Back to Privacy policy

Subprocessors

Last updated: September 8, 2026

A subprocessor is a third-party company that processes personal data on QuantRidge's behalf so that we can run the Service. Below is our list of them as of the date above — what each one does, what categories of data it can receive, where it processes them, and a link to its own privacy policy and terms.

QuantRidge is two things: the public marketing site at quantridge.net, and the signed-in application at app.quantridge.net. They have very different vendor surfaces, so each entry is labelled with where it applies. A tracker on the marketing site is not the same as a provider that can see your holdings — the labels let you tell them apart at a glance.

We publish this because a vague list is worse than none. We review and update this page periodically, and whenever our providers change. If you want the current position confirmed for a specific date, a specific provider, or a vendor-security review, write to support@quantridge.net and we will confirm in writing.

Reviewed & updated

Reviewed periodically and whenever providers change. Business customers under a DPA get 30 days' notice of a new subprocessor.

Right to object

Business customers under a DPA may object on reasonable data-protection grounds.

Contractually bound

Each provider is under written terms no less protective than our own commitments.

Account connections & financial data

Plaid

Application

Plaid Inc.

Purpose
Connects your bank and brokerage accounts read-only and retrieves balances, holdings, transactions and investment data so the platform can show them in one place.
Data it can receive
Account credentials entered in Plaid’s own secure flow (never seen by QuantRidge), account numbers in masked form, balances, holdings, transactions, and account metadata.
Processing location
United States
Note
You authorise the connection through Plaid’s own consent flow, and your credentials go to Plaid rather than to us. Connections are read-only: neither Plaid nor QuantRidge can move money or place trades through them. You can disconnect an account at any time.

SnapTrade

Application
Purpose
Brokerage account connectivity for institutions Plaid does not cover, retrieving positions and activity read-only.
Data it can receive
Brokerage account identifiers, positions, balances and transaction history.
Processing location
United States and Canada

ATTOM Data

Application
Purpose
Property and real-estate data used to value and model real estate you add to your plan.
Data it can receive
Property addresses you enter. No account or identity data is sent.
Processing location
United States

Authentication

Stack Auth

Application
Purpose
Runs sign-up, sign-in, session management and multi-factor authentication for the application.
Data it can receive
Email address, name, hashed authentication credentials, session and device metadata, and MFA enrolment.
Processing location
United States

Google (OAuth & Drive)

Application

Google LLC

Purpose
Google sign-in, and — only if you connect them — Google Drive and Gmail integrations so you can bring documents and statements into the vault. Also Places and Maps lookups used to find service providers.
Data it can receive
Your Google account email and profile basics on sign-in. If you connect Drive or Gmail, the files and messages you explicitly authorise us to read. For Places and Maps, only the location or provider being searched.
Processing location
United States and other countries where Google operates
Note
Drive access is opt-in, scoped to what you authorise, and revocable from your Google account at any time.

Infrastructure & hosting

Supabase

Application
Purpose
Managed Postgres and storage backing parts of the application.
Data it can receive
Account records and application data you create or upload.
Processing location
United States

Sentry

Application

Functional Software, Inc.

Purpose
Application error and performance monitoring, so faults are caught and diagnosed.
Data it can receive
Error messages and stack traces, the URL and browser where an error occurred, and an account identifier to correlate reports.
Processing location
United States

Svix

Application
Purpose
Delivers and verifies webhooks between QuantRidge and the services it integrates with.
Data it can receive
Event payloads and the account identifiers they reference.
Processing location
United States

Vercel

Both

Vercel Inc.

Purpose
Hosts quantridge.net, serves the site from its edge network, runs the site's serverless functions, and provides aggregate traffic analytics and page-performance measurement (Vercel Analytics and Speed Insights).
Data it can receive
IP address, request metadata, browser and device information, page URLs, page-load and performance timings, and anything submitted through a form on the site.
Processing location
United States (global edge network)

Render

Both

Render Services, Inc.

Purpose
Hosts the QuantRidge application API and the managed PostgreSQL database backing sessions and application records.
Data it can receive
Account identifiers, authentication and session records, application data you create in the product, and server logs.
Processing location
United States

MongoDB Atlas

Both

MongoDB, Inc.

Purpose
Managed database service storing account records and application data.
Data it can receive
Account information, product data you create or upload, and associated metadata.
Processing location
United States

Payments

Stripe

Both

Stripe, Inc.

Purpose
Subscription billing, payment processing, invoicing, and payment fraud prevention.
Data it can receive
Name, email address, billing address, subscription and transaction history, and partial card details.
Processing location
United States
Note
Full payment card numbers are submitted directly to Stripe and never reach QuantRidge systems. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy.

AI & machine learning

Anthropic

Application

Anthropic PBC

Purpose
Runs language models behind in-product AI agents and research features.
Data it can receive
The text of your request and the context the agent needs to answer it, which for portfolio questions can include holdings, transactions and tax-lot data from your own account.
Processing location
United States
Note
Data sent through the commercial API is not used to train models.

OpenAI

Application

OpenAI, L.L.C.

Purpose
Runs language models behind in-product AI agents and research features.
Data it can receive
The text of your request and the context the agent needs to answer it, which for portfolio questions can include your own account data.
Processing location
United States
Note
Data sent through the API is not used to train models by default.

