Skip to content
Legal center

Subprocessor List

Service-provider categories and the production vendors BagTag may configure for hosting, email, media, storage, authentication, and monitoring.

Effective
2026-08-24
Version
2026.08
Audience
Leagues, organizations, and privacy reviewers

Production-selection rule

Only providers actually configured for the production deployment process personal data. Development and mock adapters are not production subprocessors. The operator must keep this page aligned with the live environment and contract before launch.

Core infrastructure

  • Railway or the selected application host — application compute, networking, logs, and scheduled workers; location depends on the deployed service.
  • Neon or the selected PostgreSQL provider — encrypted application database, backups, and recovery; location depends on the selected project.
  • S3-compatible private object storage — league-authorization documents and other private objects; vendor and region depend on production configuration.

Communications and identity

  • Resend — transactional staff, verification, reward, privacy, invitation, and operational email.
  • Better Auth — application authentication software operating inside BagTag infrastructure; not a separate hosted recipient by default.
  • Google — OAuth identity provider only when the optional Google sign-in configuration is enabled.

Media

  • Reimage — approved-image transformation, public delivery, storage, and deletion after private moderation.
  • Gumlet — legacy/configured video processing, playback, webhook status, and deletion. New production video submission and approval are currently disabled pending the controls described in the Youth Privacy and Media Notice.

Monitoring

  • Sentry — application error and performance monitoring only when SENTRY_DSN is configured. Sensitive fields must be redacted before transmission.

Changes and questions

Material provider changes will be reflected here and communicated where a signed agreement requires advance notice. A customer's reasonable objection is handled under the DPA.

  • Privacy: support@bagtag.com
  • Security: support@bagtag.com
These documents describe the current BagTag service. A signed order or negotiated agreement may add terms for a particular organization. If you need this document in another format, use the accessibility contact in the legal center.