These are the companies that handle data on our behalf so that Equipe can run. Each one is bound by a data processing agreement, each is used for one specific job, and none of them may use your data for anything else.
The short version: this is the whole list. Nobody else touches your data, and we post a change here before it happens.
Before a new subprocessor starts handling your data, we post it under changes below, with the date it takes effect. That posting is how we notify you, and you agreed to it in our Data Processing Agreement. If you object on reasonable data protection grounds, tell us and we will look for another way.
If you would rather be told than have to look, email info@equipe.com and we will add you to the list that gets an email whenever this page changes. Anyone can join, and you can leave whenever you like.
Infrastructure
| Company | What it does | Where |
|---|---|---|
| Heroku (Salesforce) | Hosting and databases | EU |
| Google Cloud Run | Hosting | EU |
| Amazon Web Services | S3 storage for show archives, and for the files uploaded to shows and competitions such as start lists, result lists and course designs | EU |
| Amazon CloudFront | Delivery of stylesheets, scripts and images. Sees visitor IP addresses, nothing else. | Global |
| Cloudflare | Our domain names, and delivery of images and uploaded files. Sees visitor IP addresses. | Global |
Communication and payments
| Company | What it does | Where |
|---|---|---|
| SendGrid (Twilio) | Sends transactional email | USA |
| Resend | Sends transactional email | USA |
| Stripe | Card payments in Equipe Entry | USA and EU |
| Digiteal | Payments and payment status in app.equipe.com | EU (Belgium) |
| Apple | Push notifications to iOS devices. Device tokens only. | USA |
| Google (Firebase Cloud Messaging) | Push notifications to Android devices. Device tokens only. | USA |
Error tracking
We use Honeybadger (USA) to tell us when something crashes. A crash report carries the data being handled at that moment, and the name and email address of whoever was signed in. We filter out passwords and keys, not personal details.
Changes
Every change to this list, with the date it takes effect. Newest first.
| Date | Change |
|---|---|
| 1 September 2026 | First published. Everything above was already in use on this date; nothing was added in order to publish the list. |
What is not on this list
A supplier only belongs here if it handles personal data on our behalf. Two kinds of thing therefore do not appear:
- Tools that never see personal data, such as the service that scales our servers from queue depth.
- Software we run ourselves. Our interface translation and our visitor statistics run on Equipe's own servers, so nothing reaches the companies whose software we use. Statistics are collected without cookies and without tracking anyone between sites.
Public authorities we check details against
When you enter a VAT number we verify it against the European Commission's VIES service, and against HMRC for United Kingdom numbers. We send the number and nothing else.
Not subprocessors
Two groups receive data from Equipe without acting on our instructions, so they do not belong on the list above:
- Federations. The FEI and national federations such as Svenska Ridsportförbundet, KNHS, ESNZ and FFE receive entries and results as controllers in their own right, under their own rules.
- Extensions you install. When you install an extension you appoint that developer yourself. What they do with the data is between you and them, under our extension terms.
Transfers outside the EU
Where a supplier above is established outside the EU and personal data reaches it, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, with an assessment of whether that is sufficient in practice.
Questions about any of this? Email info@equipe.com and a person will answer.