Subprocessors

Last Updated: May 2026

MergeLoom uses a limited set of vetted providers to operate the website, controller, billing, support, email, analytics, advertising measurement, Cloud Hosted AI execution, and scheduling. This page lists always-on MergeLoom-operated providers and the customer-enabled integrations that a customer may connect themselves.

01.How We Engage Subprocessors

Subprocessors are engaged only where necessary to deliver the service. Each is subject to due diligence and contractual obligations consistent with applicable data protection laws. We provide notice of material changes through our standard channels and welcome subscription notification requests at support@mergeloom.ai.

02.Always-On / MergeLoom-Operated Providers

Provider Purpose Data Processed Applies To Notes
Anthropic PBC Current AI model provider for MergeLoom Cloud Hosted execution, used through MergeLoom for Cloud Hosted AI coding runs. Prompts and run instructions; ticket and work item content needed for the run; repository context and selected code snippets needed for the run; Context Engine and context-pack material when used; AI inputs and outputs; usage and cost metadata. Cloud Hosted execution. Not used by MergeLoom for Self Hosted unless the customer configures Anthropic themselves. Cloud Hosted uses Anthropic through MergeLoom today. MergeLoom does not allow training of foundation models on customer source code.
Stripe, Inc. Payment processing, card verification, subscriptions, invoices, paid plan billing, AI credit bundle purchases, and refund and dispute handling. Billing contact details; payment method metadata; transaction records; invoice data; subscription and plan status; Stripe customer, session, and payment identifiers. Paid plans, Cloud Hosted card verification, AI credit purchases, and billing and refund workflows. Card numbers are processed by Stripe and are not stored by MergeLoom.
Resend (Resend, Inc.) Transactional email delivery, including email verification, signup and customer notification emails, and product and account emails. Email address; name or workspace details where included; email content; delivery metadata; verification links and tokens where applicable. Account registration, email verification, signup notifications, and service emails. From email may be MergeLoom <support@mergeloom.ai> or MergeLoom <noreply@mergeloom.ai>. Signup notifications are delivered to support@mergeloom.ai.
Cloudflare, Inc. Public website hosting and edge delivery, website security, Cloudflare Workers and static asset hosting, KV-backed website functionality where used, Turnstile bot and abuse protection, and routing and operational security. IP address; user agent; request metadata; security and abuse signals; Turnstile verification tokens and results; website form and request data routed through Cloudflare Workers. Public website, website forms, Turnstile verification, edge and security infrastructure, and controller registration anti-abuse where configured. Used for site delivery and abuse protection; not used to host the customer's source code.
Google LLC (Google Analytics) Website analytics and measurement. Page views; referrer; device and browser information; approximate location; interaction events; analytics identifiers where applicable. Public website analytics. Measurement ID G-14WPGGRNTV.
Reddit, Inc. Advertising conversion measurement for MergeLoom campaigns. Page visits, referrer, device and browser information, campaign events, and conversion measurement identifiers where applicable. Public website advertising measurement. Reddit Pixel ID a2_j13w493szg26.
LinkedIn Corporation Advertising insight and conversion measurement for MergeLoom campaigns. Page visits, referrer, device and browser information, campaign events, and conversion measurement identifiers where applicable. Public website advertising measurement. LinkedIn Insight partner ID 9182018.
Crisp IM SAS Live chat and support messaging on the public website. Chat messages; email and name if provided by the visitor; page and session context; support conversation metadata. Public website chat and customer and prospect support conversations. Crisp website ID d06542d1-ce4b-4e5a-86e0-555e30b34cf6.
Cal.com, Inc. Demo booking and scheduling. Name; email; company and details entered into the booking form; meeting time; calendar and scheduling metadata. Book Demo flow. Demo booking URL: https://cal.com/mergeloom/20-minute-mergeloom-demo.

03.Customer-Enabled Integrations

The following providers are not always-on MergeLoom subprocessors. They are selected and authorised by the customer, and operate under the customer's own contracts and security controls with those vendors.

