Sub-processors
Effective Date: September 4, 2026 | Last Updated: September 4, 2026
A sub-processor is a company that processes personal data on our behalf so that we can run the Revquix Platform - a payment gateway, an email provider, an error monitor. This page lists every one of them. It is the companion to our Privacy Policy, which explains what we collect and why; this page answers the separate question of who else touches it.
We keep it on its own page, with its own date, so that adding or removing a vendor is a change we can publish immediately rather than one that waits for the next revision of a longer document.
We do not sell personal data, and none of the companies below is permitted to use what it receives for its own purposes. Where a row says consent-gated, nothing is sent to that company at all until you opt in through our cookie preferences.
1. Current sub-processors
1.1 Payments
| Company | What it does for us | What it receives |
|---|---|---|
| Razorpay | Takes payments charged in Indian Rupees, and issues the refunds against them | The card / UPI / net-banking details you enter on its hosted checkout, the amount, and contact details for the receipt. We never see or store a full card number |
| PayPal | Takes payments charged in US Dollars, including purchases of tool credits, and issues the refunds against them | Your PayPal or card details on its own checkout, the amount, and the order and capture identifiers we store against your purchase |
1.2 Sign-in
| Company | What it does for us | What it receives |
|---|---|---|
| Google (Identity) | “Continue with Google”, and the one-tap prompt described in Privacy Policy §2.1 | Google knows you are on a Revquix page when the prompt loads. We receive your name, email address and profile picture back - never your Google password |
| GitHub | “Continue with GitHub” | Your name, username, email address and avatar |
| “Continue with LinkedIn” | Your name, email address and profile picture |
1.3 Sessions
| Company | What it does for us | What it receives |
|---|---|---|
| Google (Meet) | Hosts the meeting room each paid session takes place in. The room is created on a Google account Revquix owns - you authorise nothing and connect no account of your own | Whatever happens in the meeting, as it would for any Meet call, plus the attendance record we read back afterwards: display name, a participant identifier, and join and leave times. We request no Google Calendar scope and hold no calendar authorisation from anyone |
1.4 Storage, delivery and abuse protection
| Company | What it does for us | What it receives |
|---|---|---|
| Cloudflare | Stores uploaded files (R2), screens forms for bots (Turnstile), and serves the site (CDN and DNS) | Every file you upload - profile photo, resume, message attachment, project or canvas asset - and, for every request to the site, your IP address |
| Clearbit | Supplies the company and school logos shown next to work experience and education | Your browser requests the logo directly, so Clearbit sees your IP address and the domain of the company or school being displayed. It receives nothing else, and no Revquix account identifier. This happens on public profile pages as well as signed-in ones |
1.5 Email
| Company | What it does for us | What it receives |
|---|---|---|
| Zoho (ZeptoMail) | Delivers transactional email - sign-in codes, booking confirmations, receipts, security notices | Your name, email address, and the contents of the message being sent to you |
| Zoho Campaigns | Delivers the newsletter and other campaign email you have opted into | Your name, email address, and whether you opened or unsubscribed |
1.6 Artificial intelligence
| Company | What it does for us | What it receives |
|---|---|---|
| DeepSeek | Generates the written parts of our career tools and the explanations, reviews and suggested edits in the code assistant | Two different things, and the difference matters. Resume and job-description text is automatically redacted first - name, email, phone, postal address, date of birth and links become placeholders and each employer becomes a neutral label (Privacy Policy §2.10). Source code is not. When you ask the code assistant to explain, fix, review or document a file, that file is sent as written, so do not put passwords, API keys or other secrets in a file before pressing one of those buttons (Privacy Policy §2.12). Your Revquix account identifiers are never sent either way |
1.7 Analytics, diagnostics and advertising
Everything in this group is consent-gated: none of it loads, and none of it receives anything, until you opt into the matching category in cookie preferences.
| Company | What it does for us | What it receives |
|---|---|---|
| Google (Analytics 4) | Aggregate usage statistics | Pages visited and usage events, under Google Consent Mode v2 |
| Microsoft (Clarity) | Heatmaps and session replay, so we can see where a screen confuses people | Clicks, scrolls and navigation. We configure Clarity to mask text and form inputs |
| Sentry (Functional Software, Inc.) | Error monitoring, and a masked replay of the moments before an error | Error diagnostics and masked session data |
| Meta (Facebook / Instagram) | Advertising measurement and retargeting | Nothing at all unless you opt into the separate Advertising category, which is off by default |
1.8 Infrastructure
Revquix runs on servers we rent and administer ourselves from a cloud hosting provider. That provider does not use your data and cannot read our application data in the ordinary course, but it does host the machines the database and application run on, so we name the category here for completeness. Everything described in Section 2 runs on those machines.
2. What we run ourselves
Three things people reasonably assume are outsourced are not, and it changes who can see your data:
- Running your code. The Playground, Projects and the coding-problem judge execute your code in a sandboxed runner on our own servers. Your code is not sent to a third-party execution service. (Asking the AI assistant about your code is a separate act that does send it to DeepSeek - see §1.6 above.)
- Search that understands meaning. The model that turns profiles, mentors, services, documentation and your inferred interests into vectors for semantic search runs on our own infrastructure. No third-party AI provider receives that text.
- Your data at rest. The database, the cache and our application logs are ours, on the servers described in §1.8.
3. Services that receive no personal data
For completeness, because their absence from the list above is deliberate rather than an oversight: we fetch daily currency exchange rates from a public rates API. That request carries a three-letter currency code and nothing else - no account, no IP of yours, no identifier of any kind. It is not a sub-processor because it processes nothing about you.
4. International transfers
We operate from Pune, India. Several of the companies above process data outside India. Where we transfer EU/UK personal data internationally, we rely on appropriate safeguards such as the Standard Contractual Clauses. See Privacy Policy §5.
5. Changes to this list
We update this page when we add, remove or replace a sub-processor, and revise the “Last Updated” date above. Where a change materially affects how your data is handled, we will also say so in-product or by email, as our Privacy Policy requires.
6. Contact
Questions about anything on this page, including a request for more detail about a particular vendor relationship:
RevquixPune, Maharashtra, India
Email: [email protected]