Back
Privacy
Natty Hatty — Website Sub-processors List
Version: v1.0
Effective Date: November 15, 2025
This Sub-processors List applies only to the Natty Hatty public-facing website, including:
Marketing and informational pages
Public program/registration pages hosted for Organizations
Public transactional (checkout) pages
Public Natty Hatty Signature pages accessed via link or QR code
This list does not cover authenticated platform services (Business Center, Customer App, Signature backend). Those are governed by the Platform Sub-processors List.
Natty Hatty engages the following third-party service providers (“Sub-processors”) to host, operate, secure, and support the website.
1. Infrastructure & Hosting
Amazon Web Services (AWS)
Function: Primary hosting, compute resources, storage, load balancing, security
Data Processed: IP addresses, device metadata, HTTP request logs, signature-page metadata
Location: United States (with global edge caching)
2. Content Delivery & Security
Cloudflare, Inc.
Function: CDN, caching, DDoS protection, firewall (WAF), bot mitigation
Data Processed: IP addresses, network metadata, request headers
Location: Global Anycast Network
Cloudflare does not use data for advertising or behavioral profiling.
3. Analytics
Google Analytics (Google LLC)
Function: Non-advertising website analytics
Data Processed: Browser info, device type, anonymized or truncated IP, pageviews
Notes:
Advertising features disabled
IP anonymization enabled
No cross-site tracking
No data sharing with Google Ads
No AI/ML training on Natty Hatty data
Location: United States
4. Email & Communication Tools
Twilio SendGrid
Function: Transactional email delivery (contact forms, signature confirmation delivery, notifications)
Data Processed: Email address, name (if provided), message content
Location: United States
SendGrid processes only what is required to deliver website communications.
5. Payment Processing (Transactional Pages)
Stripe, Inc.
Function: Payment processing for Organization-hosted checkout pages
Data Processed: Tokenized payment data, billing address, name, payment metadata
Notes:
PCI-DSS Level 1 compliant
Natty Hatty never stores card numbers or CVV
Stripe may use cookies for fraud prevention
Location: United States / Global
6. Signature Page Infrastructure (Public Signature Pages)
Public signature pages use the same website infrastructure.
All sensitive signature data is processed within the Natty Hatty Signature system and governed by our Platform Privacy & Security terms.
Website-level processing includes:
AWS
(Already listed above)
Used to host and deliver signature pages securely.
7. No Advertising, Retargeting, or Tracking Sub-processors
Natty Hatty does not use:
Facebook Pixel
TikTok Pixel
Google Ads cookies
Third-party trackers
Behavioral advertising partners
No data is sold or shared for cross-context behavioral advertising.
8. Updates to This List
Natty Hatty may update this list periodically as services evolve.
We will:
Update the “Effective Date”
Maintain transparency
Notify users if required by applicable law