Legal centre

Subprocessors & Service Providers

Third parties FotoFit currently relies on to operate storage, delivery, integrations, rendering, and billing.

Effective August 18, 2026Last updated August 18, 2026

In plain language

  • A provider receives only the data needed for the service it performs.
  • Dodo Payments is the merchant of record and handles buyer payment data under its own terms, rather than acting only as FotoFit's processor.
  • Optional integrations process data only when you connect or configure them.

Core providers

Cloudflare

Purpose: R2 object storage, content delivery, DNS, and network security. Data may include uploaded assets, generated output files, storage object identifiers, IP addresses, and request metadata.

Email delivery providers

Purpose: transactional account email and, when a customer enables it, delivery of generated outputs to recipients. FotoFit currently supports Resend and configured SMTP delivery. Data may include recipient email address, subject, message content, attachments, and delivery events.

Infrastructure and database hosting

Purpose: run the FotoFit API, rendering workers, queues, database, monitoring, and backups. FotoFit may use managed cloud infrastructure or privately operated hosts for these functions. Data may include account, workspace, content, recipient, submission, generation, and technical records. We will name a hosting provider here when customer personal data is moved to a new third-party processor.

Optional and workflow providers

Google

Purpose: Google Picker, Drive, and Sheets access when a user connects Google Sheets; and cloud task or rendering infrastructure when deployed. Data may include the connected account identifier, encrypted OAuth token, selected spreadsheet metadata and values, and render-task metadata.

Customer-selected destinations

Purpose: send email, webhooks, files, or other output to an endpoint the customer configures. The receiving service is selected and controlled by the customer, and its handling is governed by the customer's agreement with that provider.

Payment provider acting independently

Dodo Payments

Purpose: merchant-of-record checkout, payment processing, invoices, taxes, fraud screening, refunds, and disputes. Dodo is the legal seller for the payment transaction and independently determines parts of this processing under its buyer terms and privacy policy. FotoFit receives payment and subscription metadata, not full card or bank-account details.

Updates and questions

We update this page when a material provider begins or stops processing customer personal data. Product libraries that run entirely in the user's browser and do not receive data as a service are not listed as subprocessors.

For procurement questions or a provider-specific objection, email hello@fotofit.in.