Sub-processor list
Last updated: 26 April 2026
A sub-processor is a third party CampBooker engages to process personal data on our behalf in order to deliver the service. In line with Art. 28(3)(d) GDPR we publish the current list of sub-processors together with the scope of the engagement. We will give at least 14 days' notice of any change to this list to the tenant administrator's email address — you have the right to a reasoned objection under your data processing agreement.
| Entity | Processing purpose | Processing location | Categories of data | Retention | Documents / policy |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Application hosting (CAX31 ARM virtual server) | Falkenstein, Germany EU | All application data including personal data at rest (PostgreSQL database, user sessions, logs) | For the duration of the contract; deleted on account anonymisation | hetzner.com/legal/privacy-policy |
| Hetzner Online GmbH (Storage Box BX11) | Encrypted off-site backups (Restic) | Falkenstein, Germany EU | Encrypted database dumps (encryption key never leaves our infrastructure) | 14-day rotation | hetzner.com/legal/privacy-policy |
| Cloudflare, Inc. | DNS, CDN proxy, TLS termination (Origin Certificate), network tunnel and Cloudflare Access for SSH | Global edge network (Cloudflare is a US company; in-transit data may be processed worldwide) outside EU (under SCCs) | HTTP headers, client IP addresses, request metadata; no request bodies beyond TLS traffic in transit | Edge logs: up to 7 days (Free plan, per Cloudflare policy) | cloudflare.com/privacypolicy |
| Stripe, Inc. | Subscription billing (Checkout, billing portal, webhooks) | United States (Stripe Payments Europe Ltd. as the European affiliate; transfer outside the EEA based on Standard Contractual Clauses and the Stripe DPA) outside EU (under SCCs) | Tenant administrator email, Stripe customer and subscription IDs, payment metadata (card numbers never reach CampBooker — handled inside Stripe Elements iframe) | Per Stripe policy and AML/KYC requirements (typically 7 years for transactional data) | stripe.com/legal/dpa |
| Upstash, Inc. | Redis cache over HTTP and rate limiting (currently disabled — in-process fallback active) | Frankfurt, Germany (EU region) EU | Cache keys (no direct personal data), per-IP rate-limit counters | Max key TTL 24 h; rate-limit counters 60 s | upstash.com/trust/privacy |
| Functional Software, Inc. (Sentry — EU instance) | Application error monitoring, performance tracing, cron monitors | Frankfurt, Germany (EU region, ingest *.de.sentry.io) EU | Stack traces, breadcrumbs, request context (URL, status code, user identifier); the Sentry SDK scrubs sensitive data and request bodies by default | 30 days for error events (Developer plan) | sentry.io/legal/dpa |
| Aftermarket sp. z o.o. (web5.aftermarket.hosting) | SMTP server for transactional email | Poland EU | Tenant administrator email, invitee emails, reservation guest emails, and message content (confirmations, reminders, invoices) | SMTP server logs — per the provider's retention policy (typically up to 30 days for delivery logs); outbound messages are not archived on our side beyond the delivery log | aftermarket.pl/regulamin |
| Polish Ministry of Finance — National e-Invoicing System (KSeF) | Mandatory submission of structured VAT invoices to the tax administration | Poland (government system) EU | Invoice content including buyer details (NIP, name, address) and invoice line items | Per the VAT Act and Tax Ordinance — minimum 5 years from the end of the year of issue | podatki.gov.pl/ksef |
Hetzner Online GmbH
EU- Processing purpose
- Application hosting (CAX31 ARM virtual server)
- Processing location
- Falkenstein, Germany
- Categories of data
- All application data including personal data at rest (PostgreSQL database, user sessions, logs)
- Retention
- For the duration of the contract; deleted on account anonymisation
- Documents / policy
- hetzner.com/legal/privacy-policy
Hetzner Online GmbH (Storage Box BX11)
EU- Processing purpose
- Encrypted off-site backups (Restic)
- Processing location
- Falkenstein, Germany
- Categories of data
- Encrypted database dumps (encryption key never leaves our infrastructure)
- Retention
- 14-day rotation
- Documents / policy
- hetzner.com/legal/privacy-policy
Cloudflare, Inc.
outside EU (under SCCs)- Processing purpose
- DNS, CDN proxy, TLS termination (Origin Certificate), network tunnel and Cloudflare Access for SSH
- Processing location
- Global edge network (Cloudflare is a US company; in-transit data may be processed worldwide)
- Categories of data
- HTTP headers, client IP addresses, request metadata; no request bodies beyond TLS traffic in transit
- Retention
- Edge logs: up to 7 days (Free plan, per Cloudflare policy)
- Documents / policy
- cloudflare.com/privacypolicy
Stripe, Inc.
outside EU (under SCCs)- Processing purpose
- Subscription billing (Checkout, billing portal, webhooks)
- Processing location
- United States (Stripe Payments Europe Ltd. as the European affiliate; transfer outside the EEA based on Standard Contractual Clauses and the Stripe DPA)
- Categories of data
- Tenant administrator email, Stripe customer and subscription IDs, payment metadata (card numbers never reach CampBooker — handled inside Stripe Elements iframe)
- Retention
- Per Stripe policy and AML/KYC requirements (typically 7 years for transactional data)
- Documents / policy
- stripe.com/legal/dpa
Upstash, Inc.
EU- Processing purpose
- Redis cache over HTTP and rate limiting (currently disabled — in-process fallback active)
- Processing location
- Frankfurt, Germany (EU region)
- Categories of data
- Cache keys (no direct personal data), per-IP rate-limit counters
- Retention
- Max key TTL 24 h; rate-limit counters 60 s
- Documents / policy
- upstash.com/trust/privacy
Functional Software, Inc. (Sentry — EU instance)
EU- Processing purpose
- Application error monitoring, performance tracing, cron monitors
- Processing location
- Frankfurt, Germany (EU region, ingest *.de.sentry.io)
- Categories of data
- Stack traces, breadcrumbs, request context (URL, status code, user identifier); the Sentry SDK scrubs sensitive data and request bodies by default
- Retention
- 30 days for error events (Developer plan)
- Documents / policy
- sentry.io/legal/dpa
Aftermarket sp. z o.o. (web5.aftermarket.hosting)
EU- Processing purpose
- SMTP server for transactional email
- Processing location
- Poland
- Categories of data
- Tenant administrator email, invitee emails, reservation guest emails, and message content (confirmations, reminders, invoices)
- Retention
- SMTP server logs — per the provider's retention policy (typically up to 30 days for delivery logs); outbound messages are not archived on our side beyond the delivery log
- Documents / policy
- aftermarket.pl/regulamin
Polish Ministry of Finance — National e-Invoicing System (KSeF)
EU- Processing purpose
- Mandatory submission of structured VAT invoices to the tax administration
- Processing location
- Poland (government system)
- Categories of data
- Invoice content including buyer details (NIP, name, address) and invoice line items
- Retention
- Per the VAT Act and Tax Ordinance — minimum 5 years from the end of the year of issue
- Documents / policy
- podatki.gov.pl/ksef