Every company that can see data processed through ORIN is on this page. It is short, and the shortness is the point: each additional name is another organisation with access to a trading journal, so the list is kept to what the product genuinely cannot run without.
This register is generated from the same file the application reads, so it cannot quietly fall out of date with what is actually deployed.
01The current register
These are every third party that can see personal data processed through ORIN, what each one does, and the mechanism we rely on to transfer data to it from the EEA or the UK.
| Provider | What it does | What it can see | Where | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Hosted Postgres database and authentication. Stores your account, settings, analyses, journal, watchlist and event log. | Identifiers, credentials (hashed), risk settings, analysis records, journal, event log, technical logs. | The region selected for the project, with support operations in the United States and Singapore. | EU Standard Contractual Clauses and UK Addendum, under Supabase’s Data Processing Addendum. |
| Vercel | Application hosting, content delivery and serverless functions. Every request to ORIN passes through it. | Technical and log data — IP address, user agent, request path, timestamps. | United States, with edge delivery from points of presence worldwide. | EU Standard Contractual Clauses and UK Addendum, under Vercel’s Data Processing Addendum. |
| Anthropic | The language model that writes the prose explanation of an analysis the engine has already computed. | The analysis payload only — instrument, timeframe, computed evidence, levels and grade. No account identifier, no email, no journal, no name. | United States. | EU Standard Contractual Clauses. Prompts sent through the API are not used to train models. |
| StripeEngaged only if you subscribe to a paid plan. | Payment processing, subscription billing and renewal. | Identifiers, billing address, payment method details, transaction history. Stripe collects card data directly; it never reaches ORIN’s servers. | United States and Ireland. | EU Standard Contractual Clauses and UK Addendum. Stripe is certified under the EU–US Data Privacy Framework. |
| Microsoft (Clarity)Engaged only after you accept analytics. Declining, or sending a Global Privacy Control signal, means the script is never loaded and Microsoft receives no request. | Product analytics. Records how visitors move through the interface — clicks, scrolling, page transitions — as session replays and aggregate heatmaps, so we can find where the product confuses people. | Technical and behavioural data — IP address (from which Clarity derives approximate location), user agent, screen size, referrer, pages visited and interaction events. The signed-in desk is masked in our markup, so the journal, positions, account size and analyses are not transmitted. | United States. | EU Standard Contractual Clauses, under the Microsoft Products and Services Data Protection Addendum. |
| Twelve Data | Market data for stocks, ETFs, forex, indices and commodities. | None. Requests carry an instrument symbol and a timeframe. No user identifier is transmitted, so the vendor cannot associate a request with a person. | United States and European Union. | Not applicable — no personal data |
| Coinbase and Binance public endpoints | Cryptocurrency price data. Keyless public endpoints. | None. The request contains a trading pair and nothing else. | Global. | Not applicable — no personal data |
Two entries in this table process no personal data at all, and that is a design decision rather than an accident. Market-data requests carry an instrument symbol and a timeframe — never an account identifier — so those vendors are structurally incapable of building a picture of what any individual is watching.
The reasoning-model entry is worth reading closely too. What is sent is the computed analysis — instrument, timeframe, evidence, levels, grade — and not your name, your email, your account identifier, your journal or your position. The model is asked to describe an analysis, and it is given only the analysis.
02What each one is contractually bound to
Every provider on this register is engaged under a written data processing agreement requiring it to:
- process personal data only on our documented instructions;
- impose confidentiality obligations on personnel with access;
- implement appropriate technical and organisational security measures;
- engage its own sub-processors only under equivalent terms, and notify us of changes;
- assist us with data subject requests, breach notification and impact assessments;
- delete or return personal data at the end of the engagement;
- submit to audits and provide the information needed to demonstrate compliance.
We assess each provider before engaging it and rely on the transfer mechanism named in the table for personal data leaving the EEA or the UK. You can request a copy of the relevant safeguards from privacy@tryorin.xyz.
03Changes and objections
We update this page whenever the register changes. Where we add a provider that will process personal data, we will publish the change here at least 30 days before it takes effect.
If you are a business customer with a data processing agreement with us, you may object to a new sub-processor on reasonable data protection grounds within that 30-day window by writing to privacy@tryorin.xyz. If we cannot offer a reasonable alternative, you may terminate the affected subscription and we will refund the unused portion of any prepaid fee — one of the few circumstances in which the no-refund position in the Billing Policy gives way.
To be notified of changes automatically, email privacy@tryorin.xyz with the subject line “Subscribe: sub-processor changes”.
04What is not on this list
There is no advertising network, no data broker, no customer data platform, no marketing automation platform and no CRM on this register — because we use none of them. See the Cookie Policy for the browser-side equivalent of the same statement.
There is one analytics provider, Microsoft, listed above. This section previously said there was none, and that it applied to session recording tools in particular. That stopped being accurate when Clarity was added, so it was corrected in the same change rather than left to be discovered. Clarity is engaged only for visitors who accept it.
Our own email correspondence with you is handled by a standard business email provider. It sees the messages you choose to send us and nothing else, and it is not engaged to process product data.
Questions about this document go to legal@tryorin.xyz. The other documents in this set are listed here.