Sub-processors
Last updated: 5 September 2026
The third parties StoryJar relies on to run the service, what they do, and where data is held. We keep this list short by design.
Each sub-processor below operates under a data-processing agreement. We give schools prior notice before adding or changing a sub-processor.
| Sub-processor | Purpose | Personal data | Location |
|---|---|---|---|
| Railway | Application hosting, database and file storage | All service data (children's moments, staff/parent accounts) | EU West — Amsterdam, Netherlands (EEA), including backups |
| Stripe | Subscription billing & payment processing (Checkout, Customer Portal, invoicing) | Adult billing data only — the billing contact's name and email, or a school's name. No children's data is ever sent to Stripe. Card details are handled entirely by Stripe; StoryJar never sees or stores them. | Adult billing data only. The residency of Stripe's own billing processing is still being assessed, and we say so rather than imply an answer. |
| Mailjet (Sinch) | Transactional email — the sign-in link we send a parent, and staff notifications | Adult email addresses only — a parent's or staff member's address. No child's name, and no child's work, ever appears in an email: our messages are written so that if one reached the wrong person by a mistyped address, it would tell them nothing about any child. We cannot tell whether a particular parent opened an email, or whether they clicked the link in it. Open tracking and click tracking are switched off across the whole account, which covers every message we send, and switched off again on each individual message. Mailjet keeps a record of the messages it sent for us (who each one went to, when, the subject line, and whether it arrived) for 90 days on the plan we are on. Mailjet's published documentation does not say separately how long it holds the individual delivery events, or whether it holds a copy of the message itself, so we are not going to quote you a figure for those; getting that confirmed in writing is a recorded open item. What we can say is that a sign-in link works once and stops working after 30 minutes, so a stored copy would not be a lasting way into a family's account. | EU only (Google Cloud, EU data centres) |
| GitHub | Source-code hosting (no personal/customer data) | None (code only) | — |
Stripe & data residency: Stripe processes adult billing data only — never any personal data of children. The UK/EU-only requirement (rule 10) applies to children's and account-holders' personal data; the residency of Stripe's billing processing is recorded here as an open item for reviewbefore real payments are taken.
Where children's data is held: in the Netherlands (EU West, Amsterdam). Children's moments, photographs, voice recordings and all account data are stored and processed there, on a volume in the same region. Confirmed 15 August 2026, and the provider confirmed in writing on 5 September 2026 that volume backups are held in that same region. Every sub-processor that handles personal data must store and process it in the UK or EEA; this table is kept in step with reality, and a region change would be notified to schools in advance.
Being precise about “UK”: data is held in the EEA, not in the UK itself. Transfers from the UK to EEA countries are covered by the UK's adequacy regulations, so no additional transfer safeguard is required. Railway is a US-incorporated company, so its personnel may access systems for support from outside the EEA under its own data-processing terms. Obtaining and recording that provider's data-processing agreement and its onward-transfer terms is an open item on our side, and it is not yet done. We would rather state this plainly than let a school's data lead discover it later.
What we deliberately do not use
No analytics providers, no advertising networks, no social-media pixels, no behavioural-profiling services. Children are never tracked or profiled.