Legal

Sub-processor List

Last updated: 9 July 2026

Meridian uses the following sub-processors to provide the Service. We will notify firm administrators of material additions or changes at least 14 days in advance, per our Data Processing Agreement.

Sub-processorPurposeData processedLocation
Supabase (database + auth)Database hosting, authentication, row-level security enforcementAll client forecast data, account credentialsAWS eu-west-1 (Ireland)
VercelApplication hosting, deploymentApplication code execution; transient request dataAWS eu-west-1 (Ireland) / global edge network
Stripe (phase 2)Payment processingBilling name, address, payment card data (tokenised — Meridian never stores raw card numbers)Global (PCI-DSS compliant)
ResendTransactional email (login, notifications)Adviser name and email addressEU
Sentry (planned)Application error trackingTechnical error data, configured to exclude client PIIEU

We do not use any sub-processor to train third-party AI/ML models on Customer data.

Questions: support@meridiancashflow.com