Subprocessors
Last updated: June 20, 2026
This document is an MVP template. It must be reviewed and adapted by qualified legal counsel before MCP Store launches publicly. It is not legal advice.
1. About this list
To operate MCP Store we rely on a small set of trusted third-party service providers (“subprocessors”) that may process limited data on our behalf. Consistent with our data-minimization design, usage is metered as metadata only and we never share the payloads, prompts, or responses of your MCP calls with these providers. See our Privacy Policy for how we handle data overall.
2. Current subprocessors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Neon | Managed Postgres database (primary application data) | Account, listing, subscription, and usage-event metadata | United States / EU |
| Cloudflare | Edge hosting, Workers, R2 object storage, CDN, DDoS/WAF | Request metadata, served assets, IP addresses | Global edge network |
| Stripe | Payment processing and subscription billing | Billing identifiers, subscription status, payment details (handled by Stripe) | United States / Global |
| Resend | Transactional email delivery | Email address, message content for account/notification emails | United States |
| Sentry | Error monitoring (when enabled) | Redacted error/event metadata, request IDs | United States |
| PostHog | Product analytics (when enabled) | Aggregate, privacy-respecting product usage events | United States / EU |
Providers marked “when enabled” are activated only once the corresponding provider keys are configured; until then they process no data.
3. Developer endpoints are not subprocessors
When you connect through the gateway, your request is forwarded to the third-party developer’s registered endpoint. Those developers are independent operators, not our subprocessors; their handling of your request is governed by their own terms and privacy practices. Review a listing’s risk information before connecting.
4. Changes and notice
We may add or replace subprocessors as the service evolves. When we make a material change, we will update this page and revise the “Last updated” date above. Customers with a data processing agreement that provides for advance notice will be notified per that agreement.
5. Contact
Questions about our subprocessors or data processing can be sent to privacy@mcpstore.io.