Google Gemini

Application

Google LLC

Purpose
An additional language-model provider for in-product AI features.
Data it can receive
The text of your request and the context the agent needs to answer it.
Processing location
United States and other countries where Google operates

xAI

Application

X.AI LLC

Purpose
An additional language-model provider for in-product AI features.
Data it can receive
The text of your request and the context the agent needs to answer it.
Processing location
United States

Groq

Both

Groq, Inc.

Purpose
Runs the language model behind the Ask QuantRidge assistant and the in-product support assistant.
Data it can receive
The text of the message you send to an assistant, plus the recent turns of that conversation.
Processing location
United States
Note
The assistants are grounded in published product documentation. No account records, portfolio data, customer lists, or source code are placed in the model context, and assistant conversations are not used to train any model.

Market, news & research data

Finnhub

Application
Purpose
Market data, company fundamentals and news used in research and portfolio views.
Data it can receive
Security tickers being looked up. No account or identity data is sent.
Processing location
United States

Financial Modeling Prep

Application
Purpose
Fundamentals, filings and valuation data used in research and modeling.
Data it can receive
Security tickers being looked up. No account or identity data is sent.
Processing location
United States

Exa

Application
Purpose
Web search and retrieval powering the research engine and AI agents.
Data it can receive
The search query the agent runs. No account or identity data is sent.
Processing location
United States

Polygon.io

Application
Purpose
Market data and financial news used in research and portfolio views.
Data it can receive
Security tickers being looked up. No account or identity data is sent.
Processing location
United States

Massive

Application
Purpose
A news data provider feeding market and holdings-filtered news.
Data it can receive
The query or tickers being looked up. No account or identity data is sent.
Processing location
United States

Tavily

Application
Purpose
An additional web-search provider for the research engine.
Data it can receive
The search query the agent runs. No account or identity data is sent.
Processing location
United States

Communications

Resend

Marketing site
Purpose
Delivers transactional email — account verification, password resets, billing notices, and replies to messages you send us.
Data it can receive
Name, email address, and the contents of the message being sent.
Processing location
United States

Thunderbolt

Marketing site
Purpose
Provides the customer-support chat widget embedded on the public site, and stores the conversations held through it.
Data it can receive
Anything you type into the chat widget, plus the name and email you give it, your IP address, and the page you started the chat from.
Processing location
United States
Note
The widget loads on every page of the public site. Please do not type account numbers, passwords, or government identifiers into a support chat.

Analytics & marketing

Google Analytics & Google Tag Manager

Marketing site

Google LLC

Purpose
Google Analytics measures marketing-site traffic and how visitors move through the public pages. Google Tag Manager (container GTM-P2VG7W9N) is the tag-management layer that loads and configures measurement tags on the site.
Data it can receive
Truncated IP address, cookie and device identifiers, pages viewed, referrer, and approximate location.
Processing location
United States and other countries where Google operates
Note
Runs on the public marketing site only, not inside the signed-in product. Tag Manager can load additional third-party tags depending on how the container is configured; we add any such tag that receives personal data to this list as part of our periodic review, and will confirm the current container contents on request.

Apollo.io

Marketing site
Purpose
Website visitor analytics used to understand which organizations show interest in QuantRidge for business outreach.
Data it can receive
IP address, pages viewed, referrer, and business-firmographic inferences Apollo draws from them.
Processing location
United States
Note
Runs on the public marketing site only. This is the tracker most directly addressed by a Global Privacy Control signal — see Your Privacy Choices.

Changes to this list

We review this page periodically and update it when our providers change. For a new subprocessor that will process personal data, we publish the update at least 30 days before it begins processing, so business customers have time to object.

That advance notice does not apply where a provider has to be replaced urgently to keep the Service secure or available, where an existing provider stops operating, or where the change is a successor or affiliate of a current provider that does not materially change what data is processed or where. In those cases we post the change as soon as reasonably practicable instead. The full wording is clause 4 of the DPA.

List available on request. We can provide the current subprocessor list on request at any time — including for a vendor-security review, a due-diligence questionnaire, or an audit — and will confirm it in writing. Where a request is one we are not required to fulfil, we may decline it or provide the information in a summarised form; where it is unusually broad or repetitive, we may ask you to narrow it or agree reasonable confidentiality terms first.

We may change this list and these terms. QuantRidge may add, replace, or remove a subprocessor, and may modify, supplement, or discontinue any term, condition, or commitment described on this page, at any time and at our discretion. Changes take effect when posted here unless the change is one for which a notice period is stated above or required by law, in which case that notice applies instead. Nothing on this page is a guarantee that a particular provider will continue to be used, or that any arrangement described here will remain unchanged. Where you hold a signed order form or the DPA applies, that document governs where it conflicts with this page.

Business customers operating under our Data Processing Agreement may object to a new subprocessor on reasonable grounds relating to data protection by writing to support@quantridge.net within 30 days of the change being posted. We will work with you in good faith to address the objection; if we cannot, you may terminate the affected subscription without an early-termination penalty, effective at the end of the period you have already paid for. Fees already paid are not refunded, except where the law requires it. The full wording is clause 4 of the DPA.

To be notified by email whenever this list changes, write to support@quantridge.net with the subject "Subscribe to subprocessor updates".

QuantRidge does not sell personal information, and no provider on this list is permitted to use your data for its own purposes except where noted above. Links point to each provider's own current policies, which they control and may change. For how we use data ourselves, see the Privacy policy; for how it is protected, see Security.