Service providers
Reviewed August 18, 2026
These provider categories support the public site and Mithra’s internal business systems. A provider receives only the information reasonably necessary for its function. Optional analytics providers do not load before consent.
OpenAI Sites / Cloudflare infrastructure
Purpose: Hosting, database, delivery, and edge security
Data: Website, CRM, analytics, and operational records
Status: In use
OpenAI authentication
Purpose: Staff sign-in and identity
Data: Staff account identity and session data
Status: In use
Square
Purpose: Preferred hosted checkout, payment reconciliation, and refunds
Data: Billing contact, amount, description, payment status; card data remains with Square
Status: Available when Square credentials and signed webhooks are configured
Stripe
Purpose: Fallback hosted checkout and existing payment reconciliation
Data: Billing contact, amount, description, payment status; card data remains with Stripe
Status: Fallback while Square is being connected and for existing Stripe requests
Google Analytics
Purpose: Optional traffic and campaign analytics
Data: Only consented analytics data
Status: Configured; blocked before consent
Cloudflare Turnstile
Purpose: Spam and abuse prevention
Data: Browser/security signals processed by Cloudflare
Status: Used when credentials are configured
Email delivery provider
Purpose: Inquiry, booking, payment, task, and privacy-request messages
Data: Recipient, subject, delivery status, necessary message contents
Status: Used when delivery credentials are configured
Providers, terms, hosting regions, and subprocessors can change. Material changes are reflected in this register and the Privacy Policy. Client projects may use different providers only as defined in the client’s written scope and data-processing terms.
