Subprocessors
Last Updated: August 4, 2026
This page lists the third parties that process personal information on Candle’s behalf, what each receives, and where it is located. It supports the Privacy Policy, the Japan Privacy Notice, and the State-Specific Privacy Disclosures.
Where a provider processes personal information on Candle’s behalf, Candle should maintain an appropriate written data-processing agreement addressing instructions, confidentiality, security, subprocessors, assistance with rights requests, incident notice, deletion or return, and international transfers. Inclusion on this page does not by itself establish that a provider is legally a processor rather than an independent controller.
Authentication and wallets
Section titled “Authentication and wallets”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Privy | Authentication, and creation and management of embedded Solana and EVM wallets | Email address, OAuth identifiers from Google and X, wallet addresses, account identifiers | USA |
Privy holds your email address and sign-in identity. Candle accesses it through Privy rather than storing it independently.
Infrastructure and hosting
Section titled “Infrastructure and hosting”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Convex | Application database — accounts, profiles, content, scores, activity | Account and profile data, wallet addresses, Wallet IQ scores, chat messages, stream metadata, OAuth tokens, activity records | USA |
| Vercel | Frontend hosting and content delivery | IP address, request metadata, device and browser information | USA, global edge network |
| Cloudflare | Live video ingest and delivery (Stream), and file storage (R2) | Stream and video content, thumbnails, uploads, IP address, viewer request metadata | USA, global edge network |
Blockchain infrastructure
Section titled “Blockchain infrastructure”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Helius | Solana RPC and transaction parsing | Wallet addresses, transaction signatures, IP address | USA |
| Robinhood Chain RPC | Robinhood Chain (Hood) node access | Wallet addresses, transaction data, IP address | USA |
Market and token data
Section titled “Market and token data”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Birdeye | Token market data, holder data, and search | Token addresses; wallet addresses where holder data is requested | USA |
| Jupiter | Swap quoting and routing on Solana | Wallet address, transaction parameters | Global |
Transaction routing
Section titled “Transaction routing”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Relay | Cross-chain bridging and routing | Wallet addresses on origin and destination chains, transaction amounts and parameters | Global |
| Meteora | Liquidity pools for graduated Solana tokens | On-chain transaction data | Decentralised protocol |
| Uniswap | Liquidity pools for graduated Hood tokens | On-chain transaction data | Decentralised protocol |
Meteora and Uniswap are permissionless on-chain protocols rather than service providers in the conventional sense. Candle does not transmit personal information to them; interacting with them writes data to a public blockchain.
Analytics
Section titled “Analytics”| Provider | Purpose | Data received | Location |
|---|---|---|---|
| Vercel Analytics | Aggregate usage and traffic analysis | Page views, referrer, approximate country, device type. Designed to operate without cookies and without personally identifying visitors. | USA |
Linked social platforms
Section titled “Linked social platforms”These are not subprocessors in the strict sense — they are services you choose to connect. When you link one, Candle receives and stores data from it, and may act on your behalf using stored access tokens.
| Provider | Role | Data involved |
|---|---|---|
| Sign-in | Email address, profile identifier | |
| X (Twitter) | Sign-in and account linking | Handle, profile photo, follower count, OAuth tokens |
| Discord | Account linking, community roles, stream announcements | Handle, server membership, OAuth tokens |
| Twitch | Account linking | Handle, follower count, OAuth tokens |
| YouTube | Account linking | Channel identity, subscriber count, OAuth tokens |
Each operates under its own privacy policy. Unlinking an account revokes the tokens Candle holds for it.
International transfers
Section titled “International transfers”Candle is based in the United States, and most listed providers are located there. Before transferring personal information from the EEA, UK, or Switzerland to a country without an applicable adequacy decision, Candle must confirm and document the transfer mechanism actually in place, such as the European Commission’s Standard Contractual Clauses and UK Addendum where appropriate. See International Data Transfers.
For the purposes of Japan’s APPI, the United States is not designated by the Personal Information Protection Commission as providing an equivalent standard of protection. See the Japan Privacy Notice.
Changes
Section titled “Changes”Candle updates this page when it adds, removes, or replaces a subprocessor. To be notified of changes, email privacy@candle.tv and ask to be added to the subprocessor notification list.
Questions: privacy@candle.tv