Sub-processors
Effective date: 2026-06-24
To run CommandLatch, a small number of trusted third-party providers (“sub-processors”) process personal data on our behalf. We keep this list short and the data we hand to each provider minimised. This page names every sub-processor we currently use, what each one does, the categories of data it handles, where the processing takes place, and the safeguard that protects any transfer. Read it alongside the Privacy Policy.
CommandLatch is operated by Adrian Filipow (individual sole operator),
Tannenwaldweg 100B, 61350 Bad Homburg, Germany. Questions:
privacy@commandlatch.app.
Current sub-processors
Section titled “Current sub-processors”| Sub-processor | Purpose | Data categories | Processing location | Safeguard |
|---|---|---|---|---|
| Supabase | Primary backend — Postgres database with Row-Level Security, passwordless Auth, Deno Edge Functions (the command channel + billing/support functions), and a public download Storage bucket | All account/app data: email, Supabase user id, device metadata + display_name, hashed device tokens, pairing codes, command history, user-typed notification/alert title+body, hashed shortcut/webhook tokens, APNs push tokens, subscription state, support tickets | European Union | EU data residency (processing kept in the EU); Data Processing Agreement / SCCs as applicable |
| PostHog | Product and website analytics | Anonymous usage events (site/docs/desktop) and identified usage events (web/iOS/server: account id, email as a person property, command action+source, pairing, billing lifecycle, support); app/OS/CPU version. No command/notification content, no IP-derived location ($geoip_disable) | European Union (EU cloud) | EU data residency; GeoIP disabled, GPC/DNT honored, no session replay; DPA/SCCs as applicable |
| Stripe | Payment processing for the CommandLatch Pro subscription (web + macOS) | Account email, payment method/card details, subscription status, invoices, Stripe customer/subscription ids | United States | EU Standard Contractual Clauses (SCCs); PCI-DSS Level 1 |
| Resend | Transactional email — delivers passwordless sign-in codes (via Supabase custom SMTP) and support-ticket notifications | Recipient email address and the contents of the sign-in code / support notification email | United States | EU Standard Contractual Clauses (SCCs) |
| Apple | Push notification delivery (APNs for the alert action) and App Store distribution / in-app purchase billing for the iOS app (IAP planned) | APNs push token + the alert title/body delivered to the iPhone; for IAP, App Store account and purchase/subscription transaction data (handled by Apple) | United States (global infrastructure) | Apple’s developer/platform terms and data protection addendum; EU SCCs as applicable |
| Vercel | Hosting for the three web front-ends (marketing site commandlatch.app, dashboard app.commandlatch.app, docs commandlatch.dev) | Standard web request/edge logs (IP, user agent, requested URL); no application database data | United States | EU Standard Contractual Clauses (SCCs) |
| GitHub Actions | CI/CD — builds, signs, notarizes, and deploys the apps and backend on a version tag | Source code and build artifacts only — no end-user personal data is processed | United States | EU Standard Contractual Clauses (SCCs); no end-user data in scope |
Changes to this list
Section titled “Changes to this list”This list may be updated as we add, replace, or remove sub-processors. The version published here at any time is the current list. If we make a material change — adding a new sub-processor or materially changing what an existing one does — we will update this page and communicate the change through the product or by email where appropriate, so you have the opportunity to review it.
Contact
Section titled “Contact”Questions about our sub-processors or data processing:
- Email
privacy@commandlatch.app
See also
Section titled “See also”- Privacy Policy — what data we store, the legal bases, your rights, and retention.
- Security & trust model — what can and can’t run, how tokens work.