Sub-processors

Last updated: May 2026

Template notice: Keep this list in sync with the vendors you actually use. Add a row before you introduce any new processor that touches Customer Data, and announce material changes per your Privacy Policy (typically 14–30 days' notice).

appointments.page uses the following third-party processors to operate the Service. Each handles only the data needed for its function, under a written data-processing agreement (where applicable) or the vendor's standard DPA.

ProcessorPurposeData categoriesRegion
SupabaseAuthentication and Postgres database hostingAll tenant data: account, business, service, customer, appointmentUnited States / Multi-region (AWS)
VercelApplication hosting and edge deliveryRequest logs, IP addresses, application payloads in transitGlobal edge network
StripePayment processing and subscription managementBilling contact, payment method (handled directly by Stripe), subscription stateUnited States / EU
ResendTransactional email (account, booking confirmations, reminders)Recipient email, sender business name, message bodyUnited States
SentryApplication error monitoring (optional, when configured)Error stack traces, request metadata, user ID (scrubbed of PII)United States / EU
TwilioSMS reminders and notifications (paid plans only)Recipient phone number, message bodyUnited States
GoogleCalendar two-way sync (only if you connect your Google account)Calendar events tied to appointments, OAuth tokens scoped to calendar.eventsGlobal

Notifications of change

We will notify tenants by email or in-app notice at least 14 days before adding a new sub-processor that has access to Customer Data. Tenants who object may terminate the Service per the Terms of Service. Terms.

Contact

Questions about our sub-processors: support@appointments.page.