Subprocessors and connected services

This register explains which providers may process information when Sandtime.io is used, why they are involved, and whether they are part of the core service or an optional connection.

This informational register supplements the Privacy Policy and customer agreements. It does not replace them.

Last updated August 18, 2026.

Material changes will be reflected on this page. For privacy or provider questions, contact sandtime@sandtime.io.

Providers required to operate Sandtime.io

These providers support hosting, delivery, security, service email, customer support, error monitoring, or product analytics.

OVHcloud

EU infrastructure hosting

Information involved: Workspace data, account data, uploaded media, application logs, and database backup archives.

When used: For production hosting and recovery infrastructure in the European Union.

Provider information and privacy terms

Cloudflare

Delivery, security, and abuse prevention

Information involved: IP addresses, request metadata, browser and device signals, TLS fingerprints, and Turnstile verification data.

When used: When accessing Sandtime.io services or using protected email sign-up and sign-in forms.

Provider information and privacy terms

Twilio SendGrid

Transactional and service email

Information involved: Recipient email address, sender information, delivery metadata, and the content of service or notification emails.

When used: When Sandtime.io sends sign-in messages, notifications, reminders, or other service emails.

Provider information and privacy terms

Chatwoot

Customer support chat

Information involved: Contact details, chat contents, technical metadata, and information voluntarily shared with support.

When used: When the support widget is loaded or a visitor starts a conversation with the Sandtime.io team.

Provider information and privacy terms

PostHog

Error monitoring and product analytics

Information involved: Error messages, the page or request involved, basic device and browser information, a pseudonymous session identifier, and interaction events like clicks and page views, excluding sensitive or free-text fields.

When used: Whenever our Sites or Apps encounter an error, or continuously for product analytics.

Where processed: PostHog Cloud's European Union region.

Provider information and privacy terms

Session recording and screen replay

Session recording and screen replay are not enabled while you use our product. We may use anonymous session recording or screen replay on non-sensitive marketing pages, to understand how visitors browse them. We may also use it on our sign-up and sign-in forms, to detect bots and other abuse. Outside of these cases, PostHog only measures interaction events such as clicks and page views, never the content of your work data; sensitive or free-text input fields are excluded from that measurement.

Consented analytics and affiliate attribution

These services measure website use or attribute a referred signup. Non-essential measurement follows the consent choices available on the site.

Google Analytics

Website and product analytics

Information involved: Pseudonymous identifiers, device and browser information, page views, interactions, and approximate location derived from network information.

When used: After the applicable analytics consent is available.

Provider information and privacy terms

N-CODE

Affiliate conversion attribution

Information involved: A pseudonymous referral identifier and conversion confirmation.

When used: When a visitor arrives through a participating affiliate link and later creates an account.

Authentication providers and optional integrations

These services are involved only when a user chooses the related sign-in method or connects the integration.

Apple

Optional account authentication

Information involved: Account identifier, email address, and name returned according to the user’s Apple privacy choices.

Provider information and privacy terms

Microsoft

Optional account authentication

Information involved: Account identifier, email address, name, profile image, and locale returned by the provider.

Provider information and privacy terms

Slack

Optional time tracking integration

Information involved: Slack workspace and user identifiers, authorization details, and time tracking commands sent through the integration.

When used: Only after an organization administrator connects Sandtime.io to Slack.

Provider information and privacy terms

Sandbot does not add an external AI provider

The model behind Sandbot runs on infrastructure operated by Sandtime.io. Messages and workspace context used to answer a request are not sent to a third-party AI provider and are not used to train a model.