Service providers.
This register describes the website’s implemented services and planned production configuration. It distinguishes local software and inactive services from providers receiving visitor information.
DigitalOcean — hosting
Application hosting, self-managed PostgreSQL storage and the email queue are designed to run on DigitalOcean infrastructure. Stored data includes submitted interest details, optional phone numbers and SMS choices, consent records, referral attribution and access/security records. Broodex administers access to this infrastructure.
Configured hosting region: DigitalOcean NYC3 — New York, United States
Cloudflare — DNS and production proxy
Cloudflare manages the domain’s DNS. When its production proxy is enabled, it terminates visitor TLS connections and provides caching and security before forwarding requests to the application. It processes request metadata such as IP address, browser information, URL and security events, and carries submitted form and account requests through the proxy. The application marks sensitive responses against shared caching; the production proxy configuration must preserve that protection.
Processing uses Cloudflare’s delivery infrastructure; no dedicated regional-residency commitment is claimed for this project. Actual proxy, cache, logging and security settings determine its role. See Cloudflare privacy information.
Amazon Web Services — SES email
Amazon Simple Email Service delivers requested verification and sign-in emails, staff notifications and separately permitted project communications. It processes recipient addresses, message contents and delivery events. The application disables SES open and click tracking for these messages.
Configured SES region: us-east-1
Contact inboxes
Support, legal and privacy messages are processed through the provider configured for the role-based contact inboxes. Provider and locations: Google Workspace
CDN.MN — image delivery
CDN.MN, operated by NicNames, Inc. in the United States, is being configured to deliver the public website’s hero image. Private preview images continue to load from the application. When production delivery is enabled, CDN.MN receives image-request metadata such as the visitor’s IP address, browser information and image path. Interest-form answers and account records are not sent to the image CDN.
The service uses global delivery infrastructure; a fixed regional-residency commitment has not been established for this project. See privacy information and subprocessors. The deployment configuration determines whether image delivery is active.
MaxMind — local geolocation data
A locally installed GeoLite2 database can suggest a country from an IP address. The lookup does not send the visitor’s address to MaxMind or persist the raw IP in the registration. You can change the suggestion; the country you submit is saved. This product includes GeoLite2 data created by MaxMind, available from MaxMind.
Twilio — planned SMS service
Broodex currently collects optional phone numbers and separate permission for important-milestone texts, such as a future sales launch. It stores these in the application; no phone number or SMS consent record is currently sent to Twilio. SMS sending, phone verification and a registered project sender are not active. Email confirmation does not verify the phone number.
Twilio is the planned delivery provider. Before sending begins, the actual registered sender, supported destinations and working STOP/HELP controls will be disclosed. Intended worldwide availability remains subject to destination eligibility, carrier support and applicable requirements. See the Email and SMS Terms.
Other tools and safeguards
PostgreSQL, Caddy and the application run on the configured infrastructure; they are not separate recipients of visitor data. GitHub hosts source code and automated tests, not production lead records. No external CRM, analytics, advertising or session-replay service is installed.
Production regions, provider agreements, access locations, backup arrangements and any applicable transfer safeguards must be recorded for the deployed configuration. An advertised vendor certification does not establish a contract or certification for Broodex. Contact privacy@cybercabcollective.com for information about the processing of your data and applicable safeguards.