Saplyn Subprocessor List
Last updated: August 9, 2026 · Mommalyn Inc. ("Saplyn")
Mommalyn Inc., a Delaware corporation ("Saplyn," "we"), uses the third-party subprocessors below to provide the Saplyn childcare-management platform (the "Service"). A subprocessor is a third party we engage that may process Customer Data (as defined in our Data Processing Addendum) on our behalf. Before engaging any subprocessor, we assess its security and confidentiality practices and bind it by contract to obligations no less protective than those in our DPA.
We will provide notice of new subprocessors as described in the DPA (§ 6) before giving a new subprocessor access to Customer Data.
Infrastructure subprocessors
These subprocessors may process any category of Customer Data, because they host or transmit the Service itself.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase, Inc. | Primary database (PostgreSQL) and file storage (photos, report media, message and document attachments) | All Customer Data at rest | United States |
| Vercel Inc. | Application hosting, serverless compute, and content delivery for the web application and API | All Customer Data in transit through the application | United States |
Functional subprocessors
These subprocessors receive only the data categories listed, only when the corresponding feature is used.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing: (a) Saplyn's subscription billing to Centers; (b) tuition, fees, and waitlist deposits collected by Centers from families via Stripe Connect | Payer name and email; payment method details (card / U.S. bank account, collected directly by Stripe — full card and bank numbers never reach Saplyn's servers); invoice and payment amounts; Center business and representative details for Connect onboarding (KYC) | United States |
| Resend, Inc. | Transactional email delivery: sign-in magic links, notification emails, invitations | Recipient name and email address; email content, which may reference children by name (e.g., daily-report and billing notifications) | United States |
| Expo (650 Industries, Inc.) | Mobile push-notification delivery for the Saplyn mobile app | Device push tokens; notification title/body, which may reference children by name; delivery receipts | United States |
| Anthropic, PBC | AI features: the in-app "Saplyn" assistant and the natural-language custom report builder | Prompts and the tenant data included as context for those prompts (e.g., report parameters, operational summaries). Sent via the Claude API, which does not use API inputs/outputs to train models by default | United States |
| OpenAI, LLC (see note below) | Speech-to-text transcription of staff voice observations dictated into daily reports | Short audio clips recorded by staff, which may mention children by name; resulting transcripts | United States |
| PostHog, Inc. | Product analytics and feature-flag delivery (web and mobile) | Pseudonymous user identifier, organization identifier, page/screen views, feature-usage events, device and browser metadata. Not child records. | United States (us.i.posthog.com) |
Not subprocessors (for clarity)
- Ubiquiti / UniFi camera systems. Centers may connect their own on-premises UniFi camera hardware. The cameras and recordings belong to and are operated by the Center; Saplyn relays snapshots on demand to the Center's authorized staff and stores the connection details the Center provides. Ubiquiti is the Center's vendor, not Saplyn's subprocessor.
- Apple Inc. / Google LLC act as conduits for push notifications delivered to iOS and Android devices via Expo, under their platform terms.
- Utah Department of Workforce Services. Saplyn's public "Discover" directory is compiled from Utah DWS public childcare-licensing records. This is public government data about licensed providers, not Customer Data.
Note on transcription: the transcription integration is OpenAI-API-compatible and may be repointed to an alternative provider (e.g., Groq, Inc.). If that is done in production, this list must be updated before the change takes effect.