Subprocessors
Last updated: September 8, 2026
A subprocessor is a third-party company that processes personal data on QuantRidge's behalf so that we can run the Service. Below is our list of them as of the date above — what each one does, what categories of data it can receive, where it processes them, and a link to its own privacy policy and terms.
QuantRidge is two things: the public marketing site at quantridge.net, and the signed-in application at app.quantridge.net. They have very different vendor surfaces, so each entry is labelled with where it applies. A tracker on the marketing site is not the same as a provider that can see your holdings — the labels let you tell them apart at a glance.
We publish this because a vague list is worse than none. We review and update this page periodically, and whenever our providers change. If you want the current position confirmed for a specific date, a specific provider, or a vendor-security review, write to support@quantridge.net and we will confirm in writing.
Reviewed & updated
Reviewed periodically and whenever providers change. Business customers under a DPA get 30 days' notice of a new subprocessor.
Right to object
Business customers under a DPA may object on reasonable data-protection grounds.
Contractually bound
Each provider is under written terms no less protective than our own commitments.
Account connections & financial data
Plaid
ApplicationPlaid Inc.
- Purpose
- Connects your bank and brokerage accounts read-only and retrieves balances, holdings, transactions and investment data so the platform can show them in one place.
- Data it can receive
- Account credentials entered in Plaid’s own secure flow (never seen by QuantRidge), account numbers in masked form, balances, holdings, transactions, and account metadata.
- Processing location
- United States
- Note
- You authorise the connection through Plaid’s own consent flow, and your credentials go to Plaid rather than to us. Connections are read-only: neither Plaid nor QuantRidge can move money or place trades through them. You can disconnect an account at any time.
SnapTrade
Application- Purpose
- Brokerage account connectivity for institutions Plaid does not cover, retrieving positions and activity read-only.
- Data it can receive
- Brokerage account identifiers, positions, balances and transaction history.
- Processing location
- United States and Canada
ATTOM Data
Application- Purpose
- Property and real-estate data used to value and model real estate you add to your plan.
- Data it can receive
- Property addresses you enter. No account or identity data is sent.
- Processing location
- United States
Authentication
Stack Auth
Application- Purpose
- Runs sign-up, sign-in, session management and multi-factor authentication for the application.
- Data it can receive
- Email address, name, hashed authentication credentials, session and device metadata, and MFA enrolment.
- Processing location
- United States
Google (OAuth & Drive)
ApplicationGoogle LLC
- Purpose
- Google sign-in, and — only if you connect them — Google Drive and Gmail integrations so you can bring documents and statements into the vault. Also Places and Maps lookups used to find service providers.
- Data it can receive
- Your Google account email and profile basics on sign-in. If you connect Drive or Gmail, the files and messages you explicitly authorise us to read. For Places and Maps, only the location or provider being searched.
- Processing location
- United States and other countries where Google operates
- Note
- Drive access is opt-in, scoped to what you authorise, and revocable from your Google account at any time.
Infrastructure & hosting
Supabase
Application- Purpose
- Managed Postgres and storage backing parts of the application.
- Data it can receive
- Account records and application data you create or upload.
- Processing location
- United States
Sentry
ApplicationFunctional Software, Inc.
- Purpose
- Application error and performance monitoring, so faults are caught and diagnosed.
- Data it can receive
- Error messages and stack traces, the URL and browser where an error occurred, and an account identifier to correlate reports.
- Processing location
- United States
Svix
Application- Purpose
- Delivers and verifies webhooks between QuantRidge and the services it integrates with.
- Data it can receive
- Event payloads and the account identifiers they reference.
- Processing location
- United States
Vercel
BothVercel Inc.
- Purpose
- Hosts quantridge.net, serves the site from its edge network, runs the site's serverless functions, and provides aggregate traffic analytics and page-performance measurement (Vercel Analytics and Speed Insights).
- Data it can receive
- IP address, request metadata, browser and device information, page URLs, page-load and performance timings, and anything submitted through a form on the site.
- Processing location
- United States (global edge network)
Render
BothRender Services, Inc.
- Purpose
- Hosts the QuantRidge application API and the managed PostgreSQL database backing sessions and application records.
- Data it can receive
- Account identifiers, authentication and session records, application data you create in the product, and server logs.
- Processing location
- United States
MongoDB Atlas
BothMongoDB, Inc.
- Purpose
- Managed database service storing account records and application data.
- Data it can receive
- Account information, product data you create or upload, and associated metadata.
- Processing location
- United States
Payments
Stripe
BothStripe, Inc.
- Purpose
- Subscription billing, payment processing, invoicing, and payment fraud prevention.
- Data it can receive
- Name, email address, billing address, subscription and transaction history, and partial card details.
- Processing location
- United States
- Note
- Full payment card numbers are submitted directly to Stripe and never reach QuantRidge systems. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy.
AI & machine learning
Anthropic
ApplicationAnthropic PBC
- Purpose
- Runs language models behind in-product AI agents and research features.
- Data it can receive
- The text of your request and the context the agent needs to answer it, which for portfolio questions can include holdings, transactions and tax-lot data from your own account.
- Processing location
- United States
- Note
- Data sent through the commercial API is not used to train models.
OpenAI
ApplicationOpenAI, L.L.C.
- Purpose
- Runs language models behind in-product AI agents and research features.
- Data it can receive
- The text of your request and the context the agent needs to answer it, which for portfolio questions can include your own account data.
- Processing location
- United States
- Note
- Data sent through the API is not used to train models by default.
Google Gemini
ApplicationGoogle LLC
- Purpose
- An additional language-model provider for in-product AI features.
