Status: In force Effective date: 6 September 2026 Version: 1.0
This document lists the subprocessors and service providers OVIO uses and summarizes the security measures OVIO applies. It supplements the Privacy Policy and Data Processing Addendum.
1. Important Role Note
Some providers below act as subprocessors where OVIO processes personal data for a business under the Data Processing Addendum. Some providers also act as independent controllers for their own regulated activities, fraud prevention, payment processing, billing, security, or legal compliance.
The final public list must identify the role accurately for each vendor and flow.
2. Launch Vendor List
| Provider | Purpose | Personal data categories | Role to confirm | Region / location to confirm |
|---|---|---|---|---|
| Supabase | Authentication, database, storage, and backend services | Account, profile, booking, order, message, business, support, and log data | Processor/subprocessor | EU (Ireland, eu-west-1) |
| Stripe | Payment processing, Checkout, subscriptions, Connect onboarding, refunds, disputes, tax support where enabled | Payment metadata, account identifiers, billing details, connected-account data, tax metadata, fraud/dispute data | Processor and/or independent controller depending on flow | Global, including the United States |
| Resend | Transactional and permitted marketing email | Email address, name, message content, delivery events, unsubscribe/suppression data | Processor/subprocessor | Global, including the United States |
| Vercel | Hosting, deployment, edge/network services, logs, web analytics where enabled | IP address, device/browser data, logs, page/event data where analytics is enabled | Processor/subprocessor | EU (Frankfurt and Dublin) with a global CDN |
| Google Analytics | Analytics where configured and consented | Device and usage events, identifiers, approximate location, page/activity data | Processor/controller status to confirm | Global, including the United States |
| Mapbox | Maps, geocoding, location search, directions where enabled | Addresses, coordinates, map interactions, IP/device data | Processor/controller status to confirm | Global, including the United States |
| Sentry | Application error and performance monitoring | Error reports and stack traces, which may contain user, business, and booking identifiers, IP address, request metadata | Processor/subprocessor | Global, including the United States |
| OpenAI | AI phrasing, classification, and text embeddings for already-computed facts | Business and listing text, message and review text where a feature sends it, derived embeddings | Processor/subprocessor | Global, including the United States |
| Google Cloud Translation | Machine translation of business-authored content into supported languages | Business-authored text such as service names, event titles and descriptions | Processor/subprocessor | Global, including the United States |
| Google Maps Platform (Routes) | Travel time and route calculation for arrival guidance | Origin and destination coordinates, travel mode, request metadata | Processor/controller status to confirm | Global, including the United States |
| Apple | In-app purchase and subscription processing, transaction verification, and server notifications, where in-app purchase is enabled | Purchase and subscription history, store transaction identifiers, an app account token linking a purchase to a business | Independent controller for the purchase; processor for transaction data returned to OVIO | Apple Inc., United States |
| Google Play | In-app purchase and subscription processing, purchase verification, and real-time developer notifications, where in-app purchase is enabled | Purchase and subscription history, purchase tokens, an obfuscated account identifier linking a purchase to a business | Independent controller for the purchase; processor for purchase data returned to OVIO | Google LLC, United States |
Apple and Google Play engage only where in-app purchase is enabled in the mobile apps. Where a store processes the purchase it acts as the merchant of record and is an independent controller for that transaction; OVIO receives purchase and subscription state back and processes it to grant the business its plan.
This list is reviewed and updated whenever OVIO adds, replaces, or removes a provider that processes personal data.
3. Data Categories
Depending on feature use, vendors may process:
- Account and authentication data.
- Business identity and public profile data.
- Customer booking, order, queue, event, and message data.
- Payment and subscription metadata.
- Email, notification, and unsubscribe data.
- Location and map data.
- Device, log, analytics, and security data.
- Support, report, moderation, and dispute data.
OVIO does not intend vendors to process unnecessary special-category data. Regulated service categories must be reviewed before launch.
4. Subprocessor Changes
OVIO may add or replace vendors as the service changes. Where required, OVIO will update this list or provide notice of material new subprocessors.
Businesses that have accepted the DPA may object to a material new subprocessor on reasonable data-protection grounds as described in the DPA.
5. Security Measures
OVIO uses technical and organizational measures designed to protect personal data, including:
- Authentication and account access controls.
- Role-based business staff permissions.
- Separation between customer, business, and administrative access.
- Encryption in transit.
- Managed hosting and database infrastructure.
- Service-role restrictions for privileged operations.
- Webhook signature verification for Stripe and email webhooks where configured.
- Cryptographic verification of App Store server notifications against Apple's certificate chain, and of Google Play notifications before any purchase is honoured; store purchase state is always re-read from the store's own API rather than trusted from the device.
- Logging and monitoring for operational and security events.
- Cookie-consent controls for analytics where required.
- Environment separation for development and production.
- Least-privilege access practices for internal tools.
- Incident response and escalation procedures.
No online service can guarantee absolute security.
6. Payment Security
Payments are processed through Stripe where enabled. OVIO does not store full card numbers. Stripe-hosted or Stripe-backed payment flows may collect payment, identity, tax, fraud-prevention, and connected-account information under Stripe's terms and notices.
Paid marketplace bookings must not be enabled until the Stripe Connect charge pattern and payout responsibility match the product implementation and public payment wording.
7. Email Security and Suppression
OVIO may use Resend or another email provider for transactional and permitted marketing emails. Marketing emails must include unsubscribe where required. Suppression records may be retained to honor opt-outs and prevent unwanted marketing.
8. Incident Response
If OVIO becomes aware of a security incident affecting personal data, OVIO will investigate and take steps appropriate to the nature of the incident. Where required, OVIO will notify affected businesses, users, regulators, or other parties within required timeframes.
Business notification under the DPA may be provided in phases as information becomes available.
9. Contact
- Security: support@ovioapp.com
- Privacy: support@ovioapp.com
- Legal notices: support@ovioapp.com