Subprocessor List

> Scope & status: Part of SiteRevive's SOC2-LITE evidence trail. This is > the current list of third-party services that process data on our behalf. It > is not a certified audit artifact.

_Last reviewed: 2026-07-16_

A subprocessor is a third party that processes workspace or customer data on SiteRevive's behalf in the course of delivering the service. The table below is the current list. We keep it current; material changes are reflected here.

| Subprocessor | Purpose | Data processed | Location / notes | |---|---|---|---| | Supabase | Primary database + authentication + object storage | All workspace data (leads, campaigns, mockups, messages, events, revenue, clients, access logs); user auth identities; stored assets/screenshots | Managed Postgres/Auth/Storage on AWS. Encrypted at rest and in transit. | | Render | Application hosting / compute | No durable data store — request traffic and ephemeral compute for the app and published client sites | Managed PaaS. Stateless app tier; all durable data lives in Supabase. | | Resend | Transactional & outbound email delivery | Recipient email addresses, message content, delivery/open/click events (via signed webhooks) | Email service provider. Inbound event webhooks are Svix-signature-verified. | | Anthropic | AI generation (mockup copy, deck/content generation, reply classification) | Business/lead context needed to generate a mockup or classify a reply (business name, niche, site signals); no bulk personal-data training | Claude API over TLS. Used per-request; not used to train models on customer data. | | Stripe | Billing & payments (SaaS subscriptions, client checkout) | Billing/customer identifiers, subscription and invoice metadata, payment status (via signed webhooks). Card data is handled by Stripe directly — SiteRevive does not store card numbers. | PCI-compliant payment processor. Stripe webhooks are signature-verified. | | Google (Places API) | Local business discovery during lead sourcing | Search queries (geography + niche) and returned public business listings | Google Cloud Places API (New) over TLS. Returns publicly listed business data. | | Microlink | Qualified current-site screenshot capture | Public URLs of qualified prospect websites | Server-side Pro API over TLS. Returned image bytes are validated and copied into SiteRevive-owned Supabase Storage; the provider URL/key is not exposed in reports. Production fails closed while the paid key is absent. | | thum.io _(legacy only)_ | Historical website screenshot URLs | Public URLs of prospect websites already present in legacy reports | No longer trusted for new counted results. A qualified recapture replaces a legacy URL with owned evidence. | | Twilio _(if SMS enabled)_ | SMS delivery (TCPA-gated feature) | Recipient phone numbers and message content, delivery status (via signed webhooks) | Used only when the SMS channel is enabled for a workspace. | | Calendly / Cal.com _(scheduling, tenant-selected)_ | Meeting scheduling for booked demos | Booking metadata correlated to a lead (via leadId in tracking/metadata) | Inbound booking webhooks are HMAC-signature-verified before use. |

Notes

Explicitly not claimed

This list is an evidence artifact, not a certification. It does not by itself constitute a Data Processing Agreement — see the fill-in DPA template, which references this list.