Subprocessors
Last updated: 22 August 2026
CheckinGuest uses the third party providers listed below to deliver the service. Each is engaged under a written data processing agreement and may process personal data on our instructions.
Where a new subprocessor is added, we notify customers at least 30 days before it begins processing personal data.
Infrastructure
Supabase
Database and file storage. All guest records, check-in data, messages and police submission confirmations are held here.
Data processed: guest identity details, consent records, messages, reservation data, police confirmation documents.
Location: European Union (Ireland).
Transfer basis: data remains in the EU. Supabase Pte. Ltd is registered in Singapore and its data processing agreement incorporates EU Standard Contractual Clauses for any transfer outside the EEA.
Agreement: supabase.com/legal/dpa
Vercel
Application hosting. Our software runs on Vercel's infrastructure.
Data processed: all personal data passes through Vercel's compute environment while a request is being handled. Vercel does not store guest data.
Location: Frankfurt, Germany (eu-central-1).
Transfer basis: processing takes place in the EU. Vercel Inc. is registered in the United States and its data processing agreement incorporates EU Standard Contractual Clauses.
Agreement: vercel.com/legal/dpa
Cloudflare
Secure network tunnel between our application and the machine that submits registrations to the Czech Foreign Police.
Data processed: guest registration data passes through an encrypted tunnel. Cloudflare does not store it.
Location: global network. Traffic for this service is routed via European points of presence.
Agreement: cloudflare.com/cloudflare-customer-dpa
Document reading and support
Anthropic
Two functions. First, reading the details from a photographed passport or identity document so the guest does not have to type them. Second, powering the assistant in the in-app support chat.
Data processed: the photographed document image and the details extracted from it. Separately, the text of support chat messages.
Location: United States.
Retention: Anthropic retains inputs and outputs for up to 30 days for safety and security monitoring, then deletes them. Data sent through the API is not used to train Anthropic's models.
Transfer basis: EU Standard Contractual Clauses, incorporated into Anthropic's Commercial Terms of Service.
Agreement: anthropic.com/legal/commercial-terms
We do not store the document image ourselves. It exists only in memory while the request is processed.
Communications and payments
Resend
Sending transactional email: booking confirmations, receipts, staff invitations, and internal operational alerts.
Data processed: recipient email addresses and the content of those emails, which may include a guest name or reservation reference.
Location: United States.
Transfer basis: certified under the EU-US Data Privacy Framework and the UK Extension.
Agreement: resend.com/legal/dpa
Stripe
Processing card payments for accommodation tax and any add-on purchases.
Data processed: payment card details, billing email address, transaction amounts. Card numbers are entered directly into Stripe and never reach our systems.
Location: United States, with EU processing infrastructure.
Transfer basis: EU Standard Contractual Clauses.
Agreement: stripe.com/legal/dpa
Property systems
Cloudbeds
Property management system. Where an operator uses Cloudbeds, we read reservation information from it so guests can find their booking.
Data processed: we receive guest name and stay dates. We do not send guest personal data to Cloudbeds.
Location: United States.
Where the operator is already a Cloudbeds customer, Cloudbeds is that operator's own processor under their existing agreement.
TTLock
Smart door locks, where a property uses them.
Data processed: door access codes and validity dates. No guest names or identity details are sent.
Location: servers in the European Union (EU developer platform).
Not a subprocessor
Registrations submitted through UbyPort go to the Czech Foreign Police because the law requires it. The police are an independent recipient acting under statutory powers, not a processor acting on our instructions.
What we do not use
We do not use analytics, advertising, tracking or session recording services. The guest check-in flow sets one cookie, which is strictly necessary to keep you signed in to your own check-in session.
Questions
Contact: info@pragueretreat.com