TerraVex

TerraVex Subprocessors

Last updated: October 7, 2026

This list is incorporated into the Data Processing Addendum (https://app.terravexos.com/legal/dpa) as Annex III and is the single source of truth for the vendors that process data for TerraVex. Each is bound by a written agreement that requires it to give personal data the same or equal protection as our Privacy Policy and the DPA, and to use it only to provide its service to TerraVex. To receive notice of changes by email, write to privacy@terravexos.com; Customers' admin addresses are emailed at least 30 days before a subprocessor is added or replaced, as described in Section 6.3 of the DPA.

Subprocessors we use

SubprocessorPurposeData processedRegionNotes
SupabaseApplication backend: database, authentication, serverless functions and file storageAll Customer Data at rest and in transit through the platform, including property plans, inspection photos, application records and uploaded documentsUnited StatesCore hosting provider; data encrypted at rest and in transit; daily backups
NetlifyWeb hosting and content delivery for app.terravexos.com and terravexos.comRequest metadata (IP address, user agent) in access logs; website contact-form submissionsUnited StatesServes the application; no Customer Data stored
StripeSubscription billing; payment processing and Stripe Connect payouts for Customers' invoices; platform fee collectionPayment and payout metadata; cardholder data handled directly by Stripe (PCI)United StatesCustomer is merchant of record on its connected account
TwilioClick-to-dial calling and SMS messagesPhone numbers, message/call metadata and content initiated by the Customer, and text consent statusUnited StatesOptional; Customer-enabled. A Customer may instead connect its own Twilio account
ResendTransactional and client email delivery, including sign-in codes, service records and invoicesRecipient email, subject, and message contentUnited States
SentryError and performance monitoring for the web app and backend functionsError details, the page, recent actions before the error, device and browser type, and the signed-in user's ID, email, company ID and role; performance timings for about 5% of sessionsUnited StatesError reports kept up to 90 days
OpenAIAI features: vision estimating from photos and video frames, walkthrough voice-note transcription, note polishing, and staff-only course draftingPhotos and video frames, walkthrough audio, notes and transcripts, and the generated outputs; sent only after the person gives permission in the appUnited StatesTerms prohibit training on inputs and outputs; inputs may be kept up to 30 days for abuse monitoring; see the AI Features Disclosure (https://app.terravexos.com/legal/ai)
GoogleOptional Sign in with Google; web fonts (Google Fonts); address geocoding (Google Maps Platform)For sign-in, the user's Google account email and name; for fonts, the viewer's IP address and browser type; for geocoding, property addresses and derived coordinatesUnited States
OpenStreetMap FoundationGeocoding (Nominatim) when Google geocoding is not configured or is unavailable; map images on the jobs mapProperty address text (geocoding); the viewer's IP address, browser type and the map area shown (map images)United KingdomSingle low-volume queries with attribution, under OpenStreetMap's usage policies
Browser push services (Apple, Google, Mozilla)Delivering push notifications to browsers that have turned them onThe browser's push address; notification content is encrypted end to end and unreadable to the push serviceUnited StatesOptional; user-enabled in the browser
AppleOptional Sign in with AppleThe user's Apple account email (or relay address) and nameUnited StatesOptional; user-chosen
RentCastProperty-data lookup for estimatingProperty address and returned property attributes (for example square footage)United StatesOptional
Better StackUptime monitoring and the public status pageNone beyond the availability of public endpointsUnited States

Services used only if you connect them

These services hold their own accounts with the Customer. Data moves between TerraVex and the service only after the Customer connects it, and only at the Customer's direction.

ServicePurposeData processedRegionNotes
QuickBooks (Intuit)Optional accounting synchronizationInvoice, customer and financial records the Customer chooses to syncUnited StatesCustomer-connected
CheckrOptional background checks and drug screeningCandidate name, email, phone and work location, sent when a Customer orders a screening, including from the new hire flow; consent and the report itself are handled on Checkr's own pages; TerraVex receives the report's status, Checkr's recommended outcome label and a link to the reportUnited StatesCustomer-connected to its own Checkr account
FingercheckOptional payroll and HR connection: adding new hires and sending hoursNew hire name, email, phone, start date, job title, pay type and base pay rate, sent when the Customer adds a hire to Fingercheck; hours, overtime and time off per pay period, sent from the Timesheet; TerraVex keeps only the Fingercheck employee number. Tax and direct-deposit forms are completed on Fingercheck's own onboarding, not in TerraVexUnited StatesCustomer-connected with keys from its own Fingercheck account
GustoOptional payroll connection: sending hours and reading pay ratesTeam member names, hours, overtime, time off and pay ratesUnited StatesCustomer-connected to its own Gusto account

Web addresses a Customer sets up to receive its own data through the Service's API keys or webhooks (for example an automation tool) are chosen and controlled by the Customer and are not TerraVex subprocessors.

Onward subprocessors used by the providers above are governed by their respective agreements.

Change log