CUECALLER

Subprocessors

Effective July 30, 2026 · Referenced by the Privacy Policy

Every third party that processes data on our behalf, what each one actually receives, and where it sits. This is the complete list. If you are doing vendor review for a production company or a venue, this page plus the Privacy Policy should answer most of your questionnaire; email [email protected] for anything else.

There are six, two of them optional, and one on its way out. CueCaller is deliberately built on a small stack. No advertising networks, no analytics vendors, no data brokers, no session-replay tools, no chat widgets, no CRM.

Always in use

ProviderWhat it doesWhat it receivesWhere
Cloudflare, Inc.
core
Hosting and CDN (Pages), database (D1), show-file storage (R2), machine translation (Workers AI), DNS, and aggregate traffic counts Everything the Service stores: account records, hashed passwords, sessions, plan state, cloud-saved show files, and standard request data including IP address. Cue text you choose to translate. United States, plus Cloudflare's global network. Data sits in the region nearest the request.
Stripe, Inc.
core
Payments, subscriptions, invoices, and the billing portal Your email, billing details, and card data, which you enter on Stripe's own hosted checkout. We receive back only a customer ID, a subscription ID, and status. We never see or store your card number. United States
Resend (Plus Five Five, Inc.)
core
Transactional email: password resets, account notices, renewal reminders, receipts, and the waitlist list Your email address and the content of those messages. Some announcement emails record opens and clicks so we know whether an important notice landed. United States
Google LLC
core
Google Workspace, which runs our own @cuecaller.app mailboxes Support email you send us and our replies. Nothing else. Our typefaces used to load from Google Fonts, which meant Google received every visitor's IP address; since 30 July 2026 they are served from our own servers and that request no longer happens. United States and Google's global network
Have I Been Pwned
core
Checks a new password against known breach corpora so we can refuse a compromised one The first five characters of a SHA-1 hash of the password, and nothing else. This is the k-anonymity range API: your password never leaves our server, and neither does the full hash. It cannot identify you. United Kingdom / Cloudflare network
Webflow, Inc.
core
Serves one image: the Visually Impressive Productions mark in the page header Your IP address and browser details when that image loads, on five marketing and sign-in pages. It sets no cookie. We are moving this image onto our own servers, after which Webflow drops off this list entirely. United States / global CDN

Only if you turn them on

ProviderWhat it doesWhat it receivesWhere
Google Sheets and Google Drive
optional
Reads a cue sheet you link, and writes cue edits back if you enable two-way sync Only what is needed to read and write the specific sheets you choose. We request the narrowest scope Google offers for this, so we cannot see the rest of your Drive. Your OAuth tokens are stored encrypted with AES-GCM and you can disconnect at any time from the app. United States and Google's global network
Cloudflare Workers AI
optional
Translates cue text when you switch on translated voice calls The cue strings you choose to translate. The result is cached in your browser and spoken from that cache, so the live show path makes no network call. Cloudflare states Workers AI inputs are not used to train models. Cloudflare's global network
YouTube (Google LLC)
optional
Hosts the explainer video embedded on our marketing page Nothing until you press play. The page shows a still panel with a play button that we draw ourselves and that makes no outside request. On click we load the player from youtube-nocookie.com, and from then on Google may set cookies and receive viewing data under its own privacy policy. It never appears inside the application. Google's global network

How transfers are covered

We are in the United States and so are most of our providers. Where personal data moves out of the UK, EU, or EEA, we rely on the Standard Contractual Clauses in each provider's data processing addendum, with the UK Addendum where relevant, and on the EU-U.S. Data Privacy Framework where a provider is certified to it. Each provider above publishes a DPA and a security page; we can point you at the current versions on request.

Changes to this list

If we add or replace a subprocessor that handles personal data, we will update this page before it goes live and note the change below. Customers with a signed agreement that requires advance notice will get it by email.

Contact

Visually Impressive Productions Corp
930 S 4th St, Ste 209
Las Vegas, NV 89101
[email protected]

← CueCallerTermsPrivacyRefunds & Cancellation
CueCaller · by Visually Impressive Productions · © 2026