bsns.cc
Sub-processors
Last updated August 25, 2026
The third parties below process bsns.cccustomer data on our behalf. The list is exhaustive for the default deployment; the “optional integrations” section only applies when a tenant has connected the vendor.
A change to this page is a change to source — pull-request reviewable. We commit to giving paid customers 30 days’ notice (via /status and email to tenant admins on file) before a new sub-processor begins processing data.
DPA status legend. Executed a data-processing addendum has been countersigned for bsns.cc, Inc. specifically. Standard termsthe vendor’s published DPA applies via their standard terms and is binding by acceptance. Review pendingthe relationship exists but the DPA hasn’t been reviewed yet. Not applicable the vendor does not process customer personal data on our behalf.
Core infrastructure
These vendors host production, non-production, persistent data, object storage, and independent recovery copies.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Google Cloud | Application hosting for all environments, global load balancing, managed Postgres, object storage, DNS, schedules and queued tasks, secrets, logs, monitoring, and container storage. Google Cloud's published data-processing terms apply. | United States (us-west1) / Global edge | Standard terms |
| Vercel | Operator of disconnected historical Blob stores awaiting verified deletion. No application runtime, project, deployment, or live request path remains. Vercel's published DPA + sub-processor list applies. | United States | Standard terms |
| Vercel Blob | Disconnected historical object custody pending vendor-assisted deletion. Production performs no reads or writes against these stores. Covered by Vercel platform DPA. | United States | Standard terms |
| Cloudflare (R2) | Off-site nightly database backups (business + identity databases) for disaster recovery. Backups are client-side encrypted (age) before upload, so the storage vendor holds ciphertext only; the decryption key is escrowed separately. | United States / Global | Standard terms |
Identity, secrets, and credentials
These vendors hold either authentication factors or operational secrets used to access other systems.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| 1Password | Primary operator-secret store: production credentials, encryption keys, third-party API tokens. Does not store customer PII; operator secrets only. | Canada / United States | Standard terms |
| Bitwarden | Encryption-key escrow with a required local fingerprint guard. Backup of 1Password key material. Does not store customer PII; key escrow only. | United States | Standard terms |
Communications
Email, SMS, and voice providers. Customer message metadata and content transits through these vendors.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Resend | Transactional email delivery (invites, password reset, signing notifications, customer-facing receipts). | United States | Standard terms |
| Twilio | SMS, voice, and call-recording for the loop app. Tenant-configurable; not every tenant uses Twilio. Per-tenant credentials — each customer's traffic rides their own Twilio account when configured. | United States / Global | Standard terms |
| Telnyx | Alternative SMS/voice provider, tenant-configurable; per-tenant selection. | United States / Global | Standard terms |
Payments and financial
Card processing, bank linking, and accounts-receivable rails. Cardholder data does not transit bsns.cc; we hold tokens only.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Stripe | Card and ACH processing for AR invoices in bill and work; subscription billing for the suite itself. PCI scope is minimized by hosted-checkout — full cardholder data never reaches our infrastructure. | United States / Global | Standard terms |
| Plaid | Bank-account linking and balance refresh for the /finance dashboard. Tenant-optional. | United States | Standard terms |
AI and inference
Model providers used by the support agent, workflow copilot, and OCR. Zero-retention configurations preferred where the provider offers them.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Anthropic (Claude API) | Powers the in-app support agent, the workflow copilot, agentic actions behind the AI feature gate, and OCR helpers. Zero-data-retention mode requested where applicable. Tenant opt-in binding; $0 default budget fails closed. | United States | Standard terms |
| OpenAI (API) | Direct API availability fallback for permitted AI assistant, summarization, and extraction features. Restricted Wren Gmail context is Anthropic-only and is not routed to this fallback. | United States | Review pending |
Operational tooling
Caching, rate-limiting, monitoring, and alerting. These vendors see request metadata and operational telemetry but not stored business records.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Upstash (Redis) | Short-lived shared state for auth: rate-limiter counters for login, MFA, password-reset, and invite endpoints, session-revocation records, single-use launch-token IDs, passkey challenges, and a cached sales-tax rate table. Counters and identifiers only (IP, email, user ID, token ID), each with a short expiry; no stored business records. Held on a bsns.cc-owned Upstash account since 2026-08-18, no longer a Vercel Marketplace resource. | United States (us-central1) | Standard terms |
| Better Stack | Uptime monitoring and on-call alerts for public endpoints. Receives URLs and HTTP-status metadata; no payload bodies. | United States / European Union | Standard terms |
| ntfy.sh | Operator-side alert fan-out for cron failures, observability alerts, and incident notifications. Alert payloads are PII-safe by construction (no tenant data, no user identifiers — only the alert type and a request ID). | European Union | Not applicable |
| Healthchecks.io | Independent cron dead-man's switch on a separate provider from Better Stack to avoid single-vendor blind spots. Ping metadata only; no customer data. | United States | Not applicable |
Optional integrations (customer-initiated)
These vendors are involved only when a tenant connects them. A tenant that doesn't use the integration has no data flowing to the vendor.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| Google (Calendar, Gmail, Sign-in) | Calendar sync for the work planner and rsvp booking flow; a user-owned, read-only Gmail private pilot; and optional Sign-in-with-Google for the auth portal. Calendar and Gmail OAuth credentials are encrypted at rest. Gmail content is fetched on demand, not copied into a mailbox index; Wren requires separate consent and sends only explicit, bounded context to Anthropic. Federated sign-in stores the linked provider identity/email, not a reusable Google access token. | Global | Standard terms |
| Apple (Sign in with Apple) | Optional Sign-in-with-Apple for the auth portal (web + the native mobile app). OAuth-based identity verification only; the provider identity token is verified against Apple's JWKS, no Apple account data is stored beyond the linked email. | United States / Global | Standard terms |
| Zoom | Video-conferencing link creation for rsvp bookings when the tenant has connected Zoom. | United States / Global | Standard terms |
| Checkr | Background checks during the crew onboarding flow. Driver / employee PII flows directly to Checkr at the tenant's direction. Per-tenant API keys; each tenant has its own Checkr relationship. | United States | Standard terms |
| Samsara | Optional telematics signals for Crew performance reviews. Retained Ride/Auto integration code is not a production runtime. | United States / Global | Standard terms |
What's not here
A handful of vendors touch the company but never see customer data and so don’t belong on this list: GitHub (source control of code, not data), Anthropic Console (operator-side AI tools used by Graham personally, not embedded in product), analytics on the marketing site only (no authenticated session activity), and standard developer tooling (npm, GitHub Actions). If we add a tool that begins to touch customer data, this list gets a new row before the data starts flowing.
Questions
Email security@bsns.cc for clarification on any row, or to request an executed DPA. For privacy-specific questions, privacy@bsns.cc.