Where your data can travel.
The short list of trusted third parties Marqee routes data through, updated 30 days before any change.
A sub-processor is a third-party company Marqee engages to help us run the service — a cloud host that holds the databases, a payments platform that tokenizes a card, a video-conferencing tool that carries a strategist call. In the language of the Marqee Data Processing Agreement, we are the processor acting on your instructions, and every sub-processor listed below sits one layer further down: they process your personal data on our behalf, only for the purpose we hire them for, and only under a contract that binds them to at least the same commitments we make to you.
Our stance is that the shorter this list is, the better we are doing our job. We use as few sub-processors as we can get away with, we prefer vendors with a defensible privacy posture and a public track record, and every one of them has a signed data processing agreement on file before a single record crosses. When a vendor cannot meet those bars, we either build the capability in-house or we do without it. This page is the public registry of the vendors that pass; it is refreshed whenever the list changes, and it is the single place you should look if you want the current answer.
01The registry
Every sub-processor Marqee currently routes personal data through, with the category we hired them for, the purpose they serve, the region of primary processing, and whether we have a signed DPA on file.
| Category | Provider | Purpose | Region | DPA on file |
|---|---|---|---|---|
| Cloud hosting | AWS | Runs marqee.com, the Marqee API, and the strategist Backstage — application servers, databases, and the platform's core compute layer. | us-east-1 + us-west-2 | Yes |
| File storage | AWS S3 | Encrypted object storage for résumés, generated materials, and any files a member uploads to their account. | us-east-1 | Yes |
| Transactional email | Postmark | Delivers member notifications, sign-in links, weekly readouts, and password resets — no marketing sends, no shared IP pools. | US | Yes |
| Calendar & video | Google Workspace | Interview scheduling and strategist meetings — calendar reads, meeting holds, and the Meet room used for briefings. | US | Yes |
| Video conferencing | Zoom | Strategist–member sessions and interview-prep calls where a member prefers Zoom over Meet. | US | Yes |
| Error reporting | Sentry | Crash and error diagnostics from the web app and the Marqee mobile app. Personal data in traces is scrubbed before capture. | US | Yes |
| Payments | Stripe | Tokenizes cards and runs weekly subscription billing plus one-time Sprint charges. Card numbers never reach Marqee servers. | US | Yes |
| Analytics | PostHog | First-party product analytics on member flows — aggregated where possible, never shared with advertisers, never sold. | US | Yes |
All rows current as of 2026-07-11. This page is the authoritative source; anything you read elsewhere that conflicts with the registry is stale.
Two design choices are worth calling out. First, the list is deliberately boring — every provider is one you can look up, read the security page of, and form your own opinion about. Second, several categories are covered by only one vendor. That is on purpose. Sub-processor sprawl is a leading indicator of a company that has stopped thinking about who touches its data.
A few categories that a reader might expect are intentionally absent. Marqee does not use a third-party customer-data platform, does not pipe personal data to an ad-tech vendor, and does not embed session-recording tools that capture what members type into their dashboard. If a vendor's business model centers on reselling the data that flows through it, we do not put it in the stack.
02Change policy & the thirty-day notice
How we tell you when this registry is about to change, how much notice you get, and what your options are if a change is not acceptable.
The single most important thing a sub-processor registry can promise is that it will not be quietly rewritten. We publish changes to this list on marqee.com/changelog at least thirty (30) days before they take effect. That includes adding a new sub-processor to a category, replacing a sub-processor within a category, and materially changing what an existing sub-processor is used for. A typo fix or a wording clarification is not a material change and does not trigger the thirty-day clock; adding a video-conferencing platform, moving analytics to a new provider, or shifting the primary hosting region does.
When the change window opens, controllers receive an email at the address on file — members through their account email, HR partners through their designated privacy contact, program partners through their partner-portal contact. The notice describes what is changing, why we are changing it, the new region if it differs, and the effective date on the other side of the thirty-day window. The changelog entry stays live even after the change goes into effect, so the history of who has touched the stack is auditable in one place.
Members can object to a change on data-protection grounds. To object, email privacy@marqee.com before the effective date with the change identifier from the changelog entry and a plain description of the concern. We will respond within five business days. Where the objection is well founded and we can work around the change for the member's account, we will; where the objection is well founded and we cannot, the member is entitled to cancel for cause with a prorated refund of unused fees.
Enterprise buyers — the HR partners, outplacement providers, and program sponsors procuring Marqee for a bench — can request a contractual addendum that pins the sub-processor list at a specific version, requires advance written approval for future changes in named categories, or restricts hosting to specific regions. Addenda are handled by the Marqee Data Protection lead and are attached to the master services agreement. Ask for one in the initial procurement conversation, or write to privacy@marqee.com after signature to have it added.
The short version: the registry changes rarely, and never quietly. Thirty days' notice, a public changelog entry, and a clear path to object or terminate if the change is unacceptable.
