Privacy Center

Subprocessors

Third parties that process personal data on Bursa’s behalf.

Privacy Center

If the Indonesian and English versions conflict, the Indonesian version governs.

Effective: 4 August 2026

If the Indonesian and English versions differ, the Indonesian version governs.

Subprocessors are third parties that process personal data on Bursa’s behalf to run the platform. We do not sell your personal data.

Active and planned subprocessors

SubprocessorServiceData processedLocationStatus
Vercel Inc.App hosting, CDN, serverlessAccount data, access logs, request metadataUS (global edge)Active
Neon / PostgreSQL cloudDatabaseAccount, transaction, progress dataUS / EU (region-dependent)Active
Google LLCOAuth loginEmail, name, public profile photoUSActive
Midtrans / XenditPayment gatewayTransaction data, payment tokensIndonesiaPlanned
ResendTransactional and waitlist-lifecycle emailEmail, name (if available), topic preferences, delivery eventsUSActive
Cloudflare Email RoutingForwarding inbound @bursanalar.com to a monitored mailboxAddress, SMTP metadata, message body when forwardedGlobalActive (Path B2)
BrevoHuman outbound mail From @bursanalar.com (not waitlist blast)Address, outbound message bodyEU / globalPlanned — active after domain authentication
PostHogProduct analyticsPseudonymous/aggregate behaviourEU/USPlanned
Bunny.net / MuxVideo streaming CDNStreaming metadata, IPEU/USPlanned

Processing categories

Infrastructure

Vercel and the cloud database run the Bursa application. Data is stored encrypted with strict access control.

Authentication

Google OAuth processes optional login. We receive only email and the public profile — not other Google data.

Payments

The payment gateway processes transactions. Bursa does not store card numbers — all card data is handled by a PCI-DSS certified gateway.

Communications

Resend sends transactional notices (for example password reset) and waitlist lifecycle mail based on explicit consent. Opt-out, bounce, and complaint status are synced so later sends stop. Waitlist marketing email is managed separately from security and account-transaction email.

Human mailboxes (esakaisar@, support@, privacy@, security@) inbound via Cloudflare Email Routing to a monitored inbox, and outbound via authenticated SMTP (Brevo) so branded From addresses pass DMARC. This stream is separate from Resend.

Analytics

Analytics data is pseudonymised/aggregated to improve the product — not to sell individual profiles.

Subprocessor changes

We will update this list when we add or replace a subprocessor. Material changes will be notified by email or platform notification.

To object to a new subprocessor, contact privacy@bursanalar.com with subject “Subprocessor objection”.

Relation to the Trust Center

Subprocessor security controls: Trust Center — Security.