Last updated: August 2026
These are the companies we rely on to run Meritan. Each one receives only what its job needs. If you are evaluating us for a security review, this page plus the DPA and the security page is the set you are looking for.
| Company | What it does | What it receives | Where |
|---|---|---|---|
| Railway | Hosting and database storage | All application data, including interview recordings | EU (EU West region) |
| Polar | Payments, invoicing and sales tax, as merchant of record | Billing name, email, payment details, which they collect directly | US, SCCs |
| Resend | Transactional email, invites, verification, notifications | Recipient email address and message contents | US, EU sending region, SCCs |
| LiveKit | Screen sharing during live sessions, when used | Real-time audio and video in transit. Not recorded, not stored | US, SCCs |
| Google sign-in, only if a user chooses it | Account identifier and email of the signing-in user | US, SCCs | |
| jsDelivr / Cloudflare | Public CDN that serves the Python runtime to the browser | No account data. The browser’s IP address reaches the CDN, as with any web request | Global |
Before we add a sub-processor that handles customer or candidate data, we will update this page and email workspace owners at least 30 days in advance. If you object on reasonable data protection grounds within those 30 days, tell us and we will work with you on an alternative or, failing that, you may cancel for the unused part of your term.
Want the email? Write to founders@meritan.team with the address to add and we will put you on the list.