Legal
Subprocessors
Last updated:
visyoner engages a small number of third-party service providers ("subprocessors") to operate the Service. Each subprocessor is bound by a written data-processing agreement, receives only the data necessary for its function, and is named below so you can review its own privacy practices. This page is the authoritative list and is referenced from Section 3 of the Privacy Policy.
Several subprocessors are located in the United States. Where this is the case, your personal information is transferred outside Canada when it is processed by them. We have reviewed each transfer and rely on the safeguards listed in the right-hand column, as well as data minimization (sending the smallest viable subset of data to each provider), to protect your information. See Section 4 of the Privacy Policy for the full cross-border-transfer disclosure.
| Subprocessor | Purpose | Data shared | Location | Safeguard |
|---|---|---|---|---|
| Plaid Inc. | Financial-institution connectivity (transactions, balances, holdings). | Banking credentials entered into Plaid Link, returned transaction and account data, institution metadata. | United States | Plaid Data Processing Addendum; SOC 2 Type II. |
| Stripe, Inc. (incl. Stripe Payments Canada, Ltd.) | Subscription billing and payment-method storage. | Billing name, email, address, Stripe customer identifier, payment-method tokens. Card numbers go directly to Stripe and are not stored by us. | United States, with Canadian processing through Stripe Payments Canada, Ltd. | Stripe Data Processing Addendum; PCI-DSS Level 1. |
| OpenAI, L.L.C. | AI chat assistant and spending-insight generation. | Chat messages, system prompt, and the transaction context retrieved to answer each question. | United States | OpenAI API Data Processing Addendum; data is not used to train OpenAI models. |
| Functional Software, Inc. d/b/a Sentry | Application error monitoring. | Stack traces, request metadata, user identifier. Personal data is scrubbed client- and server-side before transmission. | United States | Sentry Data Processing Addendum; SOC 2 Type II. |
| Laravel Nightwatch (Tighten LLC) | Application performance monitoring and queue/job observability. Used to surface slow requests, queue backlogs, failed jobs, and database-query hotspots; complementary to Sentry, which covers exception telemetry. | Request paths and methods, response status and timing, the authenticated user identifier (no email or name), database query shape (SQL + timing, no parameter values by default), queue job class names and outcomes, and console command runs. | United States | Tighten LLC privacy policy; SQL parameter bindings disabled by default; per-user data limited to opaque integer id matching the Sentry posture. |
| Zendesk, Inc. | Customer-support ticketing. | Support ticket content, attachments, requester name and email. | United States | Zendesk Master Subscription Agreement and Data Processing Agreement. |
| Laravel Forge / Laravel VPS (Tighten LLC) | Server provisioning, deployment orchestration, and operational management. Production runs on the "Laravel VPS" product, which is a Forge-managed Ubuntu server delivered through Tighten's infrastructure partnership with DigitalOcean (see next row for the underlying compute provider). | Environment variables (database credentials, API keys), application source at deploy time, server logs accessible via the Forge dashboard, and SSH access metadata. | United States | Forge Terms of Service and Privacy Policy; SSH-key-based server access; production env vars never written to source control. |
| DigitalOcean, LLC | Underlying cloud-compute provider for the Laravel VPS instance described above. The application database, file storage, queue, and application runtime live on a DigitalOcean droplet that Tighten provisions and manages on our behalf. | Everything stored or processed by the application at rest and in transit through the droplet: user records, transactions, AI chat sessions, support tickets, encrypted Plaid tokens, and all other persisted state. | Production droplet runs in DigitalOcean's Toronto (TOR1) data centre, so application data at rest is physically located in Canada. DigitalOcean, LLC itself is US-incorporated — US authorities may have legal reach over the parent company under the CLOUD Act even though the servers are on Canadian soil. | DigitalOcean Data Processing Agreement; SOC 2 Type II; ISO 27001; PCI-DSS for the payment-relevant subset; encryption in transit (TLS) and at rest at the disk level. |
| Mailtrap (Railsware Products Inc.) | Transactional and (when the recipient has opted in) marketing email delivery. Sends every email visyoner generates: verification, password reset, sync alerts, household invitations, data-export download links, billing receipts, and inactivity re-engagement. | Recipient email address, message subject and body (which may include account information, transaction summaries, and household activity), delivery and bounce metadata. | European Union | Mailtrap Data Processing Agreement; SOC 2 Type II; TLS in transit; bounce/complaint suppression. |
| Conva Ventures Inc. d/b/a Fathom Analytics | Privacy-first marketing analytics. Counts pageviews and a small catalog of named CTA-click events on the public landing surface (Hero / Why / How / Pricing / FinalCta variants) so we can measure conversion and iterate on copy. No in-app product events are sent to Fathom today; see docs/requirements/event-tracking.md for the Phase 2 plan. | URL path, referrer, approximate country (derived from IP), device type, browser family, and the event name (e.g. "Demo CTA Hero"). Does not include cookies, does not include user identifiers, and IP addresses are hashed with a daily-rotating salt before any record is written — so the same visitor on two consecutive days appears as two unrelated rows. | Conva Ventures Inc. is incorporated in Canada (Squamish, BC). Data processing for the Fathom Lite product happens through a global CDN that includes United States, European, and Asia-Pacific regions. | Fathom Data Policy (no PII, no cookies, hashed IPs, daily-rotating salt); honors Do-Not-Track; no advertising or cross-site identifiers; GDPR / CCPA / ePrivacy compliant by design (no consent banner required because nothing personal is stored). |
Changes to This List
We will update this page whenever a subprocessor is added, removed, or changed in a way that materially affects how your personal information is processed. The "Last updated" date at the top of this page always reflects the current version. Material changes are also announced by email or in-app notice at least 14 days before they take effect, consistent with the change-notice commitment in our Privacy Policy.
Questions
For questions about a specific subprocessor or to request additional information about the safeguards in place, contact our Privacy Officer at [not configured].