1. How to read this list
Each subprocessor below performs a specific, limited function for DonorCARE and is bound by a data-processing agreement or terms of service consistent with the obligations in our Data Processing Addendum. No subprocessor is authorised to use donor or donation data for its own purposes beyond providing its service to us.
2. Current subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Neon | Primary PostgreSQL database — stores account, donor, donation, receipt, and MyInvois submission records. | Managed cloud Postgres. See our Security & Compliance page for our current data-residency statement. |
| Railway | Hosts the DonorCARE backend API and its background jobs. | Managed cloud infrastructure. |
| Vercel | Hosts the DonorCARE admin dashboard and the donorcare.my marketing/donor-facing frontend. | Global edge network; frontend deployment configured for Singapore (sin1). |
| Cloudflare | Object storage (R2) for uploaded files and receipts, Workers for custom-domain routing, and CDN/DNS for donorcare.my and customer custom domains. | Global edge network. |
| SendGrid | Sends transactional email (receipts, notifications, password resets) and organisation-initiated email campaigns. | United States. |
| CHIP | Payment gateway — processes donation and subscription card/bank payments. Card and bank credentials are handled by CHIP directly and are never stored on DonorCARE's own servers. | Malaysia. |
| BizCARE (MyInvois API) | Submits, validates, and cancels e-invoices with the Inland Revenue Board (LHDN) MyInvois system, for organisations that have enabled e-invoicing. | Malaysia. |
| Anthropic | Powers the AI Copilot feature. Copilot reads are scoped to the requesting organisation; write actions require explicit human approval before execution. Prompts and data are not used by Anthropic to train models. | United States. |
| Voyage AI | Generates text embeddings used to power semantic search in the public NPO directory. | United States. |
| JomCARE (accounts.jom.care) | Federated sign-in for organisations that link their DonorCARE account to a JomCARE hub account, and hub-side billing for linked organisations. | Operated by a sibling CARE Business Apps service. |
3. This list can change
We add or remove subprocessors as the platform evolves — for example, when we change a hosting provider or add a new integration. This page is the notice mechanism: we update it before, or at the latest at, the point a new subprocessor begins processing data, and we do not maintain a separate notification list. If your organisation needs advance notice of subprocessor changes for its own compliance reasons, contact us to discuss what we can support.
4. Contact us
Questions about a specific subprocessor can be sent to [email protected].

