Concerto uses the following third-party subprocessors to deliver our service. This list is maintained by Archa Solutions, LLC and was last updated on August 19, 2026.
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Application and background worker hosting | All application data in transit and at rest | United States (us-west-2, Oregon) |
| PlanetScale | Managed PostgreSQL database | Account details, project and song metadata, comments, and other application records | United States (AWS us-west-2, Oregon) |
| Cloudflare (R2, Workers & Tunnel) | Object storage, edge delivery, and network ingress for our API | Audio files, attachments, user-uploaded content, and API requests in transit | United States |
| Vercel | Frontend hosting and CDN | Static assets, client-side application code | United States |
| Modal | GPU compute for AI stem separation | Audio files submitted for stem separation, accessed through short-lived presigned URLs | United States |
| Polar | Payment processing (Merchant of Record) | Billing information, subscription status | Sweden |
| OAuth authentication provider | Email address, name, profile photo (only when Google sign-in is used) | United States | |
| Resend | Transactional email delivery | Email addresses, user names, notification content | United States |
| Sentry | Error monitoring and performance tracking | Error logs, stack traces, anonymized user context | United States |
| Logfire (Pydantic) | Application observability and logging | Application logs, request metadata, system metrics | United States |
Concerto reserves the right to update this subprocessor list as our service evolves. We will notify users of any material changes via email or through the application.
If you have questions about our subprocessors or data processing practices, please contact us at info@archasolutions.com.