# Subprocessors

Draft list of the third parties that process data for the ClarkCant Marketplace, and the external services it depends on.

> **Draft — requires legal review before production launch.** This text describes how the service works today. It is not final legal terms, and placeholders marked TO BE CONFIRMED still need an owner's decision.

## Subprocessors

| Provider | What they do for us | Data involved |
| --- | --- | --- |
| Cloudflare, Inc. | Hosting (Workers), database (D1), file storage (R2), background jobs (Queues, Workflows), request logs | All service data, including account data and request logs |
| GitHub, Inc. | Sign in with GitHub, only when GitHub sign-in is enabled | Your GitHub account id, profile and email, exchanged when you choose GitHub sign-in |

## Data sources (not subprocessors)

| Service | Use | Personal data sent |
| --- | --- | --- |
| npm registry (registry.npmjs.org) | Source of package metadata, tarballs and integrity digests for indexing | None; the marketplace fetches public package data |
| Cloudflare DNS over HTTPS (cloudflare-dns.com) | Looks up TXT records when a publisher verifies a domain | The domain name being verified |
| GitHub (raw.githubusercontent.com) | Reads a verification file when a publisher links a repository | The repository name |

## Loaded by your browser

Google Fonts serves the site's fonts and jsDelivr serves images referenced by package READMEs. Your browser requests them directly; see the [Privacy Policy](/privacy).

Changes to this list will be published here before a new subprocessor starts processing personal data. [TO BE CONFIRMED: notification channel for customers.]