Subprocessors
The third parties WinkPG engages to process personal data, what each one does and where it does it.
The WinkPG platform default. An operator may replace it with their own text. Last reviewed 20 September 2026.
How to read this list
Each entry is a third party that can reach personal data in the course of providing the service. Each is engaged under a written contract imposing data protection obligations no weaker than the ones in the data processing addendum.
The list describes a platform deployment the operator runs. An instance a customer hosts themselves may differ, and its operator publishes their own list on this page.
Payment processors appear as a category rather than as named entries, because which ones handle a merchant's transactions follows from that merchant's own acquiring relationship. Your boarding record names yours.
Changes
An addition or a replacement is published here before it takes effect, with enough notice for a customer to object on the terms their agreement sets. The review date at the top of the page moves when the list does.
Current subprocessors
| Subprocessor | Purpose | Data categories | Location |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, managed databases, storage, key management and messaging for the whole platform. | All data the platform processes, including cardholder data, merchant records and user accounts. | United States |
| New Relic | Application performance monitoring and error tracking. | Operational telemetry and diagnostic logs. Cardholder data and authentication secrets are redacted before they leave the platform. | United States |
| Payment processors and acquirers | Authorization, capture, settlement and refund of the transactions a merchant submits. Each merchant is boarded to the processors their own acquiring relationship names. | Cardholder data, transaction data and the billing details a transaction carries. | Determined by the merchant's acquiring relationship |
| Email and SMS delivery providers | Transactional notifications: receipts, invoices, security notices and one-time passcodes. | Recipient name, email address, phone number and the content of the notification. A full card number never appears in a notification. | United States |
Evidence and compliance materials
This surface states posture and publishes no evidence. The attestations, reports and control matrices behind these statements are in the trust documents catalogue, where a signed-in developer account can retrieve them and every retrieval is recorded.