Service VIN — Legal
Sub-processors
Every third party that can receive personal data through Service VIN, what it is used for, what it receives, and where it runs. Derived from this product’s actual dependencies and configuration — not from a template.
Last updated: August 5, 2026
Status of this document
This is the sub-processor list currently in force for Service VIN, operated by Obsidian Auto Inc. of 168 MacEwan Ridge Close NW, Calgary, Alberta T3K 3J4, Canada. It is the list referenced by our Data Processing Agreement and our Privacy Policy, and it is kept current as vendors are added or removed — see notice of changes below.
1. How this list was built
A vendor appears here only if code in this repository sends it data. Each entry was derived from one of three sources: the dependency manifest, the validated server environment schema, or the integration registry that defines every per-shop connector.
Where a vendor is configuration-gated, the table says which variable gates it. With that variable unset the adapter is a no-op: no outbound request is made and the vendor receives nothing at all.
Two caveats stated before the tables, not after.
- Where the application actually runs. The production database and object storage are hosted in AWS us-east-1(Northern Virginia, United States). Serverless functions run in our host’s default US East region. Both are stated as a matter of fact, not as a contractual data-residency guarantee — we do not currently offer one, Canadian or otherwise, and would rather say so than imply it.
- Legal entity names are given only where we can state them confidently. Where we cannot, the row says “not confirmed” instead of guessing.
2. Core infrastructure (always in the data path)
Scroll the table sideways for the rest of the columns
| Vendor | Purpose | Personal data | Region | Engaged when |
|---|---|---|---|---|
| SupabaseSupabase, Inc. (Delaware, USA)DPA | Primary PostgreSQL database, authentication, and private object storage. | Effectively all of it — user accounts, customers, vehicles, jobs, quotes, invoices, payments, messages, calls and transcripts, uploaded documents. | AWS us-east-1 (Northern Virginia, United States) — the production project’s configured region. | Always. |
| VercelVercel Inc. (USA)DPA | Application hosting, serverless execution, TLS termination, custom-domain automation for booking storefronts, and — as separately switched platform features — Web Analytics and Speed Insights product/performance measurement. | Everything in transit through a request, plus request logs. For Web Analytics and Speed Insights: a 24-hour, non-persistent visitor hash derived from the request, the redacted route template, referrer host, country, browser/OS/device class, and page-loading timings. No cookie is set and no full URL or query string is reported. | Not pinned; the host’s default US East region. | Always. |
| AnthropicAnthropic, PBC (USA)Commercial terms | Every request-time language-model call: transcript analysis, message drafting, follow-up agents, support copilot, setup assistant. | Call transcripts, message threads, customer display names, vehicle descriptions, service interests, shop profile and knowledge-base text. | United States (vendor default). | Always — ANTHROPIC_API_KEY is a required variable. |
| InngestInngest, Inc. (USA)DPA | Durable background jobs — follow-up agents, integration syncs, call transcription and analysis, webhook dispatch, digests. | Event payloads: mostly record identifiers plus small denormalised fields such as a shop id, job id or phone number. | United States (vendor default). | Always. |
3. Feature vendors (configuration-gated; no key means no data)
Scroll the table sideways for the rest of the columns
| Vendor | Purpose | Personal data | Region | Engaged when |
|---|---|---|---|---|
| StripeStripe, Inc. (USA); Canadian acquiring via Stripe Payments Canada Ltd.DPA | Hosted Checkout for invoices and deposits, Connect payouts to shops, platform subscription billing. | Customer email, invoice amounts and line descriptions, shop payout and identity data. Card numbers never reach Service VIN. | United States / global. | STRIPE_SECRET_KEY |
| TwilioTwilio Inc. (USA)DPA | SMS send and receive, voice calling and the browser softphone, call-recording storage, Voice Intelligence transcription, VoIP push. | Customer phone numbers, full SMS bodies, call audio recordings, call transcripts. | United States (vendor default). | TWILIO_ACCOUNT_SID |
| ResendResend, Inc. (USA)DPA | Transactional email — quote, invoice and receipt links, portal notifications, digests. | Recipient name and email address, message content, links to shared documents. | United States (vendor default). | RESEND_API_KEY |
| OpenAIOpenAI, L.L.C. (USA)DPA | Service-image generation only (the image studio, when Google Imagen is not configured). Customer messages and call transcripts are never sent to OpenAI. | A short text prompt describing the service to illustrate. | United States (vendor default). | OPENAI_API_KEY — optional; absent means the adapter is a no-op. |
| GoogleGoogle LLC (USA)DPA | Sign in with Google; Calendar event sync; Business Profile reviews, replies and posts; optional Pub/Sub push for real-time review alerts. | Google account email; calendar event titles, times and attendees; review author names and review text. | United States / global. | GOOGLE_OAUTH_CLIENT_ID |
| Quo (formerly OpenPhone)OpenPhone Technologies, Inc. (USA) | Shared phone-system mirror — contacts, conversations, calls, transcripts and summaries pulled into the inbox. | Customer phone numbers, message bodies, call transcripts and AI summaries. | United States (vendor default). | A per-shop API key, stored encrypted. |
| ExpoExpo / 650 Industries, Inc. (USA) | Push notifications to the iOS and Android apps. | Device push tokens; notification title and body, which may contain a customer first name or job title. | United States (vendor default). | A staff member registering a mobile device. |
| MapboxMapbox, Inc. (USA)DPA | Geocoding addresses for mobile-service areas and booking address validation. | Street addresses submitted for geocoding. | United States (vendor default). | MAPBOX_SECRET_TOKEN |
| Entrigoentri.com — legal entity not confirmed | Optional one-click DNS setup when a shop connects its own booking domain. | Domain names and DNS records. The shop’s DNS-provider login happens inside Entri’s widget, not in our app. | Not confirmed. | ENTRI_SECRET |
4. Per-shop connectors (a shop must connect its own account)
None of these receive anything until an individual shop completes an OAuth consent flow for its own account. Access and refresh tokens are encrypted with AES-256-GCM before they are stored — see Encryption.
