PurVago — Subprocessors
Last updated: September 23, 2026 · Previous versions
This list is incorporated into the Data Processing Addendum (https://app.purvago.com/legal/dpa) as Annex III and is the single source of truth for the vendors that process data for PurVago. Each is bound by a written agreement that requires it to give personal data the same or equal protection as our Privacy Policy and this DPA, and to use it only to provide its service to PurVago. To receive notice of changes by email, write to privacy@purvago.com; Customers' admin addresses are emailed at least 30 days before a subprocessor is added or replaced, as described in Section 6.3 of the DPA.
| Subprocessor | Purpose | Data processed | Region | Notes |
|---|---|---|---|---|
| Supabase | Application backend: database, authentication, serverless functions and file storage | All Customer Data at rest and in transit through the platform, including uploaded photos and documents | United States | Core hosting provider; data encrypted at rest and in transit; daily backups |
| Netlify | Web hosting and content delivery for app.purvago.com and purvago.com | Request metadata (IP address, user agent) in access logs; website contact-form submissions | United States | Serves the application; no Customer Data stored |
| Stripe | Payment processing and Stripe Connect payouts for Customers' invoices; platform fee collection | Payment and payout metadata; cardholder data handled directly by Stripe (PCI) | United States | Customer is merchant of record on its connected account |
| Twilio | Click-to-dial calling and SMS messages | Phone numbers, message/call metadata and content initiated by the Customer | United States | Optional; Customer-enabled |
| QuickBooks (Intuit) | Optional accounting synchronization | Invoice/customer/financial records the Customer chooses to sync | United States | Optional; Customer-connected |
| Gusto | Optional payroll synchronization (Hiring & payroll add-on) | Sent to Gusto: employee identifiers and the hours, overtime and paid-time-off totals the Customer chooses to send. Received from Gusto: the Customer's Gusto company name and identifier, its employee list (name, work email and identifier) for matching, pay-period details, and, when the Customer's owner asks for it, each matched employee's current pay rate and pay period. No tax identifiers, bank details, addresses or payroll amounts are received | United States | Optional; Customer-connected to its own Gusto account |
| Checkr | Optional background checks and drug screening (Hiring & payroll add-on) | Candidate name, email, phone and work location; consent and the report itself are handled on Checkr's own pages; PurVago receives the report's status, Checkr's recommended outcome label and a link to the report | United States | Optional; Customer-connected to its own Checkr account |
| OpenAI | AI features: vision estimating from photos and video frames, walkthrough voice-note transcription, note polishing, and staff-only course drafting | Photos and video frames, walkthrough audio, notes and transcripts, and the generated outputs; sent only after the person gives permission in the app | United States | Terms prohibit training on inputs and outputs; inputs may be kept up to 30 days for abuse monitoring; see the AI Features Disclosure (https://app.purvago.com/legal/ai) |
| Resend | Transactional and client email delivery, including sign-in codes | Recipient email, subject, and message content | United States | |
| Address geocoding and maps (Google Maps Platform); optional Google sign-in; web fonts (Google Fonts) | Property addresses and derived coordinates; for sign-in, the user's Google account email and name; for fonts, the viewer's IP address and browser type | United States | ||
| OpenStreetMap Foundation | Geocoding fallback (Nominatim) used only when Google's geocoding is unavailable; map images on the jobs map | Property address text (geocoding); the viewer's IP address, browser type and the map area shown (map images) | United Kingdom | Single low-volume queries with attribution, under OpenStreetMap's usage policies |
| Apple | Optional Sign in with Apple | The user's Apple ID email (or relay address) and name | United States | Optional; user-chosen |
| RentCast | Property-data lookup for estimating | Property address and returned property attributes | United States | Optional |
| Sentry | Error and performance monitoring for the web app, the iOS app and backend functions | Error details, the page, recent actions before the error, device and browser type, and the signed-in user's ID, email, company ID and role; performance timings for about 5% of sessions | United States | Error reports kept up to 90 days |
| Browser push services (Apple, Google, Mozilla) | Delivering push notifications to browsers that have turned them on | The browser's push address; notification content is encrypted end to end and unreadable to the push service | United States | Optional; user-enabled in the browser |
| Better Stack | Uptime monitoring and the public status page | None beyond the availability of public endpoints | United States | |
| ImprovMX and Proton | Delivery and storage of email sent to purvago.com support and billing addresses | Sender address and message content of email you send us | United States / Switzerland (Proton) | Support correspondence only |
Onward subprocessors used by the providers above are governed by their respective agreements.
Change log
- September 23, 2026 — OpenAI entry corrected to the features that actually use it (voice dictation uses the device's own speech recognition, not OpenAI) and notes that nothing is sent without the person's permission; Sentry entry corrected to cover the web and iOS apps and the data an error report carries; Google entry now includes Google Fonts; OpenStreetMap entry now includes the jobs-map images; browser push services listed; Xero removed (never connected); each provider's obligation stated as the same or equal protection as the Privacy Policy and DPA. Google Fonts, OpenStreetMap map images and browser push services were already in use and are listed now so the list is complete; Customers' admin addresses are emailed on this date.
- September 18, 2026 — OpenStreetMap Foundation (Nominatim) listed as its own entry (previously noted under Google); Checkr entry states the report status, outcome label and link that PurVago receives; encryption at rest noted for Supabase; Gusto entry now states what PurVago receives from Gusto as well as what it sends, including the optional pay-rate read added the same day.
- September 17, 2026 — Supabase replaced Base44 as hosting provider; OpenAI named as the AI provider; Netlify, Google, Apple, Sentry, Better Stack, ImprovMX and Proton, Gusto and Checkr added.
- August 10, 2026 — first published.