Transparency register
Subprocessors and connected services
This register explains which providers may process information when Sandtime.io is used, why they are involved, and whether they are part of the core service or an optional connection.
This informational register supplements the Privacy Policy and customer agreements. It does not replace them.
Last updated July 22, 2026.
Material changes will be reflected on this page. For privacy or provider questions, contact privacy@sandtime.io.
Core service delivery
Providers required to operate Sandtime.io
These providers support hosting, delivery, security, service email, or customer support.
OVHcloud
EU infrastructure hostingInformation involved: Workspace data, account data, uploaded media, application logs, and database backup archives.
When used: For production hosting and recovery infrastructure in the European Union.
Cloudflare
Delivery, security, and abuse preventionInformation involved: IP addresses, request metadata, browser and device signals, TLS fingerprints, and Turnstile verification data.
When used: When accessing Sandtime.io services or using protected email sign-up and sign-in forms.
Twilio SendGrid
Transactional and service emailInformation involved: Recipient email address, sender information, delivery metadata, and the content of service or notification emails.
When used: When Sandtime.io sends sign-in messages, notifications, reminders, or other service emails.
Chatwoot
Customer support chatInformation involved: Contact details, chat contents, technical metadata, and information voluntarily shared with support.
When used: When the support widget is loaded or a visitor starts a conversation with the Sandtime.io team.
Website measurement
Consented analytics and affiliate attribution
These services measure website use or attribute a referred signup. Non-essential measurement follows the consent choices available on the site.
Google Analytics
Website and product analyticsInformation involved: Pseudonymous identifiers, device and browser information, page views, interactions, and approximate location derived from network information.
When used: After the applicable analytics consent is available.
N-CODE
Affiliate conversion attributionInformation involved: A pseudonymous referral identifier and conversion confirmation.
When used: When a visitor arrives through a participating affiliate link and later creates an account.
User-chosen connections
Authentication providers and optional integrations
These services are involved only when a user chooses the related sign-in method or connects the integration.
Information involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Apple
Optional account authenticationInformation involved: Account identifier, email address, and name returned according to the user's Apple privacy choices.
Microsoft
Optional account authenticationInformation involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Yahoo
Optional account authenticationInformation involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Slack
Optional time tracking integrationInformation involved: Slack workspace and user identifiers, authorization details, and time tracking commands sent through the integration.
When used: Only after an organization administrator connects Sandtime.io to Slack.
Self-hosted AI
Sandbot does not add an external AI provider
The model behind Sandbot runs on infrastructure operated by Sandtime.io. Messages and workspace context used to answer a request are not sent to a third-party AI provider and are not used to train a model.