Service providers
Subprocessors and connected services
These are the current provider categories used to operate FormSide. Whether a provider is a processor, independent controller or merely a public-data source depends on the service and data flow.
Last updated 17 August 2026 · Version 2026-08-17
Current provider list
| Provider | Purpose | Data involved | When used |
|---|---|---|---|
| Vercel | Application hosting, deployment, content delivery and serverless execution. | Request, technical and application data needed to serve the site. | Core service |
| Supabase | Authentication, PostgreSQL database, row-level access controls and private media storage. | Accounts, organisation, camp, booking, consent, attendance and payment-status records. | Core service |
| Resend (planned production default) or the specifically disclosed SMTP provider | Transactional booking and payment emails. | Recipient email plus a deliberately limited confirmation payload; no medical or emergency details. | Production email |
| Cloudflare Turnstile | Bot and booking-abuse protection. | Challenge token, request IP and related device/security signals. | Production booking security |
| Stripe | Optional hosted card checkout and payment-status webhooks. | Booker email, amount, currency, camp description and limited booking/payment identifiers. | Only when card payments are enabled |
| OpenStreetMap / Nominatim provider | Map display and low-volume server-side venue geocoding. | Camp venue text for geocoding; request IP and device data only after a visitor asks to load the interactive map. | Geocoding and user-requested public maps |
| YouTube privacy-enhanced mode or Vimeo | Display an organiser-supplied public gallery video after a visitor asks to load it. | The visitor's request IP, device/browser data and any provider-controlled storage after activation; no participant booking record is sent by FormSide. | Optional, user-requested public media |
Changes and questions
Every affected organiser will receive reasonable notice before a material new subprocessor is appointed where required by the data processing terms. The production data map must name the actual provider legal entity, processing location and transfer safeguard before live personal data is sent. Questions or reasonable objections based on data-protection risk can be sent to privacy@formside.app.