BestFoot

Last updated 8 September 2026

Service providers and subprocessors

BestFoot uses a small set of external services to operate the product. This page explains what each provider does, the information it may process, and where to find its current downstream provider list.

How to read this page

The providers below process personal information on BestFoot's behalf when their service is active. They may also process limited account, billing, security or support information for their own purposes under their privacy notices. In data-protection terminology, the direct provider is generally our processor and a provider it appoints is its subprocessor.

Provider legal entities and locations can depend on the BestFoot account, plan, selected region and user location. The links lead to each provider's maintained list. This disclosure describes ordinary product use and does not mean every downstream provider on those lists processes every BestFoot request.

Current providers

ProviderPurpose and informationPrimary location information
ClerkActiveAuthentication, account identity, session management and user lifecycle webhooks. Name, email address, Clerk identifiers, verification state, session and security data.Clerk account region and the locations in Clerk's current subprocessor list. Provider subprocessor information.
Amazon Web ServicesActiveAPI hosting, request security, temporary CV file storage, rate limiting and operational logs. API requests and responses, temporary source PDFs, pseudonymous rate-limit keys and limited operational records.Primary infrastructure in Ireland (AWS eu-west-1); support, edge and downstream processing may use other locations listed by AWS. Provider subprocessor information.
NeonActiveManaged PostgreSQL database hosting. Account, profile, career, CV draft, job, application and associated audit metadata stored by BestFoot.The selected Neon project region and locations used by Neon's current subprocessors. Provider subprocessor information.
OpenAIActiveCV extraction, achievement refinement, job analysis, matching, CV drafting and writing suggestions. The career, CV and job text needed for the AI feature the user invokes, plus generated output and request metadata.OpenAI infrastructure locations determined by the BestFoot API project configuration and OpenAI's current subprocessor list. Provider subprocessor information.
VercelActiveWeb application hosting, content delivery and privacy-focused product analytics. Web requests and technical metadata; page routes and allow-listed analytics events. Product analytics excludes CV, profile, job description, note, and contact text.Global content-delivery locations and the function, analytics and subprocessor locations configured or documented by Vercel. Provider subprocessor information.
SentryOptionalApplication error and performance monitoring when configured. Error messages, stack traces, routes, request identifiers and limited technical context; default PII collection is disabled.The selected Sentry data region and locations used by Sentry's current subprocessors. Provider subprocessor information.

International processing

BestFoot's API and temporary CV storage are deployed in the AWS Europe (Ireland) region. Other providers may process information in the United Kingdom, European Economic Area, United States or other locations listed on their pages. Where UK data-protection law requires a transfer safeguard, we use an applicable adequacy regulation or approved contractual mechanism and assess the provider's commitments.

Data minimisation and retention

Providers receive only the information needed for their role. BestFoot does not send CV, profile, job, note or contact text to product analytics. Original CV files are deleted from BestFoot's temporary storage after processing, with automatic expiry as a backstop. Provider-controlled security and service logs can follow separate schedules.

See the privacy policy, data retention policy and AI disclosure for more detail about purposes, storage periods and AI requests.

Changes and questions

We review this list when adding or changing a provider and at least once each year. Where reasonably practicable, we will update the list before a new provider begins processing user information and will communicate a material change where appropriate.

Questions or concerns can be sent to privacy@bestfoot.io.