Skip to main content

Service VIN — Legal

Sub-processors

Every third party that can receive personal data through Service VIN, what it is used for, what it receives, and where it runs. Derived from this product’s actual dependencies and configuration — not from a template.

Last updated:

Status of this document

This is the sub-processor list currently in force for Service VIN, operated by Obsidian Auto Inc. of 168 MacEwan Ridge Close NW, Calgary, Alberta T3K 3J4, Canada. It is the list referenced by our Data Processing Agreement and our Privacy Policy, and it is kept current as vendors are added or removed — see notice of changes below.

1. How this list was built

A vendor appears here only if code in this repository sends it data. Each entry was derived from one of three sources: the dependency manifest, the validated server environment schema, or the integration registry that defines every per-shop connector.

Where a vendor is configuration-gated, the table says which variable gates it. With that variable unset the adapter is a no-op: no outbound request is made and the vendor receives nothing at all.

Two caveats stated before the tables, not after.

  • Where the application actually runs. The production database and object storage are hosted in AWS us-east-1(Northern Virginia, United States). Serverless functions run in our host’s default US East region. Both are stated as a matter of fact, not as a contractual data-residency guarantee — we do not currently offer one, Canadian or otherwise, and would rather say so than imply it.
  • Legal entity names are given only where we can state them confidently. Where we cannot, the row says “not confirmed” instead of guessing.

2. Core infrastructure (always in the data path)

Scroll the table sideways for the rest of the columns

Core infrastructure sub-processors
VendorPurposePersonal dataRegionEngaged when
SupabaseSupabase, Inc. (Delaware, USA)DPAPrimary PostgreSQL database, authentication, and private object storage.Effectively all of it — user accounts, customers, vehicles, jobs, quotes, invoices, payments, messages, calls and transcripts, uploaded documents.AWS us-east-1 (Northern Virginia, United States) — the production project’s configured region.Always.
VercelVercel Inc. (USA)DPAApplication hosting, serverless execution, TLS termination, custom-domain automation for booking storefronts, and — as separately switched platform features — Web Analytics and Speed Insights product/performance measurement.Everything in transit through a request, plus request logs. For Web Analytics and Speed Insights: a 24-hour, non-persistent visitor hash derived from the request, the redacted route template, referrer host, country, browser/OS/device class, and page-loading timings. No cookie is set and no full URL or query string is reported.Not pinned; the host’s default US East region.Always.
AnthropicAnthropic, PBC (USA)Commercial termsEvery request-time language-model call: transcript analysis, message drafting, follow-up agents, support copilot, setup assistant.Call transcripts, message threads, customer display names, vehicle descriptions, service interests, shop profile and knowledge-base text.United States (vendor default).Always — ANTHROPIC_API_KEY is a required variable.
InngestInngest, Inc. (USA)DPADurable background jobs — follow-up agents, integration syncs, call transcription and analysis, webhook dispatch, digests.Event payloads: mostly record identifiers plus small denormalised fields such as a shop id, job id or phone number.United States (vendor default).Always.

3. Feature vendors (configuration-gated; no key means no data)

Scroll the table sideways for the rest of the columns

Feature sub-processors
VendorPurposePersonal dataRegionEngaged when
StripeStripe, Inc. (USA); Canadian acquiring via Stripe Payments Canada Ltd.DPAHosted Checkout for invoices and deposits, Connect payouts to shops, platform subscription billing.Customer email, invoice amounts and line descriptions, shop payout and identity data. Card numbers never reach Service VIN.United States / global.STRIPE_SECRET_KEY
TwilioTwilio Inc. (USA)DPASMS send and receive, voice calling and the browser softphone, call-recording storage, Voice Intelligence transcription, VoIP push.Customer phone numbers, full SMS bodies, call audio recordings, call transcripts.United States (vendor default).TWILIO_ACCOUNT_SID
ResendResend, Inc. (USA)DPATransactional email — quote, invoice and receipt links, portal notifications, digests.Recipient name and email address, message content, links to shared documents.United States (vendor default).RESEND_API_KEY
OpenAIOpenAI, L.L.C. (USA)DPAService-image generation only (the image studio, when Google Imagen is not configured). Customer messages and call transcripts are never sent to OpenAI.A short text prompt describing the service to illustrate.United States (vendor default).OPENAI_API_KEY — optional; absent means the adapter is a no-op.
GoogleGoogle LLC (USA)DPASign in with Google; Calendar event sync; Business Profile reviews, replies and posts; optional Pub/Sub push for real-time review alerts.Google account email; calendar event titles, times and attendees; review author names and review text.United States / global.GOOGLE_OAUTH_CLIENT_ID
Quo (formerly OpenPhone)OpenPhone Technologies, Inc. (USA)Shared phone-system mirror — contacts, conversations, calls, transcripts and summaries pulled into the inbox.Customer phone numbers, message bodies, call transcripts and AI summaries.United States (vendor default).A per-shop API key, stored encrypted.
ExpoExpo / 650 Industries, Inc. (USA)Push notifications to the iOS and Android apps.Device push tokens; notification title and body, which may contain a customer first name or job title.United States (vendor default).A staff member registering a mobile device.
MapboxMapbox, Inc. (USA)DPAGeocoding addresses for mobile-service areas and booking address validation.Street addresses submitted for geocoding.United States (vendor default).MAPBOX_SECRET_TOKEN
Entrigoentri.com — legal entity not confirmedOptional one-click DNS setup when a shop connects its own booking domain.Domain names and DNS records. The shop’s DNS-provider login happens inside Entri’s widget, not in our app.Not confirmed.ENTRI_SECRET

