DFF Reach legal
Subprocessor & Service Supplier List
Last updated: 20 September 2026
This page identifies the principal suppliers DFF Reach may use to operate the service. Availability and processing depend on the feature and deployment. Connected social providers are generally independent third parties rather than DFF Reach subprocessors.
Supplier transparency
- Vercel and Supabase support the core hosted application and data layer.
- Cloudflare R2, Resend and Stripe are used only where the corresponding media, email or billing feature is enabled.
- Social networks process data under their own terms when the user chooses to connect them.
- Material supplier changes will be reflected here or notified as required by an applicable DPA.
1. Core subprocessors
The following suppliers may process limited Customer Personal Data to provide the stated infrastructure function. Corporate location and actual processing regions can vary with the supplier configuration and lawful service delivery.
- Vercel Inc. — application hosting, content delivery, serverless execution and bounded operational logging.
- Supabase, Inc. and its infrastructure providers — authentication, PostgreSQL database services, access controls and related platform operations.
- Cloudflare, Inc. — object storage or delivery for approved media through Cloudflare R2 where that feature is enabled.
- Resend, Inc. — transactional and security email delivery where email sending is enabled.
2. Payment supplier
Stripe and its group companies may process checkout, card, billing, tax, invoice or fraud-prevention information where paid billing is enabled. Depending on the processing activity and local law, Stripe may act as a processor, service provider or independent controller. Stripe's own terms and privacy notice also apply.
DFF Reach does not store complete payment-card or bank-account details.
4. Data minimisation
DFF Reach sends each supplier only the information reasonably needed for its function. Provider passwords, raw service secrets, complete card details and unrelated customer records must not be included in ordinary supplier payloads.
Supplier access is restricted through server-side credentials, scoped permissions, environment separation and contractual or technical controls appropriate to the service.
5. Changes and objections
This list may change as DFF Reach replaces or adds infrastructure. A material new subprocessor will be published here and notified where the applicable DPA or law requires advance notice.
A Customer with a legally supportable data-protection objection should contact support@directfoodfinder.com with the subject “DFF Reach subprocessor objection” during the stated notice period, identifying the Customer and the specific grounds.
3. Connected social and publishing providers
TikTok, Meta services, Instagram, Facebook Pages, Threads and any later connected destinations are selected by the user and operate their own services. They normally determine their own purposes and rules for provider accounts, content, messages, analytics and platform security.
They are therefore not listed as DFF Reach subprocessors merely because DFF Reach transmits an authorised publication or retrieves a supported result. Their own privacy policies, terms and international-transfer arrangements apply.