Beehiiv Subprocessors List (October 2026): Changes and History
Beehiiv names 17 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Beehiiv subprocessors (October 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon | Cloud hosting | Washington, USA |
| 2 | E-Hawk | Fraud detection | New York, USA |
| 3 | Salesforce | Cloud hosting | California, USA |
| 4 | Sendgrid | Email service provider | Colorado, USA |
| 5 | Newrelic | Cloud monitoring | Georgia, USA |
| 6 | Cloudflare | CDN and web application firewall | California, USA |
| 7 | Crunchydata | Database hosting | South Carolina, USA |
| 8 | Sentry.io | Error reporting | California, USA |
| 9 | Stripe | Payment processing and identity verification | California, USA |
| 10 | Retool | Internal dashboards and tools | California, USA |
| 11 | Zendesk | Support ticket management | California, USA |
| 12 | Customer.io | Analytics and customer outreach | Oregon, USA |
| 13 | Kickbox | Email validation | New York, USA |
| 14 | IPQualityScore | Fraud detection | Nevada, USA |
| 15 | Tiptap | Collaborative text editor hosting | Berlin, Germany |
| 16 | Clickhouse Cloud | Database hosting | California, USA |
| 17 | Fullstory | Customer analytics | Georgia, USA |
Get an email when Beehiiv changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Beehiiv
What Beehiiv's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Within 72 hours
“informing Customer of a confirmed Personal Data Breach without undue delay and in any event within 72 hours of becoming aware”
DPA, www.beehiiv.com ↗ - Notice of a new subprocessor
-
15 days ahead
“beehiiv will notify Customer ("Subprocessor Notification") at least 15 days prior to giving the Subprocessor access to the Personal Data”
DPA, www.beehiiv.com ↗ - Transfers outside the EU
-
Standard contractual clauses
“the Standard Contractual Clauses form part of this DPA and take precedence over the rest of this DPA to the extent of any conflict”
DPA, www.beehiiv.com ↗ - Customer data after the contract ends
-
Deleted within 30 days of the contract ending
“beehiiv will destroy all Personal Data within 30 days after the termination of this Agreement except to the extent Applicable Law requires storage of the Personal Data.”
DPA, www.beehiiv.com ↗ - Audit rights
-
Once a year
“provided that Customer may not exercise this right more than once during any twelve (12) month period.”
DPA, www.beehiiv.com ↗
Certifications at Beehiiv
What Beehiiv's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?
- SOC 2 Type I
-
Active
“SOC 2 Type I Report”
Trust page, security.beehiiv.com ↗ - SOC 2 Type II
-
Active
“As of January, 22 2026, beehiiv has achieved SOC 2 Type 2 compliance.”
Trust page, security.beehiiv.com ↗
Documents we track for Beehiiv
- DPA
- checked September 30, 2026 www.beehiiv.com ↗
- Privacy policy
- checked September 30, 2026 www.beehiiv.com ↗
- Subprocessor list
- checked September 30, 2026 subprocessors.beehiiv.com ↗
- Terms of service
- checked September 30, 2026 security.beehiiv.com ↗
- Trust page
- checked September 30, 2026 security.beehiiv.com ↗
Change history
Tracking since September 30, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Beehiiv subprocessors FAQ
- How many subprocessors does Beehiiv use?
- Beehiiv lists 17 subprocessors on its published list, including Amazon, E-Hawk, Salesforce, Sendgrid, and Newrelic and 12 more.
- Where does Beehiiv process customer data?
- The subprocessors named by Beehiiv are located in USA, California, Georgia, New York, Berlin, and Colorado and 5 other locations, as stated on its list.
- How quickly does Beehiiv report a personal data breach to customers?
- According to its DPA, Beehiiv reports a personal data breach to customers within 72 hours: “informing Customer of a confirmed Personal Data Breach without undue delay and in any event within 72 hours of becoming aware”
- How much notice does Beehiiv give before adding a subprocessor?
- Beehiiv's DPA gives 15 days' notice of a new subprocessor, the time customers have to object: “beehiiv will notify Customer ("Subprocessor Notification") at least 15 days prior to giving the Subprocessor access to the Personal Data”
- How does Beehiiv transfer personal data outside the EU?
- Beehiiv's DPA relies on standard contractual clauses: “the Standard Contractual Clauses form part of this DPA and take precedence over the rest of this DPA to the extent of any conflict”
- Does Beehiiv have a SOC 2 Type II report?
- Yes. Beehiiv's trust page lists a SOC 2 Type II report: “As of January, 22 2026, beehiiv has achieved SOC 2 Type 2 compliance.”
- Which security certifications does Beehiiv list?
- Beehiiv's trust page lists SOC 2 Type I and SOC 2 Type II.
- When was Beehiiv's subprocessor list last checked?
- ClauseTrail last checked Beehiiv's subprocessor list on September 30, 2026. Lists are re-checked daily.
- How do I find out when Beehiiv adds or removes a subprocessor?
- ClauseTrail monitors Beehiiv's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.