Subprocessor List

Consumer Dividends Holding Corp

Last updated: June 14, 2026

This list identifies the third-party service providers ("subprocessors") that may process customer personal data on behalf of Consumer Dividends Holding Corp. We publish it so that customers, their counsel, and their compliance teams can evaluate our supply chain. Updates are reflected in the "Last updated" date and, for material changes, emailed to active customers and Agency tier contacts at least 30 days before they take effect.

Active subprocessors

ProviderPurposeData processedRegionCompliance
RailwayApplication hosting (Numidian, ListingPro)All inputs and outputs during processing; access codes; usage logsUnited StatesSOC 2 alignment; encryption in transit and at rest
SupabaseDatabase backing for ListingProProperty inputs, generated outputs, account referencesUnited StatesSOC 2 Type II; GDPR-aligned
PostgreSQL on RailwayDatabase backing for NumidianCase inputs, generated outputs, access codes, case historyUnited StatesSame as Railway above
CloudflareDNS, CDN, edge security for consumerdividends.com and product subdomainsIP address, request paths, security logsGlobal edge; primary USSOC 2 Type II; ISO 27001; GDPR-aligned; DPA available
StripePayment processing, subscription management, billingCardholder data (Stripe-tokenized, not stored by us), customer email, transaction historyUnited States and other regions per StripePCI DSS Level 1; SOC 1, SOC 2; GDPR-aligned
OpenAI (via API)Language model inference for Numidian and ListingPro outputsInputs submitted at runtime; not retained for training under our API agreementUnited StatesSOC 2 Type II; GDPR-aligned; zero-retention API option in use
Google WorkspaceOperational email (support@, andreys@, admin@consumerdividends.com)Email content sent to or from usUnited StatesSOC 1/2/3; ISO 27001/27017/27018; GDPR-aligned
GitHubSource code hostingNo customer personal dataUnited StatesSOC 2 Type II

Notes on scope

OpenAI: Inputs you submit to Numidian or ListingPro are sent to OpenAI for the duration needed to generate your output. Under our API agreement with OpenAI, those inputs are not used to train OpenAI's models and are not retained beyond 30 days for abuse-monitoring purposes (and zero retention where requested for specific endpoints). We have configured our integration to minimize retention to the extent OpenAI supports.

Railway and Cloudflare: handle infrastructure and edge security. They have access to network metadata (IP addresses, request paths) but not to the contents of your inputs or outputs except as data passes through their networks in transit.

Stripe: receives payment information directly through Stripe's secure checkout. We do not store full payment card data on our systems. We receive payment confirmation events and customer identifiers from Stripe.

Changes

We may add or replace subprocessors. Material changes are communicated by:

Customers may object to a new subprocessor on reasonable grounds. If we cannot resolve the objection, the customer may terminate the affected service and receive a pro-rata refund.

Questions

support@consumerdividends.com