubprocessorWhat it does for youPrimary location
ClerkAuthentication, sessions, and sign-in with Google, Apple, or Microsoft.United States
ConvexThe application database and backend. Nearly all workspace data lives here.United States
VercelHosting and content delivery for the site and the app, plus Vercel Analytics and Speed Insights, which set no cookies.United States
StripeSubscription billing for workspaces, and crew payouts through Stripe Connect. Receives payment and payout details.United States
ResendTransactional and marketing email delivery.United States
TwilioSMS delivery. Receives phone numbers and the content of the messages we send on your behalf.United States
SentryError monitoring. Receives sanitized diagnostic payloads, and records a session replay when an error occurs.United States
GoogleGoogle Analytics 4 for measurement, in service-provider mode with advertising signals switched off in every region. Google is also one of the sign-in providers.United States
PostHogProduct analytics, session replay, and feature flags. Runs on the PostHog US cloud region.United States
DuffelFlight search and booking, when your workspace books travel through JamCrew. Receives passenger date of birth, gender, and passport number, along with the rest of the passenger record.United Kingdom
AviationStackFlight status lookups for booked travel. Receives flight numbers and dates rather than passenger identity documents.Not confirmed
Browser push servicesDelivery of web push notifications through Apple, Google, or Mozilla, depending on the browser the person uses. Receives the push subscription endpoint and the encrypted payload, sent using VAPID.United States

Optional integrations

These receive nothing until one of your workspace admins connects them. Connecting one is your instruction to send data to it. Disconnecting it stops the flow going forward, though whatever was already sent lives under that vendor's terms with you.

SubprocessorWhat it does for youPrimary location
SlackWorkspace notifications in your Slack channels. Receives only the notification content you configure.United States
QuickBooksAccounting sync. Receives the financial records you choose to sync, which can include crew names and pay amounts.United States
XeroAccounting sync. Receives the financial records you choose to sync, which can include crew names and pay amounts.New Zealand

The one to read twice: travel documents

If your workspace books flights through JamCrew, the passenger record we send to Duffel includes date of birth, gender, and passport number, along with passport expiry, issuing country, and known traveler number where the crew member has provided them. Airlines require it to issue a ticket. It is the most sensitive data we hand to any vendor, so it gets its own heading instead of a row in a table nobody reads to the bottom.

About the location column

Location is the vendor's principal place of business, and where we know the processing region we have said so. It is not a promise about every data center a vendor operates. Where it says Not confirmed, we have not verified the answer to a standard we are willing to publish. Ask us and we will get it for you in writing rather than guess on a public page.

JamCrew is operated from the United States, and data is transferred to the United States. The mechanism that covers transfers out of the EEA, the UK, and Switzerland, including the Standard Contractual Clauses, is in the Data Processing Addendum.

When this list changes

  • We update this page and notify subscribers at least 30 days before a new subprocessor starts processing customer data.
  • You have 30 days from that notice to object in writing on reasonable data protection grounds. The objection process, and what happens if we cannot resolve it, is section 10 of the Data Processing Addendum.
  • If we ever have to swap a vendor urgently to keep the service up or to close a security problem, we make the change and tell you as soon as we reasonably can, with the reason. Your objection right still applies afterward.
  • Removing a subprocessor is not a change you need warning about, so we simply take it off the list.

Get notified

Email legal@jamcrew.io with the subject line Subprocessor updates and the address you want notices sent to. Any address works: a person, a security alias, a ticketing inbox. We add it to the notice list and use it for nothing else. Reply to any notice to come off the list.

Questions about a specific vendor, or a request for the documentation behind one, go to the same address. See also the Privacy Policy for what we collect and why, and Your Privacy Choices for opting out.

Version 1.1 · Last updated: July 26, 2026