Skip to main content

Subprocessors

This page lists the named third-party service providers currently used by Afterlane in the product or when you enable related features.

Vercel

Hosts the Afterlane web application and API routes.

Data involved: HTTP request metadata, application logs, and deployment configuration needed to serve the product.

Fly.io

Runs the browser-check worker that loads monitored routes and captures results.

Data involved: Queued run jobs, route URLs, browser check output, and worker logs.

Neon

Managed PostgreSQL database for accounts, projects, runs, and billing state.

Data involved: Account records, project configuration, run history, route results, subscriptions, and related application metadata.

Cloudflare R2

Object storage for screenshots captured during route checks.

Data involved: Stored screenshots and related object metadata.

Upstash Redis

Rate limiting and abuse prevention.

Data involved: Request identifiers and rate-limit counters.

Upstash QStash

Signed job delivery from the web app to the browser-check worker.

Data involved: Queued event identifiers and delivery metadata for deploy-check processing.

GitHub OAuth

Account sign-in.

Data involved: Authentication requests and the profile information GitHub returns during sign-in.

GitHub App

Optional one-click CI setup for connecting a repository to an Afterlane project.

Data involved: Installation ID, GitHub account login, repository names, workflow file contents, and encrypted repository secrets configured during setup.

Stripe

Subscription billing for paid plans.

Data involved: Customer ID, subscription status, price identifiers, and billing period metadata.

PostHog

Optional product analytics, error telemetry, and session replay after opt-in.

Data involved: Pseudonymous usage events, device/browser metadata, pages viewed, replay metadata, and error data.

Google sign-in

Coming soon.

Data involved: Google sign-in is currently disabled and does not process authentication traffic.

Discord

Optional customer-configured alert delivery.

Data involved: Alert payloads and webhook URLs configured by the customer.

Vendor review, security questions, and subprocessor notices can be requested at [email protected].