← Legal

MissionHand Sub-processor List

Serve by Design, LLC | Last Updated: July 1, 2026 | Version 1.0



About This List

This Sub-processor List identifies the third-party companies ("Sub-processors") that Serve by Design, LLC ("Serve by Design," "we," or "us") uses to deliver MissionHand. Each Sub-processor has access to certain Customer Data as necessary to perform the functions described below.

We have entered into (or require our Sub-processors to be bound by) data protection agreements that impose obligations on them consistent with our Data Processing Addendum.

We will update this list at least 30 days before adding or replacing a Sub-processor. We will post the updated list at this URL and send email notice to customers who have opted in to Sub-processor change notifications.


Current Sub-processors

#Sub-processorParent CompanyPurposeData Categories AccessedProcessing LocationSecurity/Compliance Info
1SupabaseSupabase, Inc.Database hosting, user authentication, and file storage. All Customer Data at rest resides in Supabase's managed PostgreSQL infrastructure. Row-level security controls implement tenant isolation.All Customer Data categories (donor records, beneficiary records, volunteer records, user accounts, file attachments)United States (AWS us-east-1)Supabase is SOC 2 Type II certified. Data is encrypted at rest and in transit. [supabase.com/security]
2VercelVercel, Inc.Application hosting and content delivery. Serves the MissionHand web application to customers' browsers. May process request metadata (IP addresses, usage logs) as requests flow through its infrastructure.Request metadata (IP addresses, session tokens, usage logs). Does not have direct persistent access to Customer Data stored in Supabase.United States (with global CDN edge caching; static assets only, not Personal Data, are cached at edge)Vercel maintains SOC 2 compliance. [vercel.com/security] Confirm whether Vercel edge caching could expose any Personal Data in transit. Verify current Vercel compliance documentation.
3ResendResend Technologies, Inc.Transactional and bulk email delivery. Used to send system-generated emails (notifications, confirmations, bulk communications) on behalf of nonprofit customers.Email addresses, email content generated by Customer or MissionHand system, and basic send/delivery metadataUnited StatesConfirm Resend's current compliance posture (SOC 2, etc.) and whether a formal DPA with Resend is in place. Resend is a newer provider; verify their data processing agreement is current and adequate.
4StripeStripe, Inc.Two separate purposes: (a) Processing nonprofit customers' subscription payments to Serve by Design; (b) Facilitating donation payment processing directly into nonprofit customers' own Stripe accounts. For (b), Stripe acts as a direct processor for the nonprofit, not as a sub-processor of Serve by Design.For (a): Billing contact name, email, payment card data (Stripe holds card data; Serve by Design receives only a tokenized reference). For (b): Stripe processes donor payment data directly in the nonprofit's own Stripe account; Serve by Design receives and stores only the completed transaction record (amount, date, donor reference).United States (with global processing capabilities)Stripe is PCI DSS Level 1 certified and SOC 2 Type II certified. [stripe.com/privacy]
5PayPalPayPal Holdings, Inc.Facilitating donation payment processing directly into nonprofit customers' own PayPal accounts. Similar to Stripe (b) above: PayPal acts as a direct processor for the nonprofit. Serve by Design receives and stores only the completed transaction record.Serve by Design receives only completed transaction metadata (amount, date, donor reference). Donor payment credentials are held by PayPal in the nonprofit's account, not by Serve by Design.United States (with global processing capabilities)PayPal is PCI DSS certified. [paypal.com/privacy]

Important Notes on Donation Payment Processing

For Stripe and PayPal donation processing (Sub-processors 4(b) and 5). Serve by Design is not a money transmitter and does not take custody of donor funds. When a donor makes a donation through MissionHand, the donation flows directly from the donor into the nonprofit's own Stripe or PayPal account. Serve by Design's role is limited to.

  1. Providing the interface through which the donor initiates the payment.
  2. Passing the transaction to the nonprofit's connected payment account; and
  3. Recording the completed transaction as data within MissionHand.

The nonprofit is responsible for its own compliance with Stripe's and PayPal's terms of service and with any applicable laws governing charitable solicitations, donation receipts, or financial record-keeping.


Sub-processor Change Policy

We will.

  1. Post an updated version of this list at https://missionhand.com/legal/subprocessors at least 30 days before adding, replacing, or removing a Sub-processor.
  2. Update the "Last Updated" date at the top of this document.
  3. Send email notice to customers who have opted in to Sub-processor change notifications (manage preferences in your account settings).

If you have questions about our Sub-processors, contact us at info@servecustom.com.