Subprocessors
Version 2026-08-22 · Last updated 22 August 2026
These third parties process data on MeshCrunch's behalf. The API, workers, database, and message broker run on infrastructure we operate ourselves.
Current subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare (R2) | Object storage for uploaded 3D models and generated outputs. | Uploaded model files, optimized meshes, LOD chains, and archives. |
| Vercel | Hosting for the website and application, plus page-view analytics. | HTTP request metadata, IP addresses, and page-view events. No model data. |
| Auth0 (Okta) | Authentication and account sign-in. | Email address, authentication identifiers, and sign-in events. |
| Paddle.com Market Ltd | Checkout, payment processing, and subscription billing for paid plans. Paddle is the Merchant of Record for those purchases and sells the subscription to you directly. | Name, billing email, billing address, tax location, and payment details, all collected by Paddle in its own checkout. MeshCrunch receives back the customer and subscription identifiers, the subscription status and price, and the billing email. No model data. |
| Let's Encrypt (ISRG) | TLS certificate issuance for the API. | Domain names only. No customer data. |
Who you are buying from
Paddle is the Merchant of Record for every paid plan. That means Paddle — not MeshCrunch — is the seller on the transaction, takes the payment, charges and remits any sales tax or VAT, and issues the receipt. MeshCrunch never sees or stores your card details.
What MeshCrunch keeps is the link between your account and the subscription: the Paddle customer and subscription identifiers, the subscription status, the price purchased, the billing period dates, and the billing email Paddle reports. That is what decides which plan your account is on.
Not in use
MeshCrunch does not currently use an error-monitoring service, a support-desk platform, a transactional-email provider, or any machine-learning service. Any of these would be added here before it started processing customer data.
Hosting and residency
Every provider above is global, and each decides for itself where a given request is served or an object replicated. MeshCrunch offers no data-residency guarantee, and none should be inferred. Assume your data may be processed outside your own country, including in the United States. Where a transfer out of the UK or EEA occurs it relies on the provider's own transfer mechanism, published in the terms linked above.
If regional storage or processing is a requirement for you, MeshCrunch cannot meet it today. Say so before you upload anything rather than after.
Changes to this list
A new subprocessor is added to this page before it begins processing customer data, and the version date at the top changes with it. There is no mailing list or advance-notice commitment: those belong with a data-processing agreement, which we do not currently offer. Watching this page is the mechanism.
Questions about this page? Email support@meshcrunch.com. Security reports go to the same address.