Skip to content

Subprocessors

Last updated: June 20, 2026

This document is an MVP template. It must be reviewed and adapted by qualified legal counsel before MCP Store launches publicly. It is not legal advice.

1. About this list

To operate MCP Store we rely on a small set of trusted third-party service providers (“subprocessors”) that may process limited data on our behalf. Consistent with our data-minimization design, usage is metered as metadata only and we never share the payloads, prompts, or responses of your MCP calls with these providers. See our Privacy Policy for how we handle data overall.

2. Current subprocessors

ProviderPurposeData processedLocation
NeonManaged Postgres database (primary application data)Account, listing, subscription, and usage-event metadataUnited States / EU
CloudflareEdge hosting, Workers, R2 object storage, CDN, DDoS/WAFRequest metadata, served assets, IP addressesGlobal edge network
StripePayment processing and subscription billingBilling identifiers, subscription status, payment details (handled by Stripe)United States / Global
ResendTransactional email deliveryEmail address, message content for account/notification emailsUnited States
SentryError monitoring (when enabled)Redacted error/event metadata, request IDsUnited States
PostHogProduct analytics (when enabled)Aggregate, privacy-respecting product usage eventsUnited States / EU

Providers marked “when enabled” are activated only once the corresponding provider keys are configured; until then they process no data.

3. Developer endpoints are not subprocessors

When you connect through the gateway, your request is forwarded to the third-party developer’s registered endpoint. Those developers are independent operators, not our subprocessors; their handling of your request is governed by their own terms and privacy practices. Review a listing’s risk information before connecting.

4. Changes and notice

We may add or replace subprocessors as the service evolves. When we make a material change, we will update this page and revise the “Last updated” date above. Customers with a data processing agreement that provides for advance notice will be notified per that agreement.

5. Contact

Questions about our subprocessors or data processing can be sent to privacy@mcpstore.io.