Effective 23 August 2026
Service provider register
These companies receive data only for the listed Bidstage function. The configured payment provider receives checkout data; the other payment provider does not receive a new purchase.
Cloudflare
Cloudflare hosts the Worker and static assets, protects forms with Turnstile, answers destination DNS checks, routes support mail, and runs public URL scans. Cloudflare may process request metadata, security signals, support-routing metadata, and submitted public destination URLs.
Neon
Neon hosts PostgreSQL records for accounts, listings, payment references, public ledgers, contributor profiles, private applications, support, moderation, and operator audits. Bidstage connects through a restricted runtime role and Cloudflare Hyperdrive.
GitHub
GitHub supplies OAuth identity and public repository metadata. Bidstage requests no OAuth scopes and discards the OAuth access token after identity lookup. Visitors who open a repository use GitHub under GitHub's own terms.
Creem
Creem can act as the merchant-of-record payment provider selected for a deployment. Creem receives checkout, billing, tax, payment, refund, and dispute information and sends signed status events to Bidstage.
Dodo Payments
Dodo Payments can act as the merchant-of-record payment provider selected for a deployment. Dodo receives checkout, billing, tax, payment, refund, and dispute information and sends signed status events to Bidstage.
Direct funding services
GitHub Sponsors and Open Collective links are optional project links. Bidstage does not send placement-payment data to them. A visitor chooses whether to open the external service, whose own privacy terms then apply.
Questions: support@bidstage.app. Signed-in users can submit a privacy request from Account. Receipt holders can open a private support case from their receipt.