Sub-processors
Last Updated: September 2026
A sub-processor is a third party that receives data on Teralo's behalf in order to run the service. This page names every one of them.
Teralo publishes the complete list rather than a representative sample. An incomplete list is worse than no list, because a reader who finds one omission has no reason to trust the rest of it.
How to read this list
Platform providers receive data that an organisation puts into a project. If you are assessing Teralo as a vendor, these are the ones that matter.
Website providers receive data only about visitors to teralo.co. They never see project data, and the analytics and advertising ones run only if a visitor consents to them.
The location column says where the provider processes the data. Where a location is a provider's placement decision rather than a contractual commitment, the Privacy Policy says so explicitly. Teralo does not describe a best-effort placement as data residency.
Notification and objection
Teralo notifies customers before a new sub-processor starts receiving data, by updating this page and changing the date below.
A customer on a written agreement may object to a new sub-processor on reasonable data protection grounds, within 30 days of notification. Teralo will work with them to find an alternative, and where none is workable, the customer may terminate the affected part of the service without penalty for the remainder of the term and receive a refund of pre-paid fees for the unused portion. The binding form of this commitment is clause 5 of the Data Processing Agreement.
Questions and objections go to support@teralo.co.
The list
This list last changed on 2 September 2026.
Platform providers
| Provider | Purpose | Data it receives | Location |
|---|---|---|---|
| Supabase | Managed Postgres database behind the application | All customer project records, account details, induction records and biometric templates | Australia (AWS ap-southeast-2, Sydney) |
| Cloudflare | Application hosting, R2 object storage for uploaded files, CDN, DNS, WAF and transactional email delivery | Every uploaded file, plus request metadata, cached static content and outbound email content | Object storage in Oceania, delivered over a global edge network |
| Stripe | Payment processing and subscription billing | Billing contact details and payment method data, captured by Stripe and never held by Teralo | United States, with global processing |
| Google Gemini | AI features in the product | Prompt content and the project context submitted with it, and generated responses | Google global infrastructure |
| PostHog | Product analytics, and capture of AI prompts and responses for quality monitoring | Product usage events, and the full text of AI prompts and responses | United States (PostHog US Cloud) |
| Mapbox | Address geocoding for project and site locations | Project address strings submitted for lookup | United States (AWS) |
| CARTO | Basemap tiles for maps in the product | Map tile requests, which carry the requesting IP address | Global content delivery network |
Website providers
| Provider | Purpose | Data it receives | Location |
|---|---|---|---|
| Google Analytics | Website analytics on teralo.co | Website usage events and advertising identifiers, collected only on consent | Google global infrastructure |
| Google Ads | Advertising and remarketing for teralo.co | Website conversion events and advertising identifiers, collected only on consent | Google global infrastructure |
| Umami | Cookieless website analytics on teralo.co | Aggregated page view events, with no cookies and no personal identifiers | United States and European Union (Umami Cloud) |
Related documents
The Privacy Policy covers what Teralo collects and in what capacity. The Security page covers where data rests and how it is protected. The AI Product Terms cover the handling of AI prompts specifically.