Smart Order Capture
Legal

Sub-processors

Last updated: 2026-05-16

Pre-launch placeholder. This document has not yet been reviewed by counsel and is published so the user-facing flow exists end-to-end. The final version, signed off before public launch, will replace this text. Do not rely on it as a binding legal document yet.

This page lists every third party we share data with to operate smartordercapture. The list is current as of the "Last updated" date above. We commit to giving 30 days' advance notice — by updating this page and emailing account owners — before adding a sub-processor that will handle personal data.

If you object to a new sub-processor, you may terminate your subscription at any time per our Terms of Service.

Sub-processorPurposeData handledLocation
DigitalOceanObject storage (Spaces) for screenshots, marketplace assets, APK distributionScreenshots uploaded by user-authored workflows; account-bound and signed-URL gatedUnited States (NYC3 region)
Managed Postgres (external)Primary application database — accounts, workflows, runs, audit log, pg-boss queueAll account data, encrypted at rest, TLS in transitUnited States
StripePayment processing for paid plans and marketplace payoutsBilling email, last-4 of card, subscription state, marketplace creator payoutsUnited States
Google Firebase Cloud MessagingPush notifications to paired Android devices for workflow syncFCM tokens (opaque device identifiers), sync payload (workflowId / versionId)United States
ResendTransactional email — verification, password reset, billing receipts, security alertsRecipient email, email content (sent on a per-email basis, not retained)United States
SentryError monitoring across web, API, worker, and AndroidStack traces, request context, browser/OS metadata. PII scrubbed where detected.United States
PostHogProduct analytics and feature-flag deliveryAnonymized event stream (page views, feature usage), opt-out available in SettingsUnited States
CloudflareDNS and edge proxy (planned, pre-launch)IP address, request headers, TLS terminationGlobal anycast
Google Play StoreDistribution of the Android client (play flavor)Install metadata (Play handles, not us)United States

How we choose sub-processors

We pick vendors that publish a privacy policy, sign a data processing agreement on request, and have a track record of taking security seriously. We avoid vendors whose business model is to monetize user data.

Data processing agreements

Customers on the Team or Enterprise plan can request a DPA from legal@smartordercapture.com. Our standard DPA incorporates SCCs (EU Standard Contractual Clauses) where applicable.