Sub-processors

Last updated: 20 July 2026

WeKeep engages the third-party service providers listed below ("sub-processors") to deliver the Service. Each sub-processor receives only the personal data it needs to perform its specific function, and we require each one by contract to protect that data consistently with our Privacy Policy and with applicable Indian law.

This page is the authoritative, current list of our sub-processors. Cross-border transfers — marked ⚑ Cross-border (US) or ⚑ Cross-border (EU) — involve processing outside India; those transfers are covered by the contractual protections described in Section 5 of our Privacy Policy. We will update this page whenever a sub-processor is added or removed.

Current sub-processors

Sub-processor Purpose Data location / Jurisdiction
DigitalOcean Compute, hosting, and file storage — the Service's application servers, primary database, and the documents you upload all live in DigitalOcean's Bangalore region India (BLR)
Cloudflare Content delivery and edge security — proxies and accelerates traffic to the Service, terminates TLS at its edge, provides DDoS/WAF protection, and serves the web app and marketing site as static assets Global edge — ⚑ Cross-border (US)
Razorpay Payment processing — subscription and billing payments India
Extend (CrowdView, Inc.) Document reading — when you or your Practitioner submit a document for processing, the original file (invoice, receipt, or bank statement) is sent to Extend to be read and its contents extracted. Extracted values are advisory and are shown to a Chartered Accountant for review before they are used ⚑ Cross-border (US)
Sentry Operational observability — redacted errors, logs, traces, metrics, scheduled-job monitoring, and uptime monitoring. It is not used for session replay or product analytics. ⚑ Cross-border (EU) for primary telemetry; cron check-ins are US-resident and uptime-check data is cross-region
Resend Email — transactional email (service notifications, invitations, and alerts) and receipt of documents you forward to your WeKeep intake address ⚑ Cross-border (US)
Google Sign-in with Google — where you choose to sign in with your Google account, Google confirms your identity to us. It receives no accounting or client data ⚑ Cross-border (US)
Sandbox Statutory filing and identity verification — submitting GST returns, e-invoices, e-way bills, income-tax returns, and TDS/TRACES requests on your behalf, and verifying GSTIN, PAN, Aadhaar, bank account, CIN, and DIN where you use those features India
Gridlines Identity verification — verifying TAN and Udyam registration where you use those features India
PostHog Product analytics and session replay — understanding how you use the Service (pages, features, and masked replays of your interactions) so we can improve it; your own usage only, never a Practitioner's client data ⚑ Cross-border (EU)

Questions

For questions about this list or our data-sharing practices, contact our Grievance Officer at support@wekeep.in (see the full contact details in Section 10 of our Privacy Policy).