Sub-processors
Last updated: May 2026
Template notice: Keep this list in sync with the vendors you actually use. Add a row before you introduce any new processor that touches Customer Data, and announce material changes per your Privacy Policy (typically 14–30 days' notice).
appointments.page uses the following third-party processors to operate the Service. Each handles only the data needed for its function, under a written data-processing agreement (where applicable) or the vendor's standard DPA.
| Processor | Purpose | Data categories | Region |
|---|---|---|---|
| Supabase | Authentication and Postgres database hosting | All tenant data: account, business, service, customer, appointment | United States / Multi-region (AWS) |
| Vercel | Application hosting and edge delivery | Request logs, IP addresses, application payloads in transit | Global edge network |
| Stripe | Payment processing and subscription management | Billing contact, payment method (handled directly by Stripe), subscription state | United States / EU |
| Resend | Transactional email (account, booking confirmations, reminders) | Recipient email, sender business name, message body | United States |
| Sentry | Application error monitoring (optional, when configured) | Error stack traces, request metadata, user ID (scrubbed of PII) | United States / EU |
| Twilio | SMS reminders and notifications (paid plans only) | Recipient phone number, message body | United States |
| Calendar two-way sync (only if you connect your Google account) | Calendar events tied to appointments, OAuth tokens scoped to calendar.events | Global |
Notifications of change
We will notify tenants by email or in-app notice at least 14 days before adding a new sub-processor that has access to Customer Data. Tenants who object may terminate the Service per the Terms of Service. Terms.
Contact
Questions about our sub-processors: support@appointments.page.