Provider Purpose Data Processed Applies To Notes
Atlassian (Jira Cloud, Confluence Cloud) Jira Cloud for ticket intake, ticket comments, and workflow and status updates. Confluence Cloud for selected documentation and context sources. Ticket identifiers, titles, statuses, comments, and content needed for runs. For Confluence, page references stored by the control plane and page bodies fetched by the worker path when needed. Customers who connect Jira or Confluence to MergeLoom. Control plane stores tenant-facing integration state and Confluence page references; the control plane does not store all Confluence page bodies by default.
GitHub, Inc. GitHub App integration for GitHub Issues intake, repository clone, fetch and push, draft PR creation and update, and repository catalog sync. Repository metadata, branches, commits, file contents required for the run, issue content, and PR metadata. Customers who install the MergeLoom GitHub App. Repository operations happen from the worker path.
GitLab B.V. GitLab OAuth integration for GitLab Issues intake, project and branch discovery, repository clone, fetch and push, and draft MR creation and update. Project metadata, branches, commits, file contents required for the run, issue content, and MR metadata. Customers who connect GitLab to MergeLoom. Repository operations happen from the worker path.
Microsoft Azure DevOps (Azure Boards, Azure DevOps Repositories) Azure Boards intake and Azure DevOps Repositories PR output, including work item read, comment, and state updates, and repository and PR operations where configured. Work item metadata and content, repository metadata, branches, commits, file contents required for the run, and PR metadata. Customers who connect Azure DevOps to MergeLoom. Operates under the customer's Azure DevOps organisation and permissions.
monday.com Ltd. monday.com OAuth for board and item intake and item updates and status changes. Board and item identifiers, titles, statuses, and content needed for runs. Customers who connect monday.com to MergeLoom. Scoped to the boards the customer authorises.
Linear, Inc. Linear OAuth for team and issue intake and issue comments and workflow state updates. Team and issue identifiers, titles, statuses, and content needed for runs. Customers who connect Linear to MergeLoom. Scoped to the teams the customer authorises.
Slack Technologies, LLC Optional review notification destination. Posts PR or MR review notification messages if the customer configures it. Notification content including PR or MR links and run summaries. Customers who configure Slack notifications. Optional; can be disabled at any time.
Microsoft Teams Optional review notification destination. Posts PR or MR review notification messages if the customer configures it. Notification content including PR or MR links and run summaries. Customers who configure Microsoft Teams notifications. Optional; can be disabled at any time.
Customer-Selected AI / Model Providers Self Hosted execution against the customer's chosen provider path. Prompts, ticket and code context, AI inputs and outputs, and usage and cost metadata, all sent from the customer's worker to the customer's chosen provider. Self Hosted deployments. Possible provider paths include Codex CLI, Claude Code CLI, Codex API, Claude / Anthropic API, OpenAI-compatible private endpoints (with tool and function calling), Google Vertex AI, AWS Bedrock, and Azure AI Foundry. Customer-managed contracts and security controls apply. OpenAI-compatible endpoints must support tool and function calling for real ticket execution; prompt-only chat completion compatibility is not sufficient.

04.Self Hosted Considerations

In Self Hosted deployments, code-facing execution and many runtime dependencies are operated inside the customer's environment. The subprocessor footprint for those components, including the AI provider path, is determined and contracted by the customer. The MergeLoom control plane continues to handle coordination and configuration metadata and safe operational summaries.

05.Updates

We may add, change, or remove subprocessors as the service evolves. For the current list, or to request notification of changes, contact support@mergeloom.ai.

Contact Us

Questions about this policy? Contact us at support@mergeloom.ai.

Start Free With No Risk

Pay For Outcomes, Not Seats

Run MergeLoom on scoped work before rolling it out. You only pay when a run opens a PR/MR for review, not for seats or tickets that stop before handoff.

Cloud

50 Free PR/MR Runs

Then From £4 Per PR/MR

Self Hosted

50 Free PR/MR Runs

Then From £2 Per PR/MR

Paid Outcomes

Only PR/MR Runs Count

No PR/MR, No Run Charge

  • Free To Start
  • Pay For Outcomes
  • No Lock-In Contracts
  • No Credit Card Required (Self-Hosted)
  • Cancel Anytime

No PR/MR, No Run Charge · No Seat Pricing · Human Review Stays In Control

See Pricing