Unreviewed draft · not in force
A lawyer has not read this page.
This document was drafted in-house, against how the product is actually built, so that a lawyer has something specific to review. That review has not happened yet. It is not in force, it is not a contract, and nothing here binds you or us. It will change before launch. If you need something you can rely on today, write to help@publicviews.app and ask for it.
Drafted 20 August 2026 · never reviewed · never in force
Subprocessors
Every third party that can reach data we process on a publisher's behalf, what it does for us, and what it can see. Five vendors, and one company that people expect to find here and should not.
A subprocessor is a company we use to run the service that can, as a consequence, reach personal data a publisher has entrusted to us. This is the whole list. It is short on purpose: every vendor on it is one whose removal would stop the product working.
| Subprocessor | What it does | What it can reach | Where |
|---|---|---|---|
| Neon | Managed Postgres. The database behind everything. | All application data: the cached record projection, publisher accounts, view configuration, viewer session emails and the access log. | United States, AWS us-east-2 (Ohio) |
| Vercel | Application hosting and the network in front of it. | Every request and response, which includes the contents of any published page it serves. | United States |
| Trigger.dev | Runs our background jobs: the scheduled check against Attio, backfills, and applying an approved edit. | Record values while a job is running, and job metadata. Record values are not written to job logs. | United States |
| Resend | Transactional email: password resets, email verification, and viewer sign-in links. | Recipient email addresses and the contents of those messages. | United States |
| Stripe | Payments. Not switched on yet, because billing is not switched on yet. | Publisher billing contact and payment details. Card details go to Stripe directly and never reach our servers. | United States |
Attio is not a subprocessor
This one gets asked every time, so it is answered here rather than in a footnote. Attio is the publisher’s own system and the source of the data. We read from it under an OAuth connection the publisher authorised and write back to it only when the publisher approves an edit. We are not sending anybody’s data to Attio that Attio does not already hold, so it belongs in the description of the processing rather than in the list of vendors we hand data to.
What is not on this list, and would be if it existed
- No third-party analytics. Page view counts are recorded in our own database. There is no analytics vendor, on the marketing site or on published pages.
- No advertising or tracking pixels. Anywhere.
- No identity vendor. Sign-in runs inside our own application against our own database, so no third party holds your login.
- No AI or machine learning vendor. Customer data and cached records are not sent to any model, ours or anyone else’s, and are not used for training.
- No support desk, CRM or email marketing tool holding customer data today. Support is an inbox. If that changes, this list changes first.
Changes to this list
Before we add or replace a subprocessor, we will update this page and email publishers who have asked to be told. A publisher may object on reasonable data protection grounds, and the objection route is in the draft DPA. To be added to that notification list, email help@publicviews.app.
What is still missing
- The precise processing region each vendor operates in, confirmed with the vendor rather than inferred from where we provisioned the account. The database region is verified; the rest say United States and are being confirmed.
- The legal entity name and address of each subprocessor.
- A link to each vendor’s own DPA and subprocessor list.
- A stated notice period for a change, expressed as a number of days.
- The transfer mechanism covering these vendors, which is the same open item as in the DPA.
The other drafts