Subprocessors
Every third party that can reach data we process on a publisher's behalf, what it does for us, and what it can see. Six vendors, and one company that people expect to find here and should not.
A subprocessor is a company we use to run the service that can, as a consequence, reach personal data a publisher has entrusted to us. This is the whole list. It is short on purpose: every vendor on it is one whose removal would stop the product working.
| Subprocessor | What it does | What it can reach | Where |
|---|---|---|---|
| Neon | Managed Postgres. The database behind everything. | All application data: the cached record projection, publisher accounts, view configuration, viewer session emails and the access log. | United States, AWS us-east-2 (Ohio) |
| Vercel | Application hosting and the network in front of it. | Every request and response, which includes the contents of any published view it serves. | United States |
| Trigger.dev | Runs our background jobs: the scheduled check against Attio, backfills, and applying an edit — the one job that writes to a publisher's workspace. | Record values while a job is running, and job metadata. Record values are not written to job logs. | United States |
| Resend | Transactional email: password resets, email verification, viewer sign-in links, team invitations and requests to join a workspace, release-list confirmations, partner program messages, payment reminders, and account notices such as the weekly digest, usage alerts and a view that paused itself. | Recipient email addresses and the contents of those messages. | United States |
| Unthread | Support chat. The bubble on this website and in the publisher dashboard, and the helpdesk behind it. | Whatever you type into a chat, and what loading it involves: your IP address, your browser, and which page you were on. Your email address if you are signed in. It runs on no published view, so it reaches no cached record and nothing from an Attio workspace. | United States |
| Stripe | Payments: subscriptions to paid plans, invoices, and the cards they are paid with. | Publisher billing contact and payment details. Card details go to Stripe directly and never reach our servers. | United States |
Attio is not a subprocessor
This one gets asked every time, so it is answered here rather than in a footnote. Attio is the publisher’s own system and the source of the data. We read from it under an OAuth connection the publisher authorised and write back to it only when the publisher approves an edit, or when they have configured a view to apply edits without approval. We are not sending anybody’s data to Attio that Attio does not already hold, so it belongs in the description of the processing rather than in the list of vendors we hand data to.
Our own CRM, and what we put in it
We are a company with customers, so we keep a customer record: who signed up, which workspace they run, which plan they are on, and product milestones such as publishing a first view, inviting a teammate, running into a plan limit or changing a subscription. That record lives in our own Attio workspace, which we operate ourselves. It is not a vendor we hand you to, which is why it is described here rather than in the table above.
What goes into it is account data, never view data. Your name, your email address, your workspace name and the fact that something happened in the product. No cached records from your Attio workspace, nothing a viewer did on a published view, no viewer email addresses, and no contents of any view. The boundary is structural: the code that sends these events cannot reach the record cache, and the automated checks that run on every change are what keep that true.
This is ordinary business record-keeping, not advertising. We do not sell it, we do not share it, and it feeds no ad platform. If you would rather we did not keep product milestones against your account, email support@publicviews.app and we will stop.
What is not on this list, and would be if it existed
- No third-party analytics. Visit counts are recorded in our own database. There is no analytics vendor, on the marketing site or on published views. The chat widget in the table above is the only third-party script this website loads, and it is there to answer you rather than to measure you.
- No advertising or tracking pixels. Anywhere.
- Nothing third-party on a published view. The chat runs on this website and in the publisher dashboard. A published view loads no vendor script at all, because the people who open one are the publisher’s audience and not ours, and putting our support chat on somebody else’s client portal is not a decision we get to make for them.
- No identity vendor. Sign-in runs inside our own application against our own database. Sign in with Attio asks Attio, which already holds your Attio account, to confirm who you are; no other identity provider is involved.
- No AI or machine learning vendor. Customer data and cached records are not sent to any model, ours or anyone else’s, and are not used for training.
- No third-party CRM and no email marketing tool holding your data. The support desk is Unthread, in the table above, and what you write in a chat is used to answer you and for nothing else. We do keep our own record of you as a customer, in our own CRM, run by us. What reaches it is described below.
Changes to this list
Before we add or replace a subprocessor, we will update this page and email publishers who have asked to be told. A publisher may object on reasonable data protection grounds, and the objection route is in the draft DPA. To be added to that notification list, email support@publicviews.app.
What is still missing
- The precise processing region each vendor operates in, confirmed with the vendor rather than inferred from where we provisioned the account. The database region is verified; the rest say United States and are being confirmed.
- The legal entity name and address of each subprocessor.
- A link to each vendor’s own DPA and subprocessor list.
- A stated notice period for a change, expressed as a number of days.
- The transfer mechanism covering these vendors, which is the same open item as in the DPA.