Legal

Subprocessors

Who handles personal data for CLItrail, what each one does, where, and under which safeguard, plus how we tell you before anything on this page changes. CLItrail is a project developed by Pilot Protocol and operated by Vulture Labs, Inc. This page is Annex III of the Data Processing Addendum.

Status
In effect
Last changed
24 September 2026
Applies to
The hosted CLItrail service at clitrail.com
On this page

Summary

Subprocessors
Cloudflare® hosts and stores everything. Google hosts our email.
Your recipients
Destinations and log streams you set up are yours to choose. They are not our subprocessors.
Notice
30 days before a new subprocessor starts, by email to your organisation’s owners and in the change log below.

Three kinds of provider

  • Subprocessors handle your visitors’ and installers’ data for us, as part of running CLItrail for you. We are your processor and they are our subprocessors (section 02).
  • Our own service providers handle the data of the people who use the CLItrail dashboard: sign-in, billing and support. For that data we are the controller (section 03).
  • Recipients you choose receive data only because you set them up: your destinations and log streams. They process it under their own terms with you (section 04).

Subprocessors for your visitors’ and installers’ data

SubprocessorWhat it doesDataLocationSafeguard
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USARuns CLItrail on Cloudflare Workers®; stores its database and its separate secret store in Durable Objects™, and our operator copy of the logs in R2; carries all network traffic; keeps short-lived platform logs.All visitor and installer data CLItrail processes (Annex I of the DPA).Cloudflare’s network. The database and secret store stay in the data centre where they were created; no jurisdiction restriction is set.Cloudflare Data Processing Addendum (version 6.4, effective 3 April 2026), with SCC Modules Two and Three, the UK Addendum and Swiss transfer terms. Certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework (Cloudflare privacy policy).
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USAHosts our mailbox, founders@pilotprotocol.network (Google Workspace), for as long as an email is kept there.Only what you or an individual send us by email, for example an installation ID in a rights request.The United States and any other country in which Google or its subprocessors maintain facilities, as Google’s data processing terms permit (locations).Google Cloud Data Processing Addendum. Google LLC is certified under the Data Privacy Framework (Firebase privacy page).

Our own service providers

These providers handle Account Data, for which Vulture Labs is the controller under the privacy policy.

ProviderWhat it doesDataLocationSafeguard
Cloudflare, Inc.Hosts the dashboard and stores accounts, organisations, billing status, support requests and the activity log, as above. Domain verification looks up your DNS record through Cloudflare’s public DNS-over-HTTPS resolver.Account Data; the domain name being verified.As above.As above.
Google LLC (Firebase Authentication)Signs you in to the dashboard with your Google account or with a one-time sign-in link sent to your email address. CLItrail’s server fetches Google’s public signing keys and asks Firebase whether a sign-in has been revoked.Your email address and Firebase user ID, and the sign-in itself; for email-link sign-in, Firebase sends the sign-in email. Firebase also uses IP addresses and user-agent strings to protect sign-in against abuse, and keeps logged IP addresses for a few weeks.United States: Firebase Authentication runs only from US data centres.Google Cloud Data Processing Addendum, which covers Firebase Authentication under the Google Cloud Platform terms. Data Privacy Framework.
Google LLC (Google Workspace)Hosts founders@pilotprotocol.network, where you write to us for support, privacy, security and legal matters, and from which we send notices.Your messages and email address.As above.As above.
Stripe, LLCProcesses payments for paid plans. You enter card details on Stripe’s own pages; they never reach CLItrail. We send Stripe the organisation’s ID, the chosen plan and, for a new customer, the email address of the owner who subscribes.Billing details.United States.Stripe Data Processing Agreement. Stripe, LLC complies with the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework (Stripe privacy policy).

We use no advertising or analytics providers of our own.

