Subprocessors and connected services
This register explains which providers may process information when Sandtime.io is used, why they are involved, and whether they are part of the core service or an optional connection.
This informational register supplements the Privacy Policy and customer agreements. It does not replace them.
Last updated August 18, 2026.
Material changes will be reflected on this page. For privacy or provider questions, contact sandtime@sandtime.io.
Providers required to operate Sandtime.io
These providers support hosting, delivery, security, service email, customer support, error monitoring, or product analytics.
OVHcloud
EU infrastructure hostingInformation involved: Workspace data, account data, uploaded media, application logs, and database backup archives.
When used: For production hosting and recovery infrastructure in the European Union.
Cloudflare
Delivery, security, and abuse preventionInformation involved: IP addresses, request metadata, browser and device signals, TLS fingerprints, and Turnstile verification data.
When used: When accessing Sandtime.io services or using protected email sign-up and sign-in forms.
Twilio SendGrid
Transactional and service emailInformation involved: Recipient email address, sender information, delivery metadata, and the content of service or notification emails.
When used: When Sandtime.io sends sign-in messages, notifications, reminders, or other service emails.
Chatwoot
Customer support chatInformation involved: Contact details, chat contents, technical metadata, and information voluntarily shared with support.
When used: When the support widget is loaded or a visitor starts a conversation with the Sandtime.io team.
PostHog
Error monitoring and product analyticsInformation involved: Error messages, the page or request involved, basic device and browser information, a pseudonymous session identifier, and interaction events like clicks and page views, excluding sensitive or free-text fields.
When used: Whenever our Sites or Apps encounter an error, or continuously for product analytics.
Where processed: PostHog Cloud's European Union region.
Session recording and screen replay
Session recording and screen replay are not enabled while you use our product. We may use anonymous session recording or screen replay on non-sensitive marketing pages, to understand how visitors browse them. We may also use it on our sign-up and sign-in forms, to detect bots and other abuse. Outside of these cases, PostHog only measures interaction events such as clicks and page views, never the content of your work data; sensitive or free-text input fields are excluded from that measurement.
Consented analytics and affiliate attribution
These services measure website use or attribute a referred signup. Non-essential measurement follows the consent choices available on the site.
Google Analytics
Website and product analyticsInformation involved: Pseudonymous identifiers, device and browser information, page views, interactions, and approximate location derived from network information.
When used: After the applicable analytics consent is available.
N-CODE
Affiliate conversion attributionInformation involved: A pseudonymous referral identifier and conversion confirmation.
When used: When a visitor arrives through a participating affiliate link and later creates an account.
Authentication providers and optional integrations
These services are involved only when a user chooses the related sign-in method or connects the integration.
Information involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Apple
Optional account authenticationInformation involved: Account identifier, email address, and name returned according to the user’s Apple privacy choices.
Microsoft
Optional account authenticationInformation involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Yahoo
Optional account authenticationInformation involved: Account identifier, email address, name, profile image, and locale returned by the provider.
Slack
Optional time tracking integrationInformation involved: Slack workspace and user identifiers, authorization details, and time tracking commands sent through the integration.
When used: Only after an organization administrator connects Sandtime.io to Slack.
Sandbot does not add an external AI provider
The model behind Sandbot runs on infrastructure operated by Sandtime.io. Messages and workspace context used to answer a request are not sent to a third-party AI provider and are not used to train a model.