4. Per-shop connectors (a shop must connect its own account)

None of these receive anything until an individual shop completes an OAuth consent flow for its own account. Access and refresh tokens are encrypted with AES-256-GCM before they are stored — see Encryption.

Scroll the table sideways for the rest of the columns

Per-shop OAuth connectors
VendorPurposePersonal dataRegionEngaged when
Intuit (QuickBooks Online)Intuit Inc. (USA)Privacy / DPAAccounting sync — customers, invoices, payments.Customer name, email and address; invoice and payment amounts.United States.A shop connects its own QuickBooks company.
XeroXero Limited (New Zealand)DPAAccounting sync.Customer name and email; invoice and payment amounts.Vendor default.A shop connects its own Xero organisation.
SquareBlock, Inc. (USA)DPATerminal-sale reconciliation.Transaction amounts and timestamps; card brand and last four digits as returned by Square. Never a full card number.United States.A shop connects its own Square account.
Microsoft (Outlook / Graph)Microsoft Corporation (USA)Trust centreOutlook calendar sync.Calendar event titles, times and attendees.Determined by the shop’s Microsoft 365 tenant.A shop connects its own Microsoft account.
MailchimpIntuit Inc. / The Rocket Science Group LLC (USA)DPAMarketing audience sync.Customer name, email and tags.United States.A shop connects its own Mailchimp audience.
SlackSlack Technologies, LLC, a Salesforce company (USA)DPAPosts shop event notifications into a chosen channel.Event summaries, which may include a customer first name or job title.Determined by the shop’s Slack workspace.A shop connects its own Slack workspace.
MetaMeta Platforms, Inc. (USA)DPALead Ads — inbound lead webhooks and page-scoped token exchange.Lead name, phone, email and form answers as submitted on Facebook or Instagram.United States / global.A shop connects its own Facebook page.
PodiumPodium Corporation, Inc. (USA)Review syncing.Review author names and review text.United States.Not confirmed live. The connector is registered and env-gated, but Podium’s developer programme is application-gated and it has never run against production credentials.

5. Conditional — analytics and error monitoring

All three are engaged only when their key is configured. When off, no outbound request is made at all — and the advertising pixel is absent from the build rather than merely inert.

PostHog and Sentry use no third-party script tag and no vendor SDK in the browser: both are reached through first-party transport on our own origin, which is why there is no third-party cookie and no autocapture of form values. The ChatGPT Ads pixel is the exception, and it is stated rather than glossed:it is a vendor script served from OpenAI’s domain and it sets a first-party cookie holding the ad-click identifier. Two things bound it, both enforced in code rather than by policy — it is loaded only on our own public marketing pages, never on the signed-in application, a shop’s booking storefront or landing pages, or a page whose address contains a customer’s share link; and it is not loaded at all for a visitor sending Do Not Track or Global Privacy Control.

