Providers and transfers outside Quebec
Every service provider that processes personal information, where it happens, and the assessment behind it.
1Why this page exists
Before communicating personal information outside Quebec, Law 25 requires the enterprise to conduct a privacy impact assessment, to establish through it that the information will receive adequate protection, and to record the result in a written agreement with the recipient. This page is the published summary of those assessments. Effective 9 August 2026.
It is here rather than in a filing cabinet for a plain reason: an assessment nobody can read is indistinguishable from an assessment nobody did. Where the GDPR applies, this page also serves as the list of processors we are required to make available.
2What is weighed in each assessment
- The sensitivity of the information. A delivery address and a password hash are not the same risk, and they do not get the same answer.
- The purpose it is used for, and whether the provider could use it for anything else. Every provider below is a processor: it acts on our instructions and may not use the information for its own purposes.
- The protection measures, including contractual ones. Encryption in transit and at rest, access control, retention limits, breach notification, and the data processing terms that form part of the provider agreement.
- The legal framework of the place it is processed, including whether a public authority there can compel disclosure and what recourse a person has.
An assessment concludes that a transfer may proceed only where the four together establish adequate protection. Where they do not, the answer is to not send the information, not to send it and hope.
3Where the platform runs
The application is deployed in a single region in the eastern United States, and the database and object storage sit alongside it. So the honest headline is this: most personal information on WIN is processed in the United States, not in Quebec, and the assessments below are what that rests on.
The United States has no general federal privacy law and no adequacy decision. That is the specific weakness every assessment below has to answer, and it is answered the same way each time: by minimising what leaves, by encrypting it, by contract, and by choosing providers whose terms bind them as processors with no right to use the information for themselves.
4Infrastructure
- Vercel
- Application hosting and edge routing, United States. Processes every request in transit, plus short-lived operational logs. Conclusion: proceed. The data is transient, the provider is a processor under its data processing terms, and no member record is stored there.
- Neon
- The PostgreSQL database, United States. This is the primary store: accounts, companies, content, orders. Sensitive fields are encrypted at the application layer with AES-256-GCM before they are written, so the provider holds ciphertext for those columns and never holds a key. Conclusion: proceed, on the strength of that plus the provider agreement.
- Amazon Web Services
- Object storage and content delivery for media, key management, and automated image moderation, United States. Holds uploaded images, video and files. Conclusion: proceed. Buckets are private, media is served through signed URLs, and moderation returns a verdict without retaining the image.
- Cloudflare
- Network edge and bot defence, globally distributed. Sees connection metadata, including your IP address, before a request reaches us. Conclusion: proceed. Nothing member-identifiable is sent to it by us, and the processing is what stops the platform being trivially attacked.
5Payments
- Stripe
- Payment processing and seller onboarding, United States and Ireland. Handles card details, which never reach our servers, and the identity and bank verification data a seller supplies to be paid out. Conclusion: proceed. It is the only way to accept a card at all, the provider is itself a regulated payment institution, and the alternative is holding card data ourselves, which would be worse for you in every respect.
6Communications
- Resend
- Transactional email, United States. Receives the recipient address and the message body of an account email: a verification code, a receipt, a notification. Conclusion: proceed, limited to transactional mail. We do not send member lists to it and we do not run marketing campaigns through it.
- Push services
- Web push notifications are delivered by the push service your own browser is registered with, operated by your browser vendor. It receives an anonymous endpoint token and the encrypted notification payload. Conclusion: proceed. The payload is encrypted end to end under keys the push service does not hold, and the transfer only exists because you enabled notifications.
7Operations
- Sentry
- Error monitoring, United States. Receives stack traces and technical context from a crash. Configured to send no personal information by default, and every event is filtered before it leaves: cookies, request headers, IP address and email are removed, request bodies are scrubbed, and session replay is off. Conclusion: proceed, on the strength of that filter rather than of the provider.
- Vercel Analytics
- Anonymous page counts, United States. Loaded only if you accepted analytics cookies; refused, the script is never injected. Conclusion: proceed, on consent.
- Discord
- Operational alerting to our own team, United States. Receives security and moderation alerts, which can contain a company name, an identifier, or an excerpt of reported content. Conclusion: proceed with minimisation. Alerts carry references rather than records, and the channel is restricted to the operators who act on them.
8What no provider gets
- No provider on this page receives personal information to use for its own purposes.
- We do not sell personal information and we do not share it with an advertising network. There is no advertising provider on this list because there is none in the product.
- The contents of private messages are not sent to any provider other than the storage and database that hold them for you.
- No provider is given a member list, and none is used to build an audience or a lookalike segment.
9When this changes
Adding a provider that processes personal information means running the assessment first, then updating this page. A change in category, rather than a like-for-like replacement, is announced in the same way a material change to the Privacy Policy is. If you rely on this list for your own compliance work and want to be told when it moves, write to [email protected].
The Privacy PolicyWhat is collected, why, and what you can do about it.