Subprocessors
Effective date:
AccessLint, LLC uses a small number of third party services to run AccessLint. This page lists every one of them that can receive personal data, what we use it for, and where it processes data. It is maintained from the code, so a service appears here because the product actually calls it.
Two audiences need this list. If you have an AccessLint account, these are the companies that can hold data about you. If you use AccessLint Flows to monitor your own site, AccessLint acts as a processor of your end users’ data, so the services below are our subprocessors and this is the list your own vendor review needs.
We add a service to this page before it starts receiving data, not after.
| Subprocessor | What we use it for | What it can receive | Region |
|---|---|---|---|
| Amazon Web Services | Object storage for Flow run screenshots, evidence crops, and page snapshots. | Images of the pages we test, which can include content shown to your end users, and any content visible on screen while a Flow is signed in. | United States |
| Amplitude | Product analytics and session replay on our marketing site and web app. | A pseudonymous account or device identifier, pages viewed, features used, your plan, and session replays of some pages. We do not send email addresses. On our marketing site in the EEA, the UK, and Switzerland this runs only after you accept analytics cookies. | United States |
| Anthropic | AI models used by Flows to interpret the journeys you write and to locate elements on the pages being tested. | The text of the journeys you write and content from the pages being tested. We do not send credentials, and Anthropic does not use this data to train its models. | United States |
| Better Stack | Log storage, uptime monitoring, and scheduled job heartbeats. | Application logs and error telemetry, which can include IP addresses and the hostnames of sites we test. Retained for 90 days. | European Union |
| Browserbase | Hosted browsers that run some Flows instead of a browser on our own servers. | The pages we load on your behalf, including anything your site shows to a signed-in test user. | United States |
| Cloudflare | Turnstile bot challenge on sign in and the free scanner, DNS resolution for the test runner, and delivery of one charting library on our benchmark pages. | Your IP address and browser signals when a challenge is shown, and the hostnames the runner resolves. | Global network |
| GitHub | Sign in, repository access for pull request reviews, Marketplace billing, and hosting for www.accesslint.com. | Your GitHub account identity and email address, and the contents of repositories you authorize us to read. | United States |
| The Continue with Google sign in option. | The sign in exchange itself. We ask for your Google account identifier and email address and nothing else, and we store no Google access token. | United States | |
| Heroku (Salesforce) | Hosting for our application servers, the primary database, the job queues, and the cache. | Everything stored in AccessLint, including your account, your domains and flows, and run results. | United States |
| Resend | Sending our email, and receiving mail at the test mailboxes (@accesslint.email) that Flows sign in through. | Recipient email addresses, message content, delivery events such as bounces and spam complaints, and mail delivered to a test mailbox. | United States |
| Sentry | Error tracking for the application and the test runner. | Exception types, messages, and stack traces. We turn off the SDK's personal data collection and strip request, user, and context data before an event is sent. | European Union |
| Stripe | Subscription payments, checkout, and the billing portal. | Your billing details and subscription history, and the name of your workspace. Card numbers are entered on Stripe's own checkout page and never reach our servers. | United States |
12 subprocessors.
What a Flow run sends out
A Flow is an automated test that loads pages on a site you have verified you control, signs in when you tell it to, and checks the result for accessibility problems. That work leaves our servers in three places, and each one can carry data about the people who use your site:
- The browser that loads your pages runs either on our own servers or on Browserbase.
- Screenshots and cropped images of the elements we flag are stored in Amazon S3. Runs you keep are retained until you delete them; the rest are pruned after seven days.
- Content from the page is sent to Anthropic so that a written step can be matched to the element it names. Credentials are never included.
International transfers
Most of the services above process data in the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the equivalent United Kingdom and Swiss addenda, as incorporated into each provider’s data processing agreement, or on the provider’s certification under the EU-U.S. Data Privacy Framework.
Changes to this list
We update this page when we add or remove a subprocessor. If you have an account and the change affects data we process on your behalf, we will notify the primary email address on the account. Check back here, or write to us at the address below to be told about future changes directly.
Questions
For a data processing agreement, or any question about this list, write to support@accesslint.com. See also our Privacy Policy and Terms of Service.