Status: draft for counsel review Effective date: [TO FILL BEFORE PUBLICATION] Version: 0.1-launch-draft
This document lists the subprocessors and service providers OVIO expects to use at launch and summarizes security measures. It supplements the Privacy Policy and Data Processing Addendum.
Do not publish this document until counsel, engineering, and operations verify the production vendor list, regions, data categories, and vendor terms.
1. Important Role Note
Some providers below act as subprocessors where OVIO processes personal data for a business under the Data Processing Addendum. Some providers also act as independent controllers for their own regulated activities, fraud prevention, payment processing, billing, security, or legal compliance.
The final public list must identify the role accurately for each vendor and flow.
2. Launch Vendor List
| Provider | Purpose | Personal data categories | Role to confirm | Region / location to confirm |
|---|---|---|---|---|
| Supabase | Authentication, database, storage, and backend services | Account, profile, booking, order, message, business, support, and log data | Processor/subprocessor | [CONFIRM REGION] |
| Stripe | Payment processing, Checkout, subscriptions, Connect onboarding, refunds, disputes, tax support where enabled | Payment metadata, account identifiers, billing details, connected-account data, tax metadata, fraud/dispute data | Processor and/or independent controller depending on flow | [CONFIRM REGION] |
| Resend | Transactional and permitted marketing email | Email address, name, message content, delivery events, unsubscribe/suppression data | Processor/subprocessor | [CONFIRM REGION] |
| Vercel | Hosting, deployment, edge/network services, logs, web analytics where enabled | IP address, device/browser data, logs, page/event data where analytics is enabled | Processor/subprocessor | [CONFIRM REGION] |
| Google Analytics | Analytics where configured and consented | Device and usage events, identifiers, approximate location, page/activity data | Processor/controller status to confirm | [CONFIRM REGION] |
| Mapbox | Maps, geocoding, location search, directions where enabled | Addresses, coordinates, map interactions, IP/device data | Processor/controller status to confirm | [CONFIRM REGION] |
[PRODUCT: Add any support desk, CRM, monitoring, logging, error tracking, analytics, A/B testing, session replay, customer chat, cloud storage, AI, accounting, tax, or admin tools before publication.]
3. Data Categories
Depending on feature use, vendors may process:
- Account and authentication data.
- Business identity and public profile data.
- Customer booking, order, queue, event, and message data.
- Payment and subscription metadata.
- Email, notification, and unsubscribe data.
- Location and map data.
- Device, log, analytics, and security data.
- Support, report, moderation, and dispute data.
OVIO does not intend vendors to process unnecessary special-category data. Regulated service categories must be reviewed before launch.
4. Subprocessor Changes
OVIO may add or replace vendors as the service changes. Where required, OVIO will update this list or provide notice of material new subprocessors.
Businesses that have accepted the DPA may object to a material new subprocessor on reasonable data-protection grounds as described in the DPA.
5. Security Measures
OVIO uses technical and organizational measures designed to protect personal data, including:
- Authentication and account access controls.
- Role-based business staff permissions.
- Separation between customer, business, and administrative access.
- Encryption in transit.
- Managed hosting and database infrastructure.
- Service-role restrictions for privileged operations.
- Webhook signature verification for Stripe and email webhooks where configured.
- Logging and monitoring for operational and security events.
- Cookie-consent controls for analytics where required.
- Environment separation for development and production.
- Least-privilege access practices for internal tools.
- Incident response and escalation procedures.
No online service can guarantee absolute security.
6. Payment Security
Payments are processed through Stripe where enabled. OVIO does not store full card numbers. Stripe-hosted or Stripe-backed payment flows may collect payment, identity, tax, fraud-prevention, and connected-account information under Stripe's terms and notices.
Paid marketplace bookings must not be enabled until the Stripe Connect charge pattern and payout responsibility match the product implementation and public payment wording.
7. Email Security and Suppression
OVIO may use Resend or another email provider for transactional and permitted marketing emails. Marketing emails must include unsubscribe where required. Suppression records may be retained to honor opt-outs and prevent unwanted marketing.
8. Incident Response
If OVIO becomes aware of a security incident affecting personal data, OVIO will investigate and take steps appropriate to the nature of the incident. Where required, OVIO will notify affected businesses, users, regulators, or other parties within required timeframes.
Business notification under the DPA may be provided in phases as information becomes available.
9. Contact
- Security: [SECURITY EMAIL]
- Privacy: [PRIVACY EMAIL]
- Legal notices: [LEGAL EMAIL]