{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"subsplash","name":"Subsplash","domain":"subsplash.com","category":"Nonprofit and fundraising","one_liner":"The Subsplash Platform equips churches with the best mobile apps, church management software, websites, online giving, and more to engage","trust_center_url":"https://trust.subsplash.com/","security_page_url":null,"url":"https://certreports.com/vendors/subsplash/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/subsplash/gdpr","evidence":[{"source_type":"trust_center","source_name":"Subsplash trust centre (Vanta)","url":"https://trust.subsplash.com/","fetched_at":"2026-09-18 23:05:37.431043+00","content_hash":"3ac1e70204084e4614e2088963efda97e564f97cc2627e52fae6415ccc8e2526","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2026-10-31","issued_at":"2017-10-24","expires_at":"2026-10-31","period_start":null,"period_end":null,"auditor":"A-LIGN Compliance and Security, Inc., dba A-LIGN","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/subsplash/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:59:27.688112+00","content_hash":"014f8f4683c790324095be7403bf4904261aeefa6d37aaaf59591316410641d3","wayback_url":null,"quote":"Subsplash Wallet, Inc.: PCI DSS, assessor A-LIGN Compliance and Security, Inc., dba A-LIGN, valid through 2026-10-31","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, UK Extension Certification, SW-US Certification","issued_at":"2018-03-08","expires_at":"2027-02-09","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/subsplash/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/8002","fetched_at":"2026-09-17 15:50:22.745312+00","content_hash":"b3471562c970789166413386121b067bb34a92debbcf3bacc95d0bd3cc269483","wayback_url":null,"quote":"Subsplash: Active: EU-US Certification, UK Extension Certification, SW-US Certification","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/subsplash/security","evidence":[{"source_type":"trust_center","source_name":"Subsplash trust centre (Vanta)","url":"https://trust.subsplash.com/","fetched_at":"2026-09-18 23:05:37.431043+00","content_hash":"3ac1e70204084e4614e2088963efda97e564f97cc2627e52fae6415ccc8e2526","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Subsplash is listed in the Visa Global Registry as PCI DSS validated, with that listing valid through 31 Oct 2026 and audited by A-LIGN Compliance and Security, Inc. As of 17 Sep 2026, Subsplash is listed in the EU-US Data Privacy Framework registry with active EU-US, UK Extension, and Swiss-US certifications, valid through 09 Feb 2027. No public evidence found for SOC 2 as of 17 Sep 2026. No public evidence found for ISO 27001 as of 17 Sep 2026. No public evidence found for HIPAA as of 17 Sep 2026.","bullets":["PCI DSS: listed in Visa Global Registry as validated, expires 31 Oct 2026, audited by A-LIGN Compliance and Security, Inc. (as of 17 Sep 2026)","EU-US Data Privacy Framework: listed in registry with active EU-US, UK Extension, and Swiss-US certifications, expires 09 Feb 2027 (as of 17 Sep 2026)","SOC 2, ISO 27001, and HIPAA: no public evidence found as of 17 Sep 2026"],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:52:40.161793+00"},"legal_docs":[{"kind":"privacy","url":"https://subsplash.com/legal/privacy","availability":"public","detail":null,"as_of":"2026-09-18"},{"kind":"subprocessors","url":"https://trust.subsplash.com/","availability":"public","detail":"13 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Amazon Web Services","domain":"amazon.com","purpose":"Hosting, storage and processing Customer Data","location":"USA","vendor_url":"https://certreports.com/vendors/amazon/security"},{"name":"Hubspot","domain":null,"purpose":"CRM Integration","location":"USA","vendor_url":null},{"name":"Intercom","domain":"intercom.com","purpose":"Support and account management","location":"USA","vendor_url":"https://certreports.com/vendors/intercom/security"},{"name":"Loom","domain":null,"purpose":"Support Recordings","location":"USA","vendor_url":null},{"name":"MongoDB","domain":null,"purpose":"Database Hosting","location":"USA","vendor_url":null},{"name":"Outreach","domain":null,"purpose":"Customer Communication Tool","location":"USA","vendor_url":null},{"name":"Pendo","domain":"pendo.io","purpose":"Data analytics","location":"USA","vendor_url":"https://certreports.com/vendors/pendo/security"},{"name":"Salesforce","domain":null,"purpose":"Support and account management","location":"USA","vendor_url":null},{"name":"Sentry (Functional Software, Inc. d/b/a Sentry)","domain":"sentry.io","purpose":"Application Monitoring","location":"USA","vendor_url":null},{"name":"Slack","domain":null,"purpose":"Customer Support and Internal Communication","location":"USA","vendor_url":null},{"name":"Snowflake","domain":"snowflake.com","purpose":"Data warehouse services","location":"USA","vendor_url":"https://certreports.com/vendors/snowflake/security"},{"name":"Stripe","domain":"stripe.com","purpose":"Payment processing","location":"USA","vendor_url":"https://certreports.com/vendors/stripe/security"},{"name":"Tableau","domain":null,"purpose":"Data Visualization Platform","location":"USA","vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T00:27:03.057Z"}