Legal
Subprocessors
Last updated: July 13, 2026.
Exemption Ledger uses the third parties below to provide the Service, as described in our Data Processing Agreement. We will update this page before adding a new subprocessor that processes Customer Data.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Supabase | Database, authentication, file storage | All customer data, certificates, buyer records |
| Anthropic (Claude API) | Automated document parsing (Claude Vision) | Certificate images/PDFs at extraction time only — not used to train Anthropic's models |
| Cloudflare (R2) | Certificate file storage | Uploaded certificate files |
| Resend | Transactional email delivery | Buyer and user email addresses, email content (renewal chases, notifications) |
| Stripe | Payment processing, and (where connected) tax-exempt status sync | Billing data; for connected accounts, customer tax-exemption status |
| Vercel | Web application hosting | Session/request data, not certificate content |
| DigitalOcean | API and workflow-engine hosting | All customer data in transit and at rest on the API host |
Anthropic — additional disclosure
Exemption Ledger utilizes Anthropic, Inc. (via its commercial API) exclusively for automated text extraction from uploaded certificates. Under our commercial agreement with Anthropic, Customer Data is not used to train Anthropic's foundation AI models, and processing is strictly limited to extracting structured fields required for the Service.
Questions about this list or a specific subprocessor's data handling can be sent to legal@exemptionledger.com.