CareBridger logoCareBridger

Subprocessors

Last reviewed: 2026-07-10 · Version: 2026-07-10

These are the third parties that process personal data on behalf of CareBridger. We give 30 days’ notice before adding a new subprocessor by updating this page; account owners may object in writing to privacy@carebridger.com.

VendorPurposeRegionReference
Cloudflare (D1, KV, R2, Workers, Durable Objects)Compute, primary database, blob storage, session/state KVGlobal edge (data-locality-aware)ADR-0001 through ADR-0008
Postmark / Resend / MailChannelsTransactional email (verify, reset, invitations, security)United StatesADR-0025
TwilioOptional transactional SMS notificationsUnited States / globalADR-0021
Expo (Push Service)Native iOS and Android push notification relayUnited States / globalADR-0021 and ADR-0066
Google (OAuth and Calendar API)Calendar sync for accounts that connect Google Calendar (read-only event sync); only for users who opt inUnited States / globalADR-0033–ADR-0040
Microsoft (Outlook/Graph Calendar API)Calendar sync for accounts that connect an Outlook/Microsoft 365 calendar; only for users who opt inUnited States / globalADR-0033–ADR-0040
SentryServer- and client-side error reportingEuropean Union (sentry.io EU instance)ADR-0010
StripeSubscription billing and payment processing (Hosted Checkout + Customer Portal). Card data is collected directly by Stripe and never reaches CareBridger.United States / globalADR-0045

Any vendor referenced via a binding in backend/src/env.ts must appear in this list. CI fails any PR that adds a new vendor without updating this page.