PurVago

PurVago — Subprocessors

Last updated: September 23, 2026 · Previous versions

This list is incorporated into the Data Processing Addendum (https://app.purvago.com/legal/dpa) as Annex III and is the single source of truth for the vendors that process data for PurVago. Each is bound by a written agreement that requires it to give personal data the same or equal protection as our Privacy Policy and this DPA, and to use it only to provide its service to PurVago. To receive notice of changes by email, write to privacy@purvago.com; Customers' admin addresses are emailed at least 30 days before a subprocessor is added or replaced, as described in Section 6.3 of the DPA.

SubprocessorPurposeData processedRegionNotes
SupabaseApplication backend: database, authentication, serverless functions and file storageAll Customer Data at rest and in transit through the platform, including uploaded photos and documentsUnited StatesCore hosting provider; data encrypted at rest and in transit; daily backups
NetlifyWeb hosting and content delivery for app.purvago.com and purvago.comRequest metadata (IP address, user agent) in access logs; website contact-form submissionsUnited StatesServes the application; no Customer Data stored
StripePayment processing and Stripe Connect payouts for Customers' invoices; platform fee collectionPayment and payout metadata; cardholder data handled directly by Stripe (PCI)United StatesCustomer is merchant of record on its connected account
TwilioClick-to-dial calling and SMS messagesPhone numbers, message/call metadata and content initiated by the CustomerUnited StatesOptional; Customer-enabled
QuickBooks (Intuit)Optional accounting synchronizationInvoice/customer/financial records the Customer chooses to syncUnited StatesOptional; Customer-connected
GustoOptional payroll synchronization (Hiring & payroll add-on)Sent to Gusto: employee identifiers and the hours, overtime and paid-time-off totals the Customer chooses to send. Received from Gusto: the Customer's Gusto company name and identifier, its employee list (name, work email and identifier) for matching, pay-period details, and, when the Customer's owner asks for it, each matched employee's current pay rate and pay period. No tax identifiers, bank details, addresses or payroll amounts are receivedUnited StatesOptional; Customer-connected to its own Gusto account
CheckrOptional background checks and drug screening (Hiring & payroll add-on)Candidate name, email, phone and work location; consent and the report itself are handled on Checkr's own pages; PurVago receives the report's status, Checkr's recommended outcome label and a link to the reportUnited StatesOptional; Customer-connected to its own Checkr account
OpenAIAI features: vision estimating from photos and video frames, walkthrough voice-note transcription, note polishing, and staff-only course draftingPhotos and video frames, walkthrough audio, notes and transcripts, and the generated outputs; sent only after the person gives permission in the appUnited StatesTerms prohibit training on inputs and outputs; inputs may be kept up to 30 days for abuse monitoring; see the AI Features Disclosure (https://app.purvago.com/legal/ai)
ResendTransactional and client email delivery, including sign-in codesRecipient email, subject, and message contentUnited States
GoogleAddress geocoding and maps (Google Maps Platform); optional Google sign-in; web fonts (Google Fonts)Property addresses and derived coordinates; for sign-in, the user's Google account email and name; for fonts, the viewer's IP address and browser typeUnited States
OpenStreetMap FoundationGeocoding fallback (Nominatim) used only when Google's geocoding is unavailable; map images on the jobs mapProperty address text (geocoding); the viewer's IP address, browser type and the map area shown (map images)United KingdomSingle low-volume queries with attribution, under OpenStreetMap's usage policies
AppleOptional Sign in with AppleThe user's Apple ID email (or relay address) and nameUnited StatesOptional; user-chosen
RentCastProperty-data lookup for estimatingProperty address and returned property attributesUnited StatesOptional
SentryError and performance monitoring for the web app, the iOS app and backend functionsError details, the page, recent actions before the error, device and browser type, and the signed-in user's ID, email, company ID and role; performance timings for about 5% of sessionsUnited StatesError reports kept up to 90 days
Browser push services (Apple, Google, Mozilla)Delivering push notifications to browsers that have turned them onThe browser's push address; notification content is encrypted end to end and unreadable to the push serviceUnited StatesOptional; user-enabled in the browser
Better StackUptime monitoring and the public status pageNone beyond the availability of public endpointsUnited States
ImprovMX and ProtonDelivery and storage of email sent to purvago.com support and billing addressesSender address and message content of email you send usUnited States / Switzerland (Proton)Support correspondence only

Onward subprocessors used by the providers above are governed by their respective agreements.

Change log