This page identifies the third parties ("sub-processors") that PushRPM Global Pvt Ltd ("PubSentry," "we," "us") engages to help deliver the PubSentry service, and the categories of data each one touches. It supplements our Privacy Policy and Data Processing Addendum; where this list conflicts with the sub-processor section of the DPA, the most recently published version controls.
Effective date: June 27, 2026 Controller / processor: PushRPM Global Pvt Ltd, Delhi, India — questions to support@pubsentry.io. Governing law: This page is governed by the laws of India, subject to the mandatory provisions of applicable data-protection law.
What a sub-processor is
A sub-processor is a third party we authorise to process personal data on our behalf in the course of providing the Service — for example, the infrastructure that runs our datastores, or the vendor that sends a billing email. Engaging sub-processors is normal for a SaaS product, but it is something we keep deliberately small and disclose openly.
Two design choices keep this list short and low-risk:
- Data minimization at ingest. When the PubSentry tag scores a page view, the raw IP address and User-Agent are hashed server-side with HMAC-SHA256 and then dropped — never written to storage. What persists is a one-way keyed hash, derived network/geo attributes from an offline iptoasn dataset (no residential-proxy, VPN, or Tor lookup that would call a third party), and event metadata. There is no third-party IP-intelligence, ad-network, or data-broker call on the scoring path, so the visitor-signal flow has no sub-processor of its own.
- First-party, same-origin product. The dashboard and APIs are served from our own infrastructure; authentication uses a first-party session cookie. The few sub-processors below sit at the edges — infrastructure, payments, and email — not in the detection loop.
Our current sub-processors
We engage the following sub-processors. Each is bound by data-protection terms no less protective than those we owe you, and PubSentry remains responsible for their performance.
| Sub-processor | Role | Purpose | Data it touches | Processing location |
|---|---|---|---|---|
| Hostinger International Ltd | Cloud hosting + outbound email | Runs the application servers, ClickHouse (events), and Redis (reputation, accounts, configuration) the Service is built on, and sends transactional and account email (sign-up/verification, billing notices, alert/notification messages) via SMTP | Scored event metadata, hashed identifiers (HMAC-SHA256, raw IP/UA already dropped), reputation/velocity counters, account records (email, scrypt password hash, plan, billing state), TTL-bounded config — all at rest on infrastructure we operate; plus the recipient email address and message content of outbound mail | European Union |
| DodoPayments | Payment processing & billing | Merchant-of-record and payment processing for account subscriptions (checkout, customer portal, billing webhooks) | Billing contact details and card / payment data — handled directly by DodoPayments under its own terms; PubSentry receives only billing status and customer/subscription reference IDs, not card numbers | Per DodoPayments' terms |
| Anthropic | AI narration of de-identified detection findings | Generates plain-language narration of detection findings for the dashboard; only de-identified, aggregated detection findings are sent — no raw visitor PII | De-identified, aggregated detection findings only (no raw visitor PII) | Per Anthropic's terms |
| proxycheck.io | Optional IP-reputation lookups | Optional residential-proxy / VPN / Tor reputation lookups, only when enabled by an account; IP address only, and only for non-datacenter public IPs | IP address only (only when the optional lookup is enabled) | Per proxycheck.io's terms |
Note on the hosting provider. PubSentry self-hosts the application stack on infrastructure rented from Hostinger International Ltd. Because all persisted data lives there, this is the broadest sub-processor on the list and the one most relevant to a security review. Backend services are bound to localhost behind a reverse proxy and are not directly reachable from the public internet; data in transit is served over TLS. Hostinger International Ltd provides our cloud hosting and outbound email (European Union); data is encrypted in transit and at rest.
What is not on this list
To set expectations honestly:
- No third-party tracking, advertising, or remarketing vendors touch visitor-signal data. The detection tag sets no cross-site advertising cookies and builds no cross-site profile.
- No third-party IP-intelligence or data-broker service is called when scoring traffic; network/geo enrichment uses an offline dataset we ship.
- Google Analytics 4 runs on the public marketing site only (
pubsentry.com) for aggregate, non-identifying measurement — never inside the authenticated dashboard or the detection path. It is described in our Cookie Policy rather than treated as a processor of customer or visitor data. We do not use Google Analytics within the PubSentry application.
Engaging new sub-processors and notifying you
We may add or replace a sub-processor as the product grows — for example, if we adopt a new email provider or add a second infrastructure region.
When we do, we commit to:
- Hold the new sub-processor to equivalent obligations. Any replacement or addition must be bound by data-protection terms at least as protective as those in our DPA, and PubSentry remains responsible for its acts and omissions.
- Give you advance notice of changes affecting visitor-signal or customer personal data. We will provide reasonable prior notice before a new or replacement sub-processor starts processing such data. We will provide at least thirty (30) days' notice of any new sub-processor by updating this page and emailing account owners.
- Let you object on legitimate grounds. If you have a reasonable, data-protection-based objection to a new sub-processor, tell us at support@pubsentry.io. We will work with you in good faith; if we cannot reasonably accommodate the objection, your remedy is to terminate the affected Service as described in the DPA and Terms.
This page is the canonical, up-to-date list. Changes will be reflected here with a revised effective date, and material changes affecting personal data will additionally be communicated through the notice channel above.
How to subscribe to changes
Account owners are notified by email of any sub-processor change; this page is kept current.
Contact
Questions about our sub-processors, or to request notice of future changes: support@pubsentry.io — PushRPM Global Pvt Ltd, Delhi, India. For how we handle data overall, see our Privacy Policy and Data Processing Addendum.
