Meridian uses the following sub-processors to provide the Service. We will notify firm administrators of material additions or changes at least 14 days in advance, per our Data Processing Agreement.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase (database + auth) | Database hosting, authentication, row-level security enforcement | All client forecast data, account credentials | AWS eu-west-1 (Ireland) |
| Vercel | Application hosting, deployment | Application code execution; transient request data | AWS eu-west-1 (Ireland) / global edge network |
| Stripe (phase 2) | Payment processing | Billing name, address, payment card data (tokenised — Meridian never stores raw card numbers) | Global (PCI-DSS compliant) |
| Resend | Transactional email (login, notifications) | Adviser name and email address | EU |
| Sentry (planned) | Application error tracking | Technical error data, configured to exclude client PII | EU |
We do not use any sub-processor to train third-party AI/ML models on Customer data.
Questions: support@meridiancashflow.com