Subprocessors
Last updated October 6, 2026.
These are the third-party services that process personal data for Portal Hound, what each one does for us, and where. They're the same services our Privacy Policy describes, and the list our Data Processing Addendum refers to. We'll email customers' account contacts at least 30 days before adding or replacing one.
| Subprocessor | What it does for us | Data it handles | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosts each customer's dedicated gateway (EC2) and control plane: sign-in (Amazon Cognito, which also sends the sign-in invitation emails), worker and device records (DynamoDB), configuration (SSM, Secrets Manager), the API (API Gateway, Lambda) and logs (CloudWatch). Also stores our deployment state (S3). | Worker and administrator names, work emails and roles; device details; gateway access logs; portal lists. | United States (us-east-2, Ohio) |
| Cloudflare | Runs portalhound.com (Workers), stores orders and terms acceptances (Workers KV) and customers' installers (R2), sends our emails (Email Sending) and forwards mail sent to support@ and hello@ (Email Routing). | Website requests (IP address, browser); buyer, administrator and worker contact details in orders; email content. | Global network; data stored in the United States or as Cloudflare determines |
| Stripe | Takes payment through Stripe Checkout, runs subscriptions and invoices, works out sales tax, and hosts the billing page where you update your card or cancel. | Buyer name, email, billing address, tax ID, company name, website and team size; payment details. | United States |
| GitHub (Microsoft) | Runs the automated provisioning job (GitHub Actions) that builds a customer's gateway, control plane and apps. | The order: company name, administrator and worker names and emails, approved portal addresses. | United States |
| Our company mailbox (Google Workspace), where mail to support@ and hello@ arrives. Also Google Fonts, which serves the website's typeface. For customers who choose Google Workspace sign-in, Google confirms each user's identity. | Email you send us; website visitors' IP address and browser (fonts); sign-in identity (only with Google sign-in). | United States |
Other services the apps contact
These aren't our subprocessors (we don't send them your data), but they're part of how Portal Hound works:
- ipify (api.ipify.org). The worker app's connection test asks it which internet address the computer's ordinary traffic uses, to confirm that only approved portals go through the gateway. ipify sees that address; we send it nothing else.
- WireGuard. Workers install the free WireGuard program from wireguard.com (or the App Store) for the secure connection. It is installed and updated by the worker; it does not send data to us or to WireGuard's authors.
- Ubuntu package mirrors. The gateway server installs its software (including Squid and WireGuard tools) from Ubuntu's official package mirrors when it is built and updated.
Running in your own AWS account
If Portal Hound runs in an AWS account your company controls, AWS is your provider, not our subprocessor, and the control-plane data never leaves your account.
Questions: support@portalhound.com.