- Data it can receive
- The text of your request and the context the agent needs to answer it.
- Processing location
- United States and other countries where Google operates
xAI
ApplicationX.AI LLC
- Purpose
- An additional language-model provider for in-product AI features.
- Data it can receive
- The text of your request and the context the agent needs to answer it.
- Processing location
- United States
Groq
BothGroq, Inc.
- Purpose
- Runs the language model behind the Ask QuantRidge assistant and the in-product support assistant.
- Data it can receive
- The text of the message you send to an assistant, plus the recent turns of that conversation.
- Processing location
- United States
- Note
- The assistants are grounded in published product documentation. No account records, portfolio data, customer lists, or source code are placed in the model context, and assistant conversations are not used to train any model.
Market, news & research data
Finnhub
Application- Purpose
- Market data, company fundamentals and news used in research and portfolio views.
- Data it can receive
- Security tickers being looked up. No account or identity data is sent.
- Processing location
- United States
Financial Modeling Prep
Application- Purpose
- Fundamentals, filings and valuation data used in research and modeling.
- Data it can receive
- Security tickers being looked up. No account or identity data is sent.
- Processing location
- United States
Exa
Application- Purpose
- Web search and retrieval powering the research engine and AI agents.
- Data it can receive
- The search query the agent runs. No account or identity data is sent.
- Processing location
- United States
Polygon.io
Application- Purpose
- Market data and financial news used in research and portfolio views.
- Data it can receive
- Security tickers being looked up. No account or identity data is sent.
- Processing location
- United States
Massive
Application- Purpose
- A news data provider feeding market and holdings-filtered news.
- Data it can receive
- The query or tickers being looked up. No account or identity data is sent.
- Processing location
- United States
Tavily
Application- Purpose
- An additional web-search provider for the research engine.
- Data it can receive
- The search query the agent runs. No account or identity data is sent.
- Processing location
- United States
Communications
Resend
Marketing site- Purpose
- Delivers transactional email — account verification, password resets, billing notices, and replies to messages you send us.
- Data it can receive
- Name, email address, and the contents of the message being sent.
- Processing location
- United States
Thunderbolt
Marketing site- Purpose
- Provides the customer-support chat widget embedded on the public site, and stores the conversations held through it.
- Data it can receive
- Anything you type into the chat widget, plus the name and email you give it, your IP address, and the page you started the chat from.
- Processing location
- United States
- Note
- The widget loads on every page of the public site. Please do not type account numbers, passwords, or government identifiers into a support chat.
Analytics & marketing
Google Analytics & Google Tag Manager
Marketing siteGoogle LLC
- Purpose
- Google Analytics measures marketing-site traffic and how visitors move through the public pages. Google Tag Manager (container GTM-P2VG7W9N) is the tag-management layer that loads and configures measurement tags on the site.
- Data it can receive
- Truncated IP address, cookie and device identifiers, pages viewed, referrer, and approximate location.
- Processing location
- United States and other countries where Google operates
- Note
- Runs on the public marketing site only, not inside the signed-in product. Tag Manager can load additional third-party tags depending on how the container is configured; we add any such tag that receives personal data to this list as part of our periodic review, and will confirm the current container contents on request.
Apollo.io
Marketing site- Purpose
- Website visitor analytics used to understand which organizations show interest in QuantRidge for business outreach.
- Data it can receive
- IP address, pages viewed, referrer, and business-firmographic inferences Apollo draws from them.
- Processing location
- United States
- Note
- Runs on the public marketing site only. This is the tracker most directly addressed by a Global Privacy Control signal — see Your Privacy Choices.
Changes to this list
We review this page periodically and update it when our providers change. For a new subprocessor that will process personal data, we publish the update at least 30 days before it begins processing, so business customers have time to object.
That advance notice does not apply where a provider has to be replaced urgently to keep the Service secure or available, where an existing provider stops operating, or where the change is a successor or affiliate of a current provider that does not materially change what data is processed or where. In those cases we post the change as soon as reasonably practicable instead. The full wording is clause 4 of the DPA.
List available on request. We can provide the current subprocessor list on request at any time — including for a vendor-security review, a due-diligence questionnaire, or an audit — and will confirm it in writing. Where a request is one we are not required to fulfil, we may decline it or provide the information in a summarised form; where it is unusually broad or repetitive, we may ask you to narrow it or agree reasonable confidentiality terms first.
We may change this list and these terms. QuantRidge may add, replace, or remove a subprocessor, and may modify, supplement, or discontinue any term, condition, or commitment described on this page, at any time and at our discretion. Changes take effect when posted here unless the change is one for which a notice period is stated above or required by law, in which case that notice applies instead. Nothing on this page is a guarantee that a particular provider will continue to be used, or that any arrangement described here will remain unchanged. Where you hold a signed order form or the DPA applies, that document governs where it conflicts with this page.
Business customers operating under our Data Processing Agreement may object to a new subprocessor on reasonable grounds relating to data protection by writing to support@quantridge.net within 30 days of the change being posted. We will work with you in good faith to address the objection; if we cannot, you may terminate the affected subscription without an early-termination penalty, effective at the end of the period you have already paid for. Fees already paid are not refunded, except where the law requires it. The full wording is clause 4 of the DPA.
To be notified by email whenever this list changes, write to support@quantridge.net with the subject "Subscribe to subprocessor updates".
QuantRidge does not sell personal information, and no provider on this list is permitted to use your data for its own purposes except where noted above. Links point to each provider's own current policies, which they control and may change. For how we use data ourselves, see the Privacy policy; for how it is protected, see Security.