← Legal Legal

Sub-processors

This page identifies the third parties ("sub-processors") that PushRPM Global Pvt Ltd ("PubSentry," "we," "us") engages to help deliver the PubSentry service, and the categories of data each one touches. It supplements our Privacy Policy and Data Processing Addendum; where this list conflicts with the sub-processor section of the DPA, the most recently published version controls.

Effective date: June 27, 2026 Controller / processor: PushRPM Global Pvt Ltd, Delhi, India — questions to support@pubsentry.io. Governing law: This page is governed by the laws of India, subject to the mandatory provisions of applicable data-protection law.

What a sub-processor is

A sub-processor is a third party we authorise to process personal data on our behalf in the course of providing the Service — for example, the infrastructure that runs our datastores, or the vendor that sends a billing email. Engaging sub-processors is normal for a SaaS product, but it is something we keep deliberately small and disclose openly.

Two design choices keep this list short and low-risk:

  • Data minimization at ingest. When the PubSentry tag scores a page view, the raw IP address and User-Agent are hashed server-side with HMAC-SHA256 and then dropped — never written to storage. What persists is a one-way keyed hash, derived network/geo attributes from an offline iptoasn dataset (no residential-proxy, VPN, or Tor lookup that would call a third party), and event metadata. There is no third-party IP-intelligence, ad-network, or data-broker call on the scoring path, so the visitor-signal flow has no sub-processor of its own.
  • First-party, same-origin product. The dashboard and APIs are served from our own infrastructure; authentication uses a first-party session cookie. The few sub-processors below sit at the edges — infrastructure, payments, and email — not in the detection loop.

Our current sub-processors

We engage the following sub-processors. Each is bound by data-protection terms no less protective than those we owe you, and PubSentry remains responsible for their performance.

Sub-processorRolePurposeData it touchesProcessing location
Hostinger International LtdCloud hosting + outbound emailRuns the application servers, ClickHouse (events), and Redis (reputation, accounts, configuration) the Service is built on, and sends transactional and account email (sign-up/verification, billing notices, alert/notification messages) via SMTPScored event metadata, hashed identifiers (HMAC-SHA256, raw IP/UA already dropped), reputation/velocity counters, account records (email, scrypt password hash, plan, billing state), TTL-bounded config — all at rest on infrastructure we operate; plus the recipient email address and message content of outbound mailEuropean Union
DodoPaymentsPayment processing & billingMerchant-of-record and payment processing for account subscriptions (checkout, customer portal, billing webhooks)Billing contact details and card / payment data — handled directly by DodoPayments under its own terms; PubSentry receives only billing status and customer/subscription reference IDs, not card numbersPer DodoPayments' terms
AnthropicAI narration of de-identified detection findingsGenerates plain-language narration of detection findings for the dashboard; only de-identified, aggregated detection findings are sent — no raw visitor PIIDe-identified, aggregated detection findings only (no raw visitor PII)Per Anthropic's terms
proxycheck.ioOptional IP-reputation lookupsOptional residential-proxy / VPN / Tor reputation lookups, only when enabled by an account; IP address only, and only for non-datacenter public IPsIP address only (only when the optional lookup is enabled)Per proxycheck.io's terms
Note on the hosting provider. PubSentry self-hosts the application stack on infrastructure rented from Hostinger International Ltd. Because all persisted data lives there, this is the broadest sub-processor on the list and the one most relevant to a security review. Backend services are bound to localhost behind a reverse proxy and are not directly reachable from the public internet; data in transit is served over TLS. Hostinger International Ltd provides our cloud hosting and outbound email (European Union); data is encrypted in transit and at rest.

What is not on this list

To set expectations honestly:

  • No third-party tracking, advertising, or remarketing vendors touch visitor-signal data. The detection tag sets no cross-site advertising cookies and builds no cross-site profile.
  • No third-party IP-intelligence or data-broker service is called when scoring traffic; network/geo enrichment uses an offline dataset we ship.
  • Google Analytics 4 runs on the public marketing site only (pubsentry.com) for aggregate, non-identifying measurement — never inside the authenticated dashboard or the detection path. It is described in our Cookie Policy rather than treated as a processor of customer or visitor data. We do not use Google Analytics within the PubSentry application.

Engaging new sub-processors and notifying you

We may add or replace a sub-processor as the product grows — for example, if we adopt a new email provider or add a second infrastructure region.

When we do, we commit to:

  1. Hold the new sub-processor to equivalent obligations. Any replacement or addition must be bound by data-protection terms at least as protective as those in our DPA, and PubSentry remains responsible for its acts and omissions.
  2. Give you advance notice of changes affecting visitor-signal or customer personal data. We will provide reasonable prior notice before a new or replacement sub-processor starts processing such data. We will provide at least thirty (30) days' notice of any new sub-processor by updating this page and emailing account owners.
  3. Let you object on legitimate grounds. If you have a reasonable, data-protection-based objection to a new sub-processor, tell us at support@pubsentry.io. We will work with you in good faith; if we cannot reasonably accommodate the objection, your remedy is to terminate the affected Service as described in the DPA and Terms.

This page is the canonical, up-to-date list. Changes will be reflected here with a revised effective date, and material changes affecting personal data will additionally be communicated through the notice channel above.

How to subscribe to changes

Account owners are notified by email of any sub-processor change; this page is kept current.

Contact

Questions about our sub-processors, or to request notice of future changes: support@pubsentry.io — PushRPM Global Pvt Ltd, Delhi, India. For how we handle data overall, see our Privacy Policy and Data Processing Addendum.


Stop invalid traffic before the ad fires. Score every visitor, block the invalid ones pre-serve, protect your account. Free for your first 500 pageviews.
Start free →