Sub-processors
Last updated 1 September 2026
MetricScout uses the third-party providers below to process customer data on our behalf. We keep this list current and, as our data processing agreement requires, notify customers of material changes before a new sub-processor starts processing their data.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk | Authentication and organisation (agency) management | Account identifiers, email address, name | United States |
| Trigger.dev | Background job execution — crawls, PageSpeed, GA4/GSC sync, insight generation | Website URLs and assessment data in transit (holds no database credentials) | United States |
| Hostinger | Application and database hosting | All structured platform data stored in the database | European Union |
| OpenAI | AI rephrasing of insight wording (assist-only; never invents facts) | Insight text, which may include figures derived from connected data. Not used to train models (API data) | United States |
| Google (Analytics Data API, Search Console API, PageSpeed Insights) | Source of the marketing and performance data an agency connects | Read-only GA4 and Search Console metrics for the properties you connect | United States |
| Cloudflare (R2 object storage) | Storage of raw assessment artefacts (page HTML, PageSpeed JSON), retained 30 days | Crawled page snapshots and raw performance results | Distributed; no region pinned |
Google data and AI
Data obtained through Google APIs is handled in line with Google’s Limited Use requirements. Where insight wording is refined by OpenAI, only the text needed to phrase the insight is sent; OpenAI does not use data submitted via its API to train its models, and the AI is constrained so it can never introduce a figure, count, date or ranking that is not already in the underlying evidence. See our privacy policy for the full Google data disclosure.