Every third party that processes data on our behalf, what each one actually receives, and where it sits. This is the complete list. If you are doing vendor review for a production company or a venue, this page plus the Privacy Policy should answer most of your questionnaire; email [email protected] for anything else.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Cloudflare, Inc. core |
Hosting and CDN (Pages), database (D1), show-file storage (R2), machine translation (Workers AI), DNS, and aggregate traffic counts | Everything the Service stores: account records, hashed passwords, sessions, plan state, cloud-saved show files, and standard request data including IP address. Cue text you choose to translate. | United States, plus Cloudflare's global network. Data sits in the region nearest the request. |
| Stripe, Inc. core |
Payments, subscriptions, invoices, and the billing portal | Your email, billing details, and card data, which you enter on Stripe's own hosted checkout. We receive back only a customer ID, a subscription ID, and status. We never see or store your card number. | United States |
| Resend (Plus Five Five, Inc.) core |
Transactional email: password resets, account notices, renewal reminders, receipts, and the waitlist list | Your email address and the content of those messages. Some announcement emails record opens and clicks so we know whether an important notice landed. | United States |
| Google LLC core |
Google Workspace, which runs our own @cuecaller.app mailboxes |
Support email you send us and our replies. Nothing else. Our typefaces used to load from Google Fonts, which meant Google received every visitor's IP address; since 30 July 2026 they are served from our own servers and that request no longer happens. | United States and Google's global network |
| Have I Been Pwned core |
Checks a new password against known breach corpora so we can refuse a compromised one | The first five characters of a SHA-1 hash of the password, and nothing else. This is the k-anonymity range API: your password never leaves our server, and neither does the full hash. It cannot identify you. | United Kingdom / Cloudflare network |
| Webflow, Inc. core |
Serves one image: the Visually Impressive Productions mark in the page header | Your IP address and browser details when that image loads, on five marketing and sign-in pages. It sets no cookie. We are moving this image onto our own servers, after which Webflow drops off this list entirely. | United States / global CDN |
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Google Sheets and Google Drive optional |
Reads a cue sheet you link, and writes cue edits back if you enable two-way sync | Only what is needed to read and write the specific sheets you choose. We request the narrowest scope Google offers for this, so we cannot see the rest of your Drive. Your OAuth tokens are stored encrypted with AES-GCM and you can disconnect at any time from the app. | United States and Google's global network |
| Cloudflare Workers AI optional |
Translates cue text when you switch on translated voice calls | The cue strings you choose to translate. The result is cached in your browser and spoken from that cache, so the live show path makes no network call. Cloudflare states Workers AI inputs are not used to train models. | Cloudflare's global network |
| YouTube (Google LLC) optional |
Hosts the explainer video embedded on our marketing page | Nothing until you press play. The page shows a still panel with a play button that we draw ourselves and that makes no outside request. On click we load the player from youtube-nocookie.com, and from then on Google may set cookies and receive viewing data under its own privacy policy. It never appears inside the application. |
Google's global network |
We are in the United States and so are most of our providers. Where personal data moves out of the UK, EU, or EEA, we rely on the Standard Contractual Clauses in each provider's data processing addendum, with the UK Addendum where relevant, and on the EU-U.S. Data Privacy Framework where a provider is certified to it. Each provider above publishes a DPA and a security page; we can point you at the current versions on request.
If we add or replace a subprocessor that handles personal data, we will update this page before it goes live and note the change below. Customers with a signed agreement that requires advance notice will get it by email.
Visually Impressive Productions Corp
930 S 4th St, Ste 209
Las Vegas, NV 89101
[email protected]