Trust Center

Trust Center

Where your data lives, who processes it, and how it's protected.

Architecture & Data Flow

The data flow is linear and uses only European processing regions — with one documented exception for our AI feature (Anthropic, USA, under the EU-US Data Privacy Framework).

  1. User's browser · TLS 1.2+
  2. Vercel Edge · Frankfurt (fra1)
  3. Supabase Postgres · Ireland (eu-west-1)
  4. ↓ optional, opt-in
  5. Anthropic API · USA, EU-US Data Privacy Framework

Sub-Processors

We use the following processors. The list is kept in sync with the more detailed table in our Privacy Policy. A data processing agreement under Art. 28 GDPR is in place with each provider.

ProviderPurposeLocation / Data RegionInternational Transfer Safeguard
Vercel Inc.Hosting, CDN, edge functionsUSA, EU edge fra1EU SCCs + DPF
Supabase Inc.Postgres, Auth, StorageIreland (eu-west-1)Processing within the EU
Anthropic PBCAI anomaly explanations, help chatbotUSAEU-US DPF + SCCs
Resend Ltd.Transactional emails, newsletterUK (processing within the EU)UK adequacy decision
Plausible Insights OÜCookieless web analyticsEstonia / GermanyProcessing within the EU

Standard data processing agreement template for our customers: Download DPA template.

Encryption & Access

Backups & Availability

Compliance

Coordinated Disclosure

Found a vulnerability? Thank you. Please report it to security@themarketplaceguys.com. We acknowledge receipt within 48 hours and will keep you updated.

Machine-readable contact details are in our security.txt (RFC 9116).

Hall of Fame

We list researchers whose reports have helped us improve our security here, with their consent. Currently: no entries yet.

Downloads & Further Documents

A question about our setup? Drop us a line at security@themarketplaceguys.com. Reply within one business day.

Last updated: 2026-05-10