Scroll the table sideways for the rest of the columns
| Vendor | Purpose | Personal data | Region | Engaged when |
|---|---|---|---|---|
| Intuit (QuickBooks Online)Intuit Inc. (USA)Privacy / DPA | Accounting sync — customers, invoices, payments. | Customer name, email and address; invoice and payment amounts. | United States. | A shop connects its own QuickBooks company. |
| XeroXero Limited (New Zealand)DPA | Accounting sync. | Customer name and email; invoice and payment amounts. | Vendor default. | A shop connects its own Xero organisation. |
| SquareBlock, Inc. (USA)DPA | Terminal-sale reconciliation. | Transaction amounts and timestamps; card brand and last four digits as returned by Square. Never a full card number. | United States. | A shop connects its own Square account. |
| Microsoft (Outlook / Graph)Microsoft Corporation (USA)Trust centre | Outlook calendar sync. | Calendar event titles, times and attendees. | Determined by the shop’s Microsoft 365 tenant. | A shop connects its own Microsoft account. |
| MailchimpIntuit Inc. / The Rocket Science Group LLC (USA)DPA | Marketing audience sync. | Customer name, email and tags. | United States. | A shop connects its own Mailchimp audience. |
| SlackSlack Technologies, LLC, a Salesforce company (USA)DPA | Posts shop event notifications into a chosen channel. | Event summaries, which may include a customer first name or job title. | Determined by the shop’s Slack workspace. | A shop connects its own Slack workspace. |
| MetaMeta Platforms, Inc. (USA)DPA | Lead Ads — inbound lead webhooks and page-scoped token exchange. | Lead name, phone, email and form answers as submitted on Facebook or Instagram. | United States / global. | A shop connects its own Facebook page. |
| PodiumPodium Corporation, Inc. (USA) | Review syncing. | Review author names and review text. | United States. | Not confirmed live. The connector is registered and env-gated, but Podium’s developer programme is application-gated and it has never run against production credentials. |
5. Conditional — analytics and error monitoring
Both are engaged only when their key is configured. When off, no outbound request is made at all. Neither uses a third-party script tag or a vendor SDK in the browser: both are reached through first-party transport on our own origin, which is why there is no third-party cookie and no autocapture of form values.
Scroll the table sideways for the rest of the columns
| Vendor | Purpose | Personal data | Region | Engaged when |
|---|---|---|---|---|
| PostHogPostHog, Inc. (USA)DPA | Product analytics — a six-step signup and activation funnel. | An anonymous first-party visitor identifier, event names, and an allowlisted property set. No third-party cookie, no DOM autocapture, no form values. | EU Cloud by default (eu.i.posthog.com), chosen as the strictest-jurisdiction option. Switchable to US Cloud by configuration. | POSTHOG_KEY — unset means no outbound call and no cookie at all. |
| SentryFunctional Software, Inc. d/b/a Sentry (USA)DPA | Error monitoring. | Error message and stack text, URL path only (query strings stripped), and an allowlisted header set — currently just the user agent. No cookies, no Authorization header, no request bodies. | Determined by the configured Sentry organisation’s region. | SENTRY_DSN — unset means the module is inert. |
6. Not sub-processors
Recorded deliberately, so that nobody later mistakes dead configuration for a live data recipient.
- Cloudflare R2. Four R2 variables are declared in the environment schema, but no code reads them. Object storage is Supabase Storage. The
r2_bucketandr2_keycolumn names on the documents table are a historical artefact of an earlier plan. R2 is not a sub-processor today. - Google Gemini and Imagen. Used only by offline marketing-content scripts and the blog text-to-speech route. They never receive customer data.
- Browser push services (Apple, Google, Mozilla). Web push is sent directly to the browser vendor’s endpoint using our VAPID keypair. There is no account or contract; the endpoint receives an encrypted payload addressed to a subscription the user’s own browser created.
7. Change notification
We will give at least thirty (30) days’ notice before a new sub-processor begins processing personal information, by updating this page and notifying subscribed contacts. Customers may object on reasonable data-protection grounds within that window; the objection procedure and its consequences are set out in clause 8 of the Data Processing Agreement. Where a sub-processor must be replaced urgently — vendor failure, a security incident — we may act with less notice and will tell you as soon as practicable.
The subscription list for these notices is not yet operating. Until it is, email us and we will add you manually.
8. Questions
Security and privacy questions are answered by a person who wrote the code. See the security overview for the engineering detail behind these arrangements, the DPA for the contractual terms, and the Privacy Policy for how we handle information as a controller in our own right.