Sub-processors
Last updated: July 10, 2026
Lounge & Co. does not sell or share your personal information for cross-context behavioral advertising. CCPA opt-out does not apply because no data flow matches the definition. Sub-processors (see public sub-processors list) receive data only for the disclosed business purpose under each sub-processor DPA.
Cal. Civ. Code §1798.120(a) does not attach because no Lounge & Co. data flow matches the §1798.140(ad) "sell" or §1798.140(ah) "share" definition; the CCPA Regs §7026 opt-out-request and Do-Not-Sell-or-Share-link operational requirements correspondingly do not apply. The static disclosure above makes that posture readable in lieu of a non-functional toggle.
Full posture rationale in BUSINESS_MODEL.md §0.9 (Do Not Sell or Share — static disclosure, no opt-out toggle).
Disclosed sub-processors
| Sub-processor | Purpose | Region | DPA effective | Vendor privacy policy |
|---|---|---|---|---|
| Token of Trust | 21+ age + identity verification at signup | US | www.tokenoftrust.com | |
| Anthropic | Concierge (Sterlon/Aurelle) — Claude Haiku model inference | US | www.anthropic.com | |
| Deepgram | Sterlon voice-input transcription (Nova-3); audio not persisted past transcription | US | deepgram.com | |
| Stripe | Subscription billing (Checkout, Tax, Customer Portal, Connect for venue payouts) | US | stripe.com | |
| Hive | Automated content moderation (image NSFW + harassment text classifiers, video visual + audio moderation, CSAM detection; covers member media + concierge-attached images + transcripts) | US | thehive.ai | |
| Better Stack | Observability — log aggregation + uptime monitoring; operational telemetry only, no Member content | EU (default; US-region custom location planned post-launch per ROADMAP N43) | betterstack.com | |
| Cloudflare | Turnstile bot-protection challenge at signup, password-reset request, and waitlist submission; the widget processes IP, request headers, and session cookies client-side, and the api forwards the user's IP to Cloudflare's siteverify endpoint server-side for token validation | US/global edge | www.cloudflare.com | |
| Resend | Transactional and venue-broadcast email delivery (verification, password reset, change confirmations, TOT handoff, OAuth-only reminder, arbitration opt-out confirmation, re-confirmation and email-preference management, and venue promotional broadcasts) | US | resend.com | |
| OAuth identity provider (Sign in with Google); receives sub, email, and optional profile name on authentication | US | policies.google.com | ||
| Apple | OAuth identity provider (Sign in with Apple); optional Hide-My-Email relay processes outbound transactional email when user elects private-relay | US | www.apple.com | |
| Cloudinary | Image and video transformation + CDN delivery of moderation-cleared member media (receives only bytes that passed the CSAM + content-moderation gates; never unscanned uploads) | US/global CDN | cloudinary.com |
References
- Privacy Policy §4 — full sub-processor table including platform-scope-only vendors (e.g. product analytics, error tracking) that fall outside the per-venue DPA contract.
- Member Terms of Service §11 — member acknowledgement of sub-processor use.
- Venue DPA — `DPA_VENUE_TEMPLATE.md` §5.1 (the per-venue contract that binds every vendor on this page).