All policies

Sub-processors

Last updated: September 8, 2026

MapleDeploy uses the following third-party service providers (sub-processors) to deliver our service. Canadian providers are the default. Where no Canadian option does the job, we prefer a provider under an equivalent privacy framework, such as the EU. A few are in the United States. The location column shows where each provider is based, and the data column shows what it handles.

ProviderPurposeLocationData processed
LunaNodeVirtual machine hosting (customer servers)CanadaCustomer application data, databases, server configurations
CakemailTransactional email deliveryCanadaEmail address, name, email content
eazyBackup (EazyBackup Systems Ltd)S3-compatible object storage for database backupsCanada (Ottawa, ON)Database backup archives
Bunny.netCDN and DNS servicesSlovenia (EU)DNS records, cached static assets
Mailbox.orgBusiness email hosting (support inbox)Germany (EU)Email address, name, support correspondence
Better Stack (Better Stack, Inc.)Uptime monitoring, heartbeat monitoring, status pageUnited States (data stored in EU)Server health check responses and heartbeat pings, and for a small number of servers a monitor label carrying the server subdomain. No application logs
Let's Encrypt (ISRG)SSL/TLS certificate issuanceUnited States (nonprofit)Domain names, server IP addresses
Stripe (Stripe, LLC)Payment processing and subscription billingUnited StatesName, email address, IP address, payment card details, billing address, transaction history
Google (Google LLC)Optional sign in with GoogleUnited States (company jurisdiction)Only if you use it: your Google account identifier, email address, name, profile image
GitHub (GitHub, Inc.)Optional sign in with GitHubUnited States (company jurisdiction)Only if you use it: your GitHub account identifier, email address, name, profile image
Microsoft (Microsoft Corporation)Optional sign in with MicrosoftUnited States (company jurisdiction)Only if you use it: your Microsoft account identifier, email address, name, profile image

We offer Interac e-Transfer for customers who prefer a Canadian payment option. Learn more

Sign-in providers are optional

Google, GitHub, and Microsoft are contacted in three situations, all of which you start: choosing one of those sign-in buttons, connecting a provider from your account settings, and confirming your identity with Google before we open Coolify access for you. Signing in with a password or a passkey never involves them.

When you do use one, the provider learns that its account holder is signing in to MapleDeploy, and we receive the account identifier, email address, name, and profile image it returns. We request only each provider's standard sign-in permissions, we do not use them to read anything else from your account there, and we send no application data, server details, or billing information to any of the three. The location shown for these three is where the company is incorporated. Which of a provider's own data centers handles a given sign-in is set by that provider, not by us.

Cross-border transfers

The location column above shows where each provider is based, and where we know it, where it stores data. Where a provider is outside Canada, MapleDeploy stays accountable for the information under PIPEDA's accountability principle (Principle 4.1.3). Where a transfer involves personal information, we assess it as Quebec's Law 25 (s. 17) requires and keep the assessment in our internal compliance records. Where a provider offers a data processing agreement, we rely on it for confidentiality, security, and breach notification obligations. Where we hold no such agreement, as is the case for the optional sign-in providers, the provider's standard service terms govern.

Changes to this list

We will update this page when we add, remove, or change sub-processors. If you would like to be notified of changes, contact us at hello@mapledeploy.ca.