Authgear Logo
SECURITY
Attack Protection
Adaptive MFA
SMS Pumping Protection
Authorization
AUTHENTICATION
Authentication
Single Sign-On
Social Login
Passwordless
WhatsApp OTP
Passkeys
Biometric
Machine-to-Machine Token
USER
User Management
Self-serve Settings
BRANDING
Customization
INTEGRATION
Extensibility
PRODUCTS
On the Cloud
(Start for Free)
Migrate to Authgear
Frontline Worker Identity
Customer Identity Management
B2B SaaS Applications
Enterprise SSO
SMS Cost Saving
Blog
Case Studies
Comparison
Login Gallery
Glossary
Partners
Documentation
Github
What's New
  • Pricing
Get a Demo
Signup/Login
Get a Demo

Legal · Last updated 2026-05-31

Sub-Processors

This page lists the third-party Sub-processors engaged by Authgear (SkyMakers Digital Limited) to deliver the hosted Authgear Services. Each Sub-processor is bound by data-protection obligations substantially equivalent to those in the Data Processing Addendum.

This page is the canonical record of Authgear's current Sub-processors and related vendor relationships. See Subscribing to Changes below for notification and objection procedures.

Authgear-operated Sub-Processors (GDPR Article 28)

The vendors in the table below Process End User Personal Data on Customer's behalf in connection with the Authgear Services and therefore qualify as Sub-processors under Article 28 of the EU GDPR and the equivalent provisions of the UK GDPR.

Sub-ProcessorEntityRegionPurposePersonal Data
Google Cloud PlatformGoogle LLCGlobal GCP regionsCloud hosting and infrastructure (compute, managed databases, object storage, networking)All End User Personal Data processed by the Services
PostmarkActiveCampaign, LLCUnited StatesTransactional email delivery for the Authgear Developer Portal (account invitations, password resets, billing and security notifications)Recipient email address; message content
StripeStripe, Inc.United StatesSubscription billing and payment processing for the Authgear Developer Portal (Customer billing only)Customer billing contact details; payment-card data (stored by Stripe, not by Authgear)
SentryFunctional Software, Inc. d/b/a SentryUnited StatesApplication error and exception monitoring across the Authgear Services and PortalError and stack-trace data; may incidentally contain limited Personal Data from request context
PostHogPostHog, Inc.United StatesProduct analytics on Customer admin activity within the Authgear Developer PortalCustomer admin event data; project metadata. Tracks Customer administrators only; does not capture End User Personal Data of Customer applications.
Google Analytics / Google Tag ManagerGoogle LLCUnited StatesWeb analytics for the Authgear Developer Portal (portal.authgear.com only)Portal usage events; Customer admin browser-side analytics, governed by the Privacy Policy

Other Vendor Relationships

The vendors in the table below support Authgear's own business operations (sales, marketing, compliance, status communications, internal collaboration). They process Authgear's own data, and in some cases may incidentally process Customer administrator contact details (for example, when a Customer admin emails Authgear support or signs up for the Authgear newsletter). They do not Process Customer End User Personal Data on Customer's behalf and are therefore not Sub-processors within the meaning of Article 28 GDPR. They are listed here for transparency.

VendorEntityRegionPurposeData
Google WorkspaceGoogle LLCUnited StatesCorporate email, file storage, and internal collaboration (the mailbox behind hello@authgear.com and Authgear's internal documents)Inbound and outbound email content, including any Customer admin support correspondence; internal documents
MailerLiteMailerLite LimitedIrelandMarketing mailing list and newsletter deliveryEmail address and (where provided) name of opt-in newsletter subscribers; engagement metadata
CalendlyCalendly, LLCUnited StatesSales-demo scheduling for the Schedule a demo flowProspect or Customer admin name, email, company, time zone, meeting time, and any answers provided in the booking form
SprintoSprinto, Inc.United States (with operations in India)Compliance-program automation for maintaining ISO/IEC 27001 and SOC 2 Type IIEmployee names and access reviews; system inventory; compliance evidence metadata. No Customer End User Personal Data.

Customer-configured Integrations (not Authgear Sub-Processors)

Customers may, at their option, configure the Authgear Services to interact with third-party providers using credentials and accounts that the Customer owns and controls. Authgear is not a Sub-processor for these integrations; the Customer selects the provider, controls the data flow, and is responsible for entering into appropriate data-protection arrangements directly with the provider.

Categories include:

  • SMTP providers (any) for Customer-sent verification, password-reset, and notification emails to End Users
  • SMS providers — Twilio, Nexmo/Vonage, or any HTTP-callable custom gateway
  • WhatsApp Cloud API (Meta Platforms) for WhatsApp OTP delivery
  • Bot-protection providers — Google reCAPTCHA v2 and Cloudflare Turnstile
  • Customer-controlled cloud storage (AWS S3, Google Cloud Storage, Azure Blob Storage, Alibaba Cloud OSS) for user export and asset storage
  • Identity providers / OIDC and SAML connectors (e.g., Google, Microsoft, Apple, GitHub, Customer-operated identity providers) as configured by the Customer

Subscribing to Changes

Authgear publishes proposed Sub-processor additions or replacements on this page at least thirty (30) days before the change takes effect, unless an earlier engagement is required for security or business-continuity reasons. To receive email notifications when this list changes, please write to hello@authgear.com with the subject line "Subscribe to sub-processor updates". Objections on reasonable data-protection grounds may be raised in accordance with Section 6 of the Data Processing Addendum.

Start building with Authgear

Start for freeSchedule a demo

Free plan includes unlimited MAUs

Authgear
Authgear powered by SkyMakers Digital Group
ISO 27001 CertifiedPasskey Pledge Partner

Authgear is both ISO 27001 and SoC 2 Type II compliant.

  • Products

  • Home
  • Pricing
  • Migrate to Authgear
  • alternative

  • Okta Alternative
  • Auth0 Alternative
  • Cognito Alternative
  • Firebase Alternative
  • developers

  • Documentation
  • API Reference
  • GitHub
  • Community Forum
  • Discord
  • Integrations
  • resources

  • Blog
  • Login Gallery
  • Glossary
  • Partners
  • Free Tools

  • OIDC Discovery Explorer
  • SSL Checker
  • UUID v7 Generator
    & Timestamp Extractor
  • Base64 Decode/Encode
  • JWT & JWE Debugger
  • JWK Generator
  • Password Hash Generator/Verifier
  • HMAC Signature Generator/Verifier
  • SAML Testing Tool
  • TOTP Authenticator
  • Passkey Demo & WebAuthn Tester
  • SMS Cost Calculator
  • company

  • About Us
  • Contact Sales
  • SkyMakers Digital
  • Our Promises
© 2026 Authgear. All rights reserved.
Terms·Acceptable Use Policy·Privacy·DPA·Sub-Processors·Security & Compliance·Enterprise Licenses·SLA·
  • English
  • 中文