PublicViews

Subprocessors

Every third party that can reach data we process on a publisher's behalf, what it does for us, and what it can see. Six vendors, and one company that people expect to find here and should not.

SubprocessorWhat it doesWhat it can reachWhere
NeonManaged Postgres. The database behind everything.All application data: the cached record projection, publisher accounts, view configuration, viewer session emails and the access log.United States, AWS us-east-2 (Ohio)
VercelApplication hosting and the network in front of it.Every request and response, which includes the contents of any published view it serves.United States
Trigger.devRuns our background jobs: the scheduled check against Attio, backfills, and applying an edit — the one job that writes to a publisher's workspace.Record values while a job is running, and job metadata. Record values are not written to job logs.United States
ResendTransactional email: password resets, email verification, viewer sign-in links, team invitations and requests to join a workspace, release-list confirmations, partner program messages, payment reminders, and account notices such as the weekly digest, usage alerts and a view that paused itself.Recipient email addresses and the contents of those messages.United States
UnthreadSupport chat. The bubble on this website and in the publisher dashboard, and the helpdesk behind it.Whatever you type into a chat, and what loading it involves: your IP address, your browser, and which page you were on. Your email address if you are signed in. It runs on no published view, so it reaches no cached record and nothing from an Attio workspace.United States
StripePayments: subscriptions to paid plans, invoices, and the cards they are paid with.Publisher billing contact and payment details. Card details go to Stripe directly and never reach our servers.United States

Attio is not a subprocessor

This one gets asked every time, so it is answered here rather than in a footnote. Attio is the publisher’s own system and the source of the data. We read from it under an OAuth connection the publisher authorised and write back to it only when the publisher approves an edit, or when they have configured a view to apply edits without approval. We are not sending anybody’s data to Attio that Attio does not already hold, so it belongs in the description of the processing rather than in the list of vendors we hand data to.

Our own CRM, and what we put in it

We are a company with customers, so we keep a customer record: who signed up, which workspace they run, which plan they are on, and product milestones such as publishing a first view, inviting a teammate, running into a plan limit or changing a subscription. That record lives in our own Attio workspace, which we operate ourselves. It is not a vendor we hand you to, which is why it is described here rather than in the table above.

What goes into it is account data, never view data. Your name, your email address, your workspace name and the fact that something happened in the product. No cached records from your Attio workspace, nothing a viewer did on a published view, no viewer email addresses, and no contents of any view. The boundary is structural: the code that sends these events cannot reach the record cache, and the automated checks that run on every change are what keep that true.

This is ordinary business record-keeping, not advertising. We do not sell it, we do not share it, and it feeds no ad platform. If you would rather we did not keep product milestones against your account, email support@publicviews.app and we will stop.