Sub-processors
Last updated 4 October 2026
Peoplume relies on the services below. Each has a narrow job, and two of them do nothing at all unless the employer supplies credentials for them. This list changes when the software does — see Privacy for what is stored in the first place.
Always used
| Service | Purpose | What it receives |
|---|---|---|
| Railway | Application hosting and the database volume. | Everything, as the host — this is where the application and its database run. |
| Cloudflare | DNS and reverse proxy in front of the application; R2 object storage holding every uploaded file and the off-site database backups; Web Analytics, a cookieless page-view counter injected into our public and application pages. | Page views and referrers from the analytics beacon — no cookie, no profile, no cross-site tracking. Requests in transit; every file uploaded to Peoplume — employment contracts, identity documents, expense receipts, candidate CVs, company policies and logos — and backup copies of the database. R2 encrypts what it stores at rest; we do not encrypt it ourselves before it is sent, so Cloudflare holds it in a form it could read. |
Push notifications — only for devices that turn them on
| Service | Purpose | What it receives |
|---|---|---|
| Google, Apple and Mozilla push services | Relay a notification to a phone or browser where the person turned notifications on for that device. Which one depends on the browser: Chrome and Android use Google's, Safari and iPhone use Apple's, Firefox uses Mozilla's. | An encrypted message they cannot read — the content is encrypted to the device's own key — and the fact that a message was sent to that device. No name, no employee data, no account identifier beyond the device's own subscription address. |
Payments
| Service | Purpose | What it receives |
|---|---|---|
| Paddle | Takes subscription payments as merchant of record, which means Paddle sells to you, charges any sales tax due where you are, and remits it. | Your billing contact details and payment method, which go to Paddle directly and never reach us — we hold only a subscription status, a seat count and Paddle's own identifiers. No employee data is sent. |
Optional — only if the employer enables them
| Service | Purpose | What it receives | If not configured |
|---|---|---|---|
| Resend | Delivers transactional email: notifications, invitations, password reset links, and messages to job candidates. | Recipient address and the message body. | No email is sent at all. Every notification still appears in the app. |
| Anthropic | Two optional features: reads an uploaded expense receipt and suggests the amount, date, currency and category; and answers questions asked of the AI assistant. | For receipts: only the receipt image, and only when an employee presses the button for that receipt. For the assistant: the question, and the rows looked up to answer it — which are only rows the asking person could already open in Peoplume — and only when an administrator has switched the assistant on for the company (it is off by default). Nothing is sent automatically, and no conversation is stored. | The receipt button is not shown and the assistant page says it is not set up. Employees type receipt details in themselves. |
Whatever the receipt reader returns is treated as a suggestion and re-validated on our side before it reaches a field — the amount must be a positive number, the date cannot be in the future, and the category must match our own list rather than whatever the model decided to call it. It fills in a form that a person still submits and an approver still approves. No amount reaches a payslip because a model read it.
The assistant is read-only by construction: it can call a fixed list of lookups, each of which runs the same permission and branch checks as the page for that data, and none of which can approve, file, pay or edit anything. It is not available during a free trial.
What is not here
There is no advertising or marketing pixel, no session-recording tool, no error-reporting service and no third-party chat widget. Nothing about your employees is sent anywhere for our own purposes.
Analytics is the one exception, and it used to be on this list. Cloudflare Web Analytics counts page views and referrers; it is cookieless, builds no profile and cannot follow anyone to another site. It is injected by Cloudflare at the edge rather than added in our code, which is why it went unlisted until a content security policy blocked it and made it visible. It sees pages, not people: no employee record, name or document is involved.
