Subprocessors
Effective · Version 2026-10-08
WiseHQ uses the third-party services listed below to operate the Service. Each is bound by its own data processing terms or, for public services we use without an agreement (the OpenStreetMap and Esri maps, and Google’s website icons, fonts and YouTube thumbnails), its published privacy and usage policies. Customer data is processed only as needed to deliver the WiseHQ product.
What’s changed (October 8, 2026):Vercel now also counts visits to WiseHQ’s pages for us, without cookies. Record IDs, codes and links’ private parts are removed from every page address it counts.
Active subprocessors
The table below is current as of the effective date above. Before a new subprocessor handles customer data, we list it on this page and announce it in What’s New.
| Service | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Database, file storage, authentication | All customer data (records, files, audit logs) | US East (default); EU on request |
| Vercel | Application hosting, edge functions, CDN; visitor counts (no cookies) | HTTP request metadata, request bodies in transit (not stored); for visitor counts, the page visited with IDs and codes removed, the referring site, browser and device type, and country | Global edge network |
| Stripe | Payment processing, billing portal, tax | Billing email, payment method (held by Stripe — never touches WiseHQ servers), invoices | US |
| Anthropic | AI features (Claude API) | Prompts you submit, with the records they need (e.g. work-order text, asset names, floor plans, photos, meeting transcripts). Without anyone asking: every document you upload — its text, or the image itself for photos and scanned PDFs — to read it and suggest its type and expiry date; work-order text as you type it, to suggest a category; problem reports sent from room and asset QR codes, to write their title and, with that spot’s open work orders, to catch duplicates; each new asset, and an existing one a phone scan is linked to — its name, make, model, serial number, category, notes, install and manufacture dates and condition — to find its photo, manual, build date, service life, replacement cost and maintenance plan (using web search); and what members have written about a vendor in the vendor directory, to summarize it. Anthropic does not retain prompt data beyond 30 days and does not train on customer data. | US |
| Resend | Transactional email (invitations, expiration reminders, password resets) | Recipient email, subject + body of transactional messages | US |
| Planning Center (optional) | Calendar + people sync (only when org connects integration) | OAuth tokens, calendar/people records the org chooses to sync | US |
| Calendar sync + Sign-in with Google (only when you connect or use them); vendor website icons, fonts and video thumbnails (always) | OAuth tokens, calendar event metadata, Google profile (name, email, avatar); a vendor’s website address, to show its icon; your IP address when a page loads a Google font or a YouTube thumbnail | Global (Google infrastructure) | |
| Cloudflare | DNS, DDoS protection at the domain edge | HTTP request metadata (IP, user agent, URL); no request bodies inspected | Global edge |
| OpenAI | Document search | The text of documents you upload, and the questions you search with, turned into search vectors | US |
| Groq | Voice: transcribing videos, recordings and spoken input, and reading replies aloud | Every video you upload (a small, low-resolution copy, sent once to make its searchable transcript); audio you record for transcription; the text of replies that are read aloud | US |
| Google Maps Platform | Address and place lookups, vendor ratings | Addresses and place or vendor names you look up | Global (Google infrastructure) |
| OpenStreetMap Foundation | Maps and address lookups | Addresses you look up; the GPS position of a vehicle’s stops, to name the place; map views (your IP address and the area of the map shown) | UK / EU |
| Esri (ArcGIS) | Satellite map imagery | Map views (your IP address and the area of the map shown) | US |
| Bunny.net | Video hosting and playback | Videos you upload, such as meeting recordings and training videos | EU (company); videos delivered worldwide |
| Calendly | Booking the done-for-you setup call | Your name, email and organization name, when you open the booking calendar (so the form is filled in for you) | US |
Lookups that receive no personal data
These services answer one lookup and receive only what is looked up, from our server: UPCitemdb (a product’s barcode number, to fill in inventory items; the product picture it names is fetched by our server too, so your phone never contacts the retailer that hosts it), Amazon (a product’s ASIN, to fetch its picture for an inventory item, which we then keep ourselves) and the U.S. Department of Transportation’s NHTSA vPIC (a vehicle’s VIN, to fill in its make, model and year).
Optional integrations
Planning Center, and Google sign-in and Google Calendar, are used only when your organization connects them (or a person chooses to sign in with Google). If your organization doesn’t connect an integration, none of its data is shared through it. Google’s website icons, fonts and video thumbnails, listed above, load for everyone.
Sub-subprocessors
Each subprocessor above relies on its own infrastructure providers (e.g. Supabase runs on AWS; Vercel uses AWS / Cloudflare). Those relationships are governed by the subprocessor’s own terms, which are linked above.
Notification of changes
Before a new subprocessor handles customer data, we add it to this page and announce it in What’s New in the app. Questions or concerns about a subprocessor can go to help@getwisehq.com.
Questions
For Data Processing Agreement requests or subprocessor questions: help@getwisehq.com.
Questions? help@getwisehq.com