Transparency

Subprocessors & data location

Floatly uses the service providers below to run the platform. Each may process personal data on Floatly’s behalf under a data-processing agreement (Art. 28 GDPR). This page is the up-to-date list referenced by Floatly’s AVV (§3).

Subprocessors

ServicePurposeRegionTransfer
SupabaseDatabase, authentication and file storage (primary data store)EU (Ireland, eu-west-1)EU only
VercelApplication hosting, serverless compute and delivery (CDN)EU compute (Dublin, eu‑west‑1) · EU edgeSCC + EU‑US DPF
StripePayment processing (Stripe Connect)EU / USASCC + EU‑US DPF
ResendSending transactional email (tickets, receipts)EU / USASCC + EU‑US DPF
SentryError and performance monitoringEU / USASCC + EU‑US DPF
efstaFiscalisation / receipt signing (when enabled)EU (Austria)EU only

Data location

The primary data store (your account, bookings, guests and files) is hosted by Supabase in the EU region (Ireland, eu‑west‑1).

Application compute and hosting run on Vercel, with serverless functions executing in the EU (Dublin, eu‑west‑1)— co-located with the database — and static assets served from EU edge locations. Vercel, Stripe, Resend and Sentry are US-based companies, so any administrative access to, or transfer of, personal data outside the EU is covered by EU Standard Contractual Clauses (SCC) and, where applicable, the EU–US Data Privacy Framework (DPF).

Health declarations (Art. 9 GDPR), where a park enables them, are stored encrypted at rest.

Payments & merchant of record

Payments are processed through Stripe Connect as direct charges on the operator’s own connected Stripe account. The park operator is the seller and merchant of record towards the guest and is responsible for the sale, VAT, invoicing, refunds and consumer-law obligations.

Floatly provides the technical platform only, is not a party to the sale, and does not hold guest funds. Stripe acts as the payment processor.

Questions: support@floatly.app