Sub-processors
Last updated: 20 July 2026
WeKeep engages the third-party service providers listed below ("sub-processors") to deliver the Service. Each sub-processor receives only the personal data it needs to perform its specific function, and we require each one by contract to protect that data consistently with our Privacy Policy and with applicable Indian law.
This page is the authoritative, current list of our sub-processors. Cross-border transfers — marked ⚑ Cross-border (US) or ⚑ Cross-border (EU) — involve processing outside India; those transfers are covered by the contractual protections described in Section 5 of our Privacy Policy. We will update this page whenever a sub-processor is added or removed.
Current sub-processors
| Sub-processor | Purpose | Data location / Jurisdiction |
|---|---|---|
| DigitalOcean | Compute, hosting, and file storage — the Service's application servers, primary database, and the documents you upload all live in DigitalOcean's Bangalore region | India (BLR) |
| Cloudflare | Content delivery and edge security — proxies and accelerates traffic to the Service, terminates TLS at its edge, provides DDoS/WAF protection, and serves the web app and marketing site as static assets | Global edge — ⚑ Cross-border (US) |
| Razorpay | Payment processing — subscription and billing payments | India |
| Extend (CrowdView, Inc.) | Document reading — when you or your Practitioner submit a document for processing, the original file (invoice, receipt, or bank statement) is sent to Extend to be read and its contents extracted. Extracted values are advisory and are shown to a Chartered Accountant for review before they are used | ⚑ Cross-border (US) |
| Sentry | Operational observability — redacted errors, logs, traces, metrics, scheduled-job monitoring, and uptime monitoring. It is not used for session replay or product analytics. | ⚑ Cross-border (EU) for primary telemetry; cron check-ins are US-resident and uptime-check data is cross-region |
| Resend | Email — transactional email (service notifications, invitations, and alerts) and receipt of documents you forward to your WeKeep intake address | ⚑ Cross-border (US) |
| Sign-in with Google — where you choose to sign in with your Google account, Google confirms your identity to us. It receives no accounting or client data | ⚑ Cross-border (US) | |
| Sandbox | Statutory filing and identity verification — submitting GST returns, e-invoices, e-way bills, income-tax returns, and TDS/TRACES requests on your behalf, and verifying GSTIN, PAN, Aadhaar, bank account, CIN, and DIN where you use those features | India |
| Gridlines | Identity verification — verifying TAN and Udyam registration where you use those features | India |
| PostHog | Product analytics and session replay — understanding how you use the Service (pages, features, and masked replays of your interactions) so we can improve it; your own usage only, never a Practitioner's client data | ⚑ Cross-border (EU) |
Questions
For questions about this list or our data-sharing practices, contact our Grievance Officer at support@wekeep.in (see the full contact details in Section 10 of our Privacy Policy).