03How a vendor becomes a sub-processor
The internal bar a vendor has to clear before it appears on this page.
Adding a sub-processor is not a lightweight decision. Before a vendor is engaged, the internal review covers four things. Does the vendor have a public, up-to-date security page? Does the vendor sign an industry-standard DPA, including the Standard Contractual Clauses where applicable? Does the vendor's primary processing region match what our controllers are procuring us for, and if not, is the transfer mechanism clean? And finally: is there a smaller way to solve the same problem without adding a new sub-processor at all?
That last question is the one that has cut the list the most. When we do add a vendor, the review is documented internally, the DPA is countersigned before production access is granted, and the registry above is updated in the same pull request that ships the integration. There is no scenario in which a live vendor is missing from this page.
04What does not count as a sub-processor
A short list of relationships that a reader might reasonably wonder about, and why they are outside the scope of this registry.
- Marqee strategists and internal staff. Strategists are Marqee employees or contractors under written confidentiality and data-handling terms. They are not third parties, so they are not sub-processors — they are the team acting on your instructions.
- Public data sources. Job boards, company career pages, and public LinkedIn profiles that a strategist reads in the course of a search are not sub-processors of your personal data; they are external references we consult.
- Employers you are applying to. When a strategist submits a tailored application on your behalf, the target employer becomes a controller of the data you asked us to submit. That relationship is governed by the target employer's own privacy notice, not by ours.
- Recruiters your strategist contacts. A recruiter who receives an outreach message on your behalf is a recipient of the disclosure you authorized, not a sub-processor Marqee routes your data through in the ordinary course.
If any of those distinctions matter to your compliance posture, the DPA spells them out in more detail — particularly the roles and responsibilities section and the international transfers section, which covers the mechanism we rely on when data leaves a jurisdiction whose export controls require it.
05Request a DPA, an addendum, or a notification
One inbox, one human, and the specific things you can ask for.
Everything in this section is handled by the Marqee Data Protection lead through a single inbox: privacy@marqee.com. There is no ticket queue, no legal-hold form, and no automated router — a real person reads the email, opens the request, and answers within five business days. The requests we receive most often, and what to expect from each:
- A countersigned copy of the Marqee DPA. The default DPA is countersigned automatically when you accept the Terms of Service. If your organization requires a separately signed version on letterhead with your entity named as controller, we will return a signature-ready PDF within five business days of a verified request.
- A copy of an executed SCC template. For controllers established in the EEA, the United Kingdom, or Switzerland, we make our executed Standard Contractual Clauses template available on request. The UK Addendum and Swiss adjustments are included where relevant.
- Sub-processor change notifications by email. Any controller can opt in to receive the thirty-day notice email described above. Members are opted in by default; HR-partner and program-partner privacy contacts are added at engagement onboarding, and can be updated at any time.
- An enterprise addendum pinning the sub-processor list. Enterprise buyers can request a contractual addendum that pins the registry at a specific version, requires advance written approval for future changes in named categories, or restricts hosting to specific regions.
- A signed data-destruction certificate. When your engagement ends and the retention window has elapsed, we can issue a certificate signed by the Data Protection lead and countersigned by the security lead. See the termination section of the DPA for the retention timing.
Every request is logged internally, and every response is retained for the life of the engagement so the trail is auditable if a regulator or a member ever asks for it. If you write to privacy@marqee.com and do not hear back within five business days, that is a failure on our side and you should nudge us — the fault is almost certainly a stuck email, not a decision to ignore the request.
06Related reading
The other documents that sit next to this registry, in the order most readers want them.
- Data Processing Agreement. The controller/processor commitments this registry sits inside. Read this first if you are a corporate procurement team or an HR partner.
- Privacy Notice. The consumer-facing view — what data we collect, why we collect it, and the rights you can exercise as an individual.
- Security. The concrete technical and organizational controls Marqee operates today, at a level of detail useful to a security reviewer.
- Terms of Service. The master agreement the DPA and this registry sit underneath.
- Cookie policy. First-party analytics posture and what runs in the browser on marqee.com.
- Changelog. The public record of changes to the registry, the DPA, and other legal documents — thirty-day advance notices are posted here first.
Ask for a DPA, opt in to change notices, or request an addendum.
Every request in this section is handled by the Marqee Data Protection lead. Write to privacy@marqee.com from a verifiable address, name the request in the subject line, and expect a response from a real person within five business days.
Members are opted in to sub-processor change notices by default and receive them at the account email on file. HR-partner and program-partner privacy contacts are added at engagement onboarding — write in at any time to update the contact or opt in a new one.
Effective date: July 11, 2026. Last modified: July 11, 2026. Related legal documents: Terms of Service · Privacy Notice · DPA · Security · Cookie policy · Changelog. Report a concern about how your data is being routed: privacy@marqee.com.