1. Current providers
| Provider | Service | Data involved | Location / safeguards |
|---|---|---|---|
| Supabase, Inc. Privacy · DPA | Managed authentication, PostgreSQL database, private file storage and edge functions | Accounts, project records, photos/files, access permissions, audit history and function requests | Primary storage region selected for the FinishLedger project; provider support and subprocessors may operate internationally under contractual safeguards |
| Vercel Inc. Privacy · DPA | Website and web-application hosting, deployment and content delivery | Web requests, IP/technical delivery data, static application files and limited runtime requests | Global content-delivery infrastructure and provider locations, using applicable transfer safeguards |
| Resend, Inc. Privacy · DPA | Transactional account, invitation and workflow email delivery | Recipient email, sender, subject, message content, delivery status and technical email events | Provider infrastructure and subprocessors may operate internationally under its DPA and transfer safeguards |
Exact provider entities, regions and transfer details may depend on the contracted plan and should be confirmed in the Customer order form for regulated or location-restricted deployments.
2. Provider changes
FinishLedger may add or replace a provider to improve security, reliability or functionality. Material changes will be posted here. Commercial Customers may provide a legal notice email in their order form to receive advance notice where reasonably practicable.
Reasonable data-protection objections should be sent promptly to hello@finishledger.com.
3. Customer-controlled recipients are different
Project members, invited users, people receiving one-ticket links, email recipients, WhatsApp recipients and exported-report recipients are selected by the Customer or its users. They are not FinishLedger subprocessors. The Customer is responsible for choosing lawful recipients and secure channels.