Scroll the table sideways for the rest of the columns

Conditional analytics and monitoring sub-processors
VendorPurposePersonal dataRegionEngaged when
PostHogPostHog, Inc. (USA)DPAProduct analytics — a six-step signup and activation funnel.An anonymous first-party visitor identifier, event names, and an allowlisted property set. No third-party cookie, no DOM autocapture, no form values.EU Cloud by default (eu.i.posthog.com), chosen as the strictest-jurisdiction option. Switchable to US Cloud by configuration.POSTHOG_KEY — unset means no outbound call and no cookie at all.
Google (Google Ads)Google LLC (USA)Ads Processor TermsAdvertising measurement — attributing an account signup or a demo enquiry back to the Google ad that produced it, so campaigns can be optimised against something other than clicks.From the BROWSER, on our own public marketing pages only: that one of two conversions happened (an account was created, or a demo was requested), and the marketing page URL it happened on. The tag is never loaded on the signed-in application, on a shop's booking storefront or landing pages, or on the token-gated pages where a customer opens their own quote, invoice or job — Google's own setup instructions ask for it on every page of a website, and we deliberately do not do that. One identifier is sent, in one case: a SHA-256 hash of the email address an account was just created with (Google's "enhanced conversions"), computed in the browser, sent only with the account-creation conversion and never with a demo enquiry. No plaintext email, name, phone number or address is sent, and a build check holds it to that one hashed field. We separately keep the advertisement-click identifier from the visit that produced a signup on our own record of that account; it is not sent to Google by this tag.United States.NEXT_PUBLIC_GOOGLE_ADS_ID — unset means the tag is absent from the build entirely: no script tag, no cookie, no request. It is also absent for any visitor sending Do Not Track or Global Privacy Control.
Google (Google Analytics)Google LLC (USA)Data Processing TermsWebsite analytics for our own public marketing site — how many people visit, which pages they read, and where they came from.From the BROWSER, on our own public marketing pages only: the page address, the referring page, and the technical details Google Analytics collects with a visit (browser, device type, approximate location Google derives from the connection), keyed to a random first-party identifier in the _ga cookies. It is never loaded on the signed-in application, on a shop's booking storefront or landing pages, or on the token-gated pages where a customer opens their own quote, invoice or job; and because it can notice in-page navigation, our code switches it off for the rest of the visit the moment a visitor moves from a marketing page to one of those. No name, email, phone number or hashed identifier is sent to it. Google signals and ad personalisation are off. Reported to more than one Google Analytics property, all of them ours.United States.NEXT_PUBLIC_GA4_IDS — unset means no Google Analytics property is configured: no script, no cookie, no request. It is also absent for any visitor sending Do Not Track or Global Privacy Control.
OpenAI (ChatGPT Ads)OpenAI OpCo, LLC (USA)DPAAdvertising measurement — attributing a signup or an enquiry back to the ChatGPT ad that produced it, so campaigns can be optimised against something other than clicks.Two paths. From the BROWSER, on our own public marketing pages only: an event name from a closed list of four (page_viewed, lead_created, registration_completed, appointment_scheduled), a short label saying which form it was, and the marketing page URL the event happened on. The pixel is never loaded on the signed-in application, on a shop's booking storefront or landing pages, or on the token-gated pages where a customer opens their own quote, invoice or job. From our SERVER, via the Conversions API: that a free trial began, the plan name, and the advertisement-click identifier it came from — sent only when we still hold that identifier, so a trial we cannot attribute to an ad is not reported at all. On neither path is a name, email, phone number or hashed identifier of any kind sent; the vendor's advanced-matching feature is deliberately unused on both.United States.NEXT_PUBLIC_OPENAI_ADS_PIXEL_ID — unset means the pixel is absent from the build entirely: no script tag, no cookie, no request.OPENAI_ADS_API_KEY gates the server-side half independently; unset, no conversion is sent. Both halves are absent for any visitor sending Do Not Track or Global Privacy Control.
SentryFunctional Software, Inc. d/b/a Sentry (USA)DPAError monitoring.Error message and stack text, URL path only (query strings stripped), and an allowlisted header set — currently just the user agent. No cookies, no Authorization header, no request bodies.Determined by the configured Sentry organisation’s region.SENTRY_DSN — unset means the module is inert.

6. Not sub-processors

Recorded deliberately, so that nobody later mistakes dead configuration for a live data recipient.

  • Cloudflare R2. Four R2 variables are declared in the environment schema, but no code reads them. Object storage is Supabase Storage. The r2_bucket and r2_key column names on the documents table are a historical artefact of an earlier plan. R2 is not a sub-processor today.
  • Google Gemini and Imagen. Used only by offline marketing-content scripts and the blog text-to-speech route. They never receive customer data.
  • Browser push services (Apple, Google, Mozilla). Web push is sent directly to the browser vendor’s endpoint using our VAPID keypair. There is no account or contract; the endpoint receives an encrypted payload addressed to a subscription the user’s own browser created.

7. Change notification

We will give at least thirty (30) days’ notice before a new sub-processor begins processing personal information, by updating this page and notifying subscribed contacts. Customers may object on reasonable data-protection grounds within that window; the objection procedure and its consequences are set out in clause 8 of the Data Processing Agreement. Where a sub-processor must be replaced urgently — vendor failure, a security incident — we may act with less notice and will tell you as soon as practicable.

The subscription list for these notices is not yet operating. Until it is, email us and we will add you manually.

8. Questions

Security and privacy questions are answered by a person who wrote the code. See the security overview for the engineering detail behind these arrangements, the DPA for the contractual terms, and the Privacy Policy for how we handle information as a controller in our own right.