Sub-processors

Third-party service providers that process personal data on behalf of 4rho.

Last updated:

This page lists the third-party service providers ("sub-processors") that 4rho uses to operate the platform. Each provider processes a defined slice of personal data on 4rho's behalf, under a written data- processing addendum (DPA), and only for the purpose listed.

We update this list before adding new sub-processors. Material changes notify affected B2B counterparties at least 30 days before the change takes effect; individual users are notified through the in-app banner and an entry in the Privacy Policy changelog.

Last updated: 2026-05-14

Current sub-processors

ProviderPurposeRegionTransfer mechanism
VercelFrontend hosting + edge CDNUnited States (global edge POPs)EU Standard Contractual Clauses (SCCs) for non-US data subjects
RailwayBackend application hostingUnited StatesEU Standard Contractual Clauses (SCCs)
NeonManaged Postgres (primary database)United StatesEU Standard Contractual Clauses (SCCs)
UpstashManaged Redis (cache + rate limits)Multi-region (configurable)EU Standard Contractual Clauses (SCCs)
SentryError monitoring + performance tracesUnited StatesEU Standard Contractual Clauses (SCCs); user-PII scrubbed before send
PrivyAuthentication, embedded-wallet custodyUnited StatesEU Standard Contractual Clauses (SCCs)
ResendTransactional email delivery (verification, breach notification, support replies)United StatesEU Standard Contractual Clauses (SCCs); email address + dispatch metadata only
CloudflareDDoS mitigation + edge proxyGlobalAdequacy / SCCs (depending on user region)
ipapi.coGeoIP enrichment for sign-insMulti-regionSCCs; only IP-derived metadata, no payload
ChainalysisOFAC / sanctions wallet screeningUnited StatesSCCs; only on-chain wallet addresses

Categories of data

Each sub-processor receives only the slice of data needed for its function. The Privacy Policy enumerates the categories of personal data 4rho collects; the table below maps those categories to the sub-processors that touch them.

Data categorySub-processors
Authentication identifiers (Privy DID, OAuth subject)Privy, Sentry (incidental in error context)
Wallet addressesPrivy, Chainalysis, Sentry (incidental)
IP address + derived geolocationVercel, Cloudflare, Railway, ipapi.co, Sentry
Account profile (display name, email, DOB, preferences)Neon (primary store), Sentry (incidental)
Email address (for transactional dispatch)Privy (account-of-record), Resend (delivery only)
Trade history + on-chain receiptsNeon, Polygon (public chain — out of scope as a sub-processor)
Support ticket contentNeon

Notification of changes

When 4rho engages a new sub-processor or replaces an existing one we update this page and the changelog block at the bottom of the Privacy Policy. For B2B / institutional accounts, written notice is sent at least 30 days before the change becomes effective; objections must be raised within that window.

Contact

For DPA copies, sub-processor objections, or sub-processor-specific data-protection questions, contact the data-protection officer via the in-app support inbox at /support/tickets/new.