RetainerMeter / Legal / Subprocessors

Effective 15 August 2026

RetainerMeter Web subprocessors

Current service providers. RetainerMeter Web uses the providers listed below for the stated purposes. Provider processing locations and terms may change; RetainerMeter does not promise EU-only processing.
ProviderPurposeRelevant data boundary
CloudflareDNS/edge security, Worker application hosting, static assets, and D1 databaseWeb requests, account/workspace data, and necessary technical/security metadata; the customer database is configured in the EU
ResendEmail one-time codes, lifecycle/deletion notices, and user-directed invoice deliveryEmail address, message type/content, delivery status, and idempotency metadata. When a customer explicitly emails an invoice, saved recipients and the selected invoice PDF are also processed.
Lemon SqueezyMerchant of record, checkout, subscription/payment/refund processing, customer tax, and receiptsVerified email, Web account reference, transaction/subscription state, and payment/customer details supplied at checkout; no consultant workspace content

Change notice

RetainerMeter may add or replace a subprocessor where needed to operate Web. Where applicable law or the customer's data-processing agreement requires notice, RetainerMeter will provide reasonable advance notice and a way to raise a data-protection objection. The service boundary and privacy notice will be updated when the list changes.

Service boundary

Payment and essential service-email records remain separate from consultant workspace content. The narrow exception is a customer-confirmed invoice email, for which Resend processes the selected PDF and recipients to perform delivery. RetainerMeter does not add that PDF to a hosted invoice archive. The owner dashboard receives aggregates and content-free operational milestones, not client names, recipient addresses, notes, time entries, invoice text, attachments, or logos.