StackLégal

Measurement and observability

GDPR Sentry

In an indie stack, Sentry is used for Application error tracking. Entity cited: Functional Software, Inc. d/b/a Sentry. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Sentry

Yes. Public DPA.

Read the DPA

Stated role

Sentry is processor of personal data and the customer is controller, or a processor acting for a third-party controller.

Personal data

IP address, email, and other identifiable data that the customer configures. For repository integrations: username, public email, and repository identifier.

Sub-processors of Sentry

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

Sentry may store and process Customer Data in the United States and in any country where Sentry or its sub-processors operate. If the customer chooses a storage location, service data stays there. Infrastructure sub-processors cite the European Union and the United States.

EU–United States Data Privacy Framework

Functional Software Inc. (public name Sentry.io) is registered. EU-U.S. Data Privacy Framework status: Active.

Data Privacy Framework sheet

Cookies

The Cookie Bounty page (stated update: 9 September 2026) lists the essential cookies of the Sentry sites: sentry-sc and session on sentry.io (authentication), messages (Django notifications), __stripe_sid and __stripe_mid (payment fraud), plus third-party Stripe cookies, Cloudflare on vimeo.com, and reCAPTCHA. Cookies set by the SDK on a customer's domain: not disclosed.

Typical use, written by StackLégal and not by the vendor: Application error tracking.

History

Last update: October 4, 2026.

  1. Cookies: names from the Cookie Bounty page, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Sentry a processor within the meaning of the GDPR?

Sentry is processor of personal data and the customer is controller, or a processor acting for a third-party controller.

What DPA does Sentry publish?

Yes. Public DPA. https://sentry.io/legal/dpa/

Which further sub-processors does Sentry publish?

Public list. https://sentry.io/legal/subprocessors/

Where does Sentry state that it processes data, including outside the EU?

Sentry may store and process Customer Data in the United States and in any country where Sentry or its sub-processors operate. If the customer chooses a storage location, service data stays there. Infrastructure sub-processors cite the European Union and the United States.

Is Sentry registered under the EU–United States Data Privacy Framework?

Functional Software Inc. (public name Sentry.io) is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/5869

Which personal data does Sentry mention?

IP address, email, and other identifiable data that the customer configures. For repository integrations: username, public email, and repository identifier.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets measurement and observability

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.