Recipients you choose

These recipients receive data only when your organisation, on a paid plan, adds a destination and switches it from test mode to live, or, on Enterprise, creates a log stream. You set each one up with credentials from your own account there, and it processes the data under its own terms with you, which you accept separately. Visits made with Global Privacy Control are never used for Google Ads, Meta, TikTok or X Ads. The privacy policy lists exactly what each one receives.

RecipientThroughWhat it receivesIts role, under its own terms
Google (Google Analytics 4)Measurement ProtocolGA4 client_id; session_id while the session is recent (never after 24 hours); event name and ID; page ID; attribution method and policy; time.Under the Google Analytics terms you accept.
Google (Google Ads)Data Manager API, signed in as your own Google Cloud service accountOne click identifier (gclid, wbraid or gbraid) and Google’s session attributes when present; a transaction ID; event time; the consent values you set; optional value and currency.Under the Google Ads terms and policies you accept.
MetaConversions APIfbc and fbp; a SHA-256 hash of the installation ID as external_id; event name, time and ID; action_source “other”; optional value, currency and Limited Data Use flags.Meta’s Business Tools Terms make Meta Platforms Ireland Limited your processor for matching, measurement and analytics, and your joint controller for the collection and transmission of event data used for its own purposes; under the UK GDPR, the same with Meta Platforms, Inc.
TikTokEvents APIttclid and ttp; a SHA-256 hash of the installation ID as external_id; the install page (origin and path) and its referrer; event name, time and ID; optional value and currency.TikTok’s Jurisdiction Specific Terms make you and TikTok (TikTok Technology Limited and TikTok Information Technologies UK Limited) joint controllers for collecting and transmitting event data, where the GDPR applies.
X (X Ads)X Ads API conversions endpoint, signed with your own X app keys and access tokenstwclid; the conversion time; your pixel event ID; a conversion ID from the install event, so X can deduplicate it with its pixel; optional value and currency.X’s Conversion Tracking Program terms (X Corp. in the US; X Internet Unlimited Company, Dublin, elsewhere) place Conversion Data under X’s Inbound Controller-to-Controller Data Protection Addendum, where each party is an independent controller, and Match Data under X’s Processor Data Protection Addendum. X requires you to tell your users how to opt out of its interest-based advertising (how). See the X Ads docs.
Your webhooksYour HTTPS endpointThe install event, its install path, attribution result and journey, and the identifiers you turn on.Your own system.
Your log streams (Enterprise)Amazon S3, S3-compatible storage such as Cloudflare R2 or MinIO, or your webhookCopies of your organisation’s log records.Under your own agreement with that provider.

How we tell you about changes

  • 30 days’ notice. Before we add or replace a subprocessor in section 02, we tell you at least 30 days before it starts handling your visitors’ and installers’ data.
  • How. By email from founders@pilotprotocol.network to every owner of each organisation, at the address they sign in with, and as a dated entry in the change log below. To have notices also sent to another address, write to founders@pilotprotocol.network. Apart from sign-in link emails sent through Firebase, the CLItrail service sends no automated email; these notices are written and sent by us.
  • What the notice says. The provider’s name, where it is, what it will do, which data it will handle and which safeguard applies.
  • Objecting. You can object on reasonable data protection grounds within those 30 days by writing to founders@pilotprotocol.network. We will look for a way to meet your objection. If we cannot, you may cancel your plan, then delete the organisation once the subscription has ended (DPA section 08).
  • Urgent changes. If we must replace a subprocessor at short notice to keep data secure or the service running, we tell you as soon as we can, and you can object from then.
  • Our own service providers (section 03) are also added to the change log when they change.

Change log

DateChange
24 September 2026First published list: Cloudflare, Inc. and Google LLC (Google Workspace) as subprocessors; Cloudflare, Inc., Google LLC (Firebase Authentication, Google Workspace) and Stripe, LLC as our own service providers.

Contact

Questions or objections: founders@pilotprotocol.network. Vulture Labs, Inc., San Francisco, California, USA.