MapleDeploy uses the following third-party service providers (sub-processors) to deliver our service. Canadian providers are the default. Where no Canadian option does the job, we prefer a provider under an equivalent privacy framework, such as the EU. A few are in the United States. The location column shows where each provider is based, and the data column shows what it handles.
| Provider | Purpose | Location | Data processed |
|---|---|---|---|
| LunaNode | Virtual machine hosting (customer servers) | Canada | Customer application data, databases, server configurations |
| Cakemail | Transactional email delivery | Canada | Email address, name, email content |
| eazyBackup (EazyBackup Systems Ltd) | S3-compatible object storage for database backups | Canada (Ottawa, ON) | Database backup archives |
| Bunny.net | CDN and DNS services | Slovenia (EU) | DNS records, cached static assets |
| Mailbox.org | Business email hosting (support inbox) | Germany (EU) | Email address, name, support correspondence |
| Better Stack (Better Stack, Inc.) | Uptime monitoring, heartbeat monitoring, status page | United States (data stored in EU) | Server health check responses and heartbeat pings, and for a small number of servers a monitor label carrying the server subdomain. No application logs |
| Let's Encrypt (ISRG) | SSL/TLS certificate issuance | United States (nonprofit) | Domain names, server IP addresses |
| Stripe (Stripe, LLC) | Payment processing and subscription billing | United States | Name, email address, IP address, payment card details, billing address, transaction history |
| Google (Google LLC) | Optional sign in with Google | United States (company jurisdiction) | Only if you use it: your Google account identifier, email address, name, profile image |
| GitHub (GitHub, Inc.) | Optional sign in with GitHub | United States (company jurisdiction) | Only if you use it: your GitHub account identifier, email address, name, profile image |
| Microsoft (Microsoft Corporation) | Optional sign in with Microsoft | United States (company jurisdiction) | Only if you use it: your Microsoft account identifier, email address, name, profile image |
We offer Interac e-Transfer for customers who prefer a Canadian payment option. Learn more
Sign-in providers are optional
Google, GitHub, and Microsoft are contacted in three situations, all of which you start: choosing one of those sign-in buttons, connecting a provider from your account settings, and confirming your identity with Google before we open Coolify access for you. Signing in with a password or a passkey never involves them.
When you do use one, the provider learns that its account holder is signing in to MapleDeploy, and we receive the account identifier, email address, name, and profile image it returns. We request only each provider's standard sign-in permissions, we do not use them to read anything else from your account there, and we send no application data, server details, or billing information to any of the three. The location shown for these three is where the company is incorporated. Which of a provider's own data centers handles a given sign-in is set by that provider, not by us.
Cross-border transfers
The location column above shows where each provider is based, and where we know it, where it stores data. Where a provider is outside Canada, MapleDeploy stays accountable for the information under PIPEDA's accountability principle (Principle 4.1.3). Where a transfer involves personal information, we assess it as Quebec's Law 25 (s. 17) requires and keep the assessment in our internal compliance records. Where a provider offers a data processing agreement, we rely on it for confidentiality, security, and breach notification obligations. Where we hold no such agreement, as is the case for the optional sign-in providers, the provider's standard service terms govern.
Changes to this list
We will update this page when we add, remove, or change sub-processors. If you would like to be notified of changes, contact us at hello@mapledeploy.ca.