Subprocessors
Last updated: September 2026
This page lists key subprocessors that help OwnersPal deliver and operate the Service. These vendors may process personal or business data only as needed to provide infrastructure, billing, communications, security, and platform integrations.
| Vendor | Purpose | Data categories | Region |
|---|---|---|---|
| Supabase | Authentication and application data storage | Account profile data, auth identifiers, business profile data, generated content metadata | Global |
| Stripe | Subscription billing and payment processing | Billing identifiers, subscription status, payment metadata, invoicing records | Global |
| Resend | Transactional email delivery | Email address, message metadata, delivery and bounce events | US |
| Postmark | Transactional / fallback email delivery | Email address, message content and metadata, delivery events | US |
| Railway | Backend API hosting and runtime infrastructure | Application logs, request metadata, operational diagnostics | US |
| Vercel | Frontend hosting, delivery, and consented analytics | Site request metadata, performance telemetry, consented analytics events | Global |
| Sentry | Error monitoring and performance diagnostics | Error traces, technical diagnostics, limited request context | Global |
| Fal / model providers | Model-inference gateway (queue.fal.run) for short ad-video rendering and Brand Photoshoot photo enhancement (relight, background removal, upscaling, depth-aware cropping, product shots). Routes each image-to-video job to the model selected for the shot: Kling (Kuaishou), Seedance (ByteDance), Veo (Google), Grok (xAI), Vidu, Wan, or MiniMax H3 (an open-weight MiniMax model). Runway is not brokered through Fal — it is a direct integration (see the Runway row). | Business photo URLs and text prompts submitted for rendering or photo enhancement, photos of your team you choose for product-holding shots, generation-job metadata, and output video and image references | Global |
| Runway | Direct image-to-video rendering for short ad clips (api.dev.runwayml.com). Called directly by OwnersPal, not routed through Fal. | Business photo URLs and text prompts submitted for rendering, generation-job metadata, and output video references | US |
| ElevenLabs (via Fal) | Voice-hook text-to-speech for video ads (opt-in feature; preset voices only, no voice cloning) | Short text strings derived from your business profile (business name, hours, CTA) sent for synthesis; no customer or review content | US |
| OpenAI | Text + vision inference for AI features (captions, image intelligence, content safety analysis) + website content extraction (menus, team, FAQ, About, customer testimonials) + monthly AI-visibility probing (Presence+) + on-site AI assistant answers | Prompts, uploaded images submitted for composition + safety analysis, generated outputs, request and response metadata, website page text submitted for content extraction, business category/city/name submitted for AI-visibility probing and the returned answer's mention + competitor-name extraction, visitor questions sent to the on-site AI assistant | US |
| Headless render endpoint (optional) | Renders JavaScript-only (single-page-app) business websites so we can read their menu and photos when the page injects content client-side. Off by default; only used when an operator configures a render endpoint, and only against the business's own public site. | The business's own public website URL (no personal data) | Global |
| Twilio | SMS and WhatsApp messaging delivery | Phone numbers, message content metadata, delivery and status events | Global |
| MessageBird | Failover SMS delivery for operational alerts (opt-in) | Recipient phone number, message content | EU |
| Google APIs (Business Profile, Ads, YouTube) | OAuth integrations and connected platform operations | OAuth tokens, connected account identifiers, campaign and posting metadata, Google Business Profile reviews (cached for the optional review-overlay feature when enabled by the owner) | Global |
| Google Ads tag and conversion upload | Ad-conversion measurement for a business that connects a Google Ads account: its own Google Ads tag on its OwnersPal website, loaded only at the website's main address after the visitor accepts marketing cookies there and sends no Global Privacy Control signal, plus a once-a-day upload of its attributed bookings as Google Ads click conversions | From the visitor's browser, after marketing-cookie consent: the events the business's own Google Ads tag sends — a page view carrying the IP address, browser and device information, the page address and referring page, and Google's ad-click cookie identifiers (such as _gcl_aw, _gcl_au and _gcl_gs, stored on the website's main address only, plus a _gcl_ls entry in the browser's local storage). The tag's requests to Google's servers (such as google.com, googleadservices.com and doubleclick.net) also carry, and may set, Google's own cookies on Google's domains (such as IDE and NID), which Google controls. If the business has turned on enhanced conversions in its own Google Ads account, the tag may also send a hash of contact details entered into the website's forms. From our servers, once a day, per attributed booking: a SHA-256 hash of the customer's email/phone, the campaign click id (gclid), the booking time and an internal booking reference — contact details never leave in the clear and the hash is never stored | Global |
| Google Places API | Server-side business enrichment — looks up a business's public Google listing to import details, photos, and reviews (places.googleapis.com). Uses an API key, separate from the owner's OAuth Google connection. | Business name, place ID, and location queries sent to Google; in return, public listing data ingested including reviewer display names, review text, and business photos with their author attributions | Global |
| Google Maps (embedded map) | When a business shows a location map on its OwnersPal website, the visitor's browser loads an embedded Google Maps frame (maps.google.com). OwnersPal makes no server-side call for it; the iframe is a third-party data flow on page view. | The visitor's IP address and user-agent (sent by the browser to load the embedded map); the business's public address or map query | Global |
| YouTube (embedded video) | When a business embeds its own YouTube video on its OwnersPal website, the visitor's browser loads the clip from YouTube. We use the privacy-friendly youtube-nocookie.com host, which doesn't set a tracking cookie until the visitor presses play. OwnersPal makes no server-side call to YouTube for this. | The visitor's IP address and request metadata (sent by the browser to load the embedded video); the public video ID | Global |
| Vimeo (embedded video) | When a business embeds its own Vimeo video on its OwnersPal website, the visitor's browser loads the clip from Vimeo's player (player.vimeo.com). OwnersPal makes no server-side call to Vimeo for this. | The visitor's IP address and request metadata (sent by the browser to load the embedded video); the public video ID | Global |
| Meta APIs (Facebook/Instagram) | OAuth integrations and connected platform operations | OAuth tokens, connected account/Page/Instagram-business identifiers, the video/image content and captions we publish on your behalf, Page and ad-campaign performance metrics, and — when a connected Page or Instagram account receives one — the text and author name of inbound comments and direct messages, which we mirror into your OwnersPal inbox | Global |
| Meta Pixel and Conversions API | Ad-conversion measurement for a business that connects a Meta ad account: its own Meta Pixel on its OwnersPal website, loaded only when the website's main address is the business's own domain name itself (not an ownerspal.app address or an address under another domain) and only after the visitor accepts marketing cookies there and sends no Global Privacy Control signal, plus a once-a-day upload of its attributed bookings to the Meta Conversions API | From the visitor's browser, after marketing-cookie consent at the business's own domain: the events the business's own Meta Pixel sends — a page view carrying the IP address, browser and device information, the page address and referring page, and Meta's first-party cookie identifiers (_fbp, _fbc, placed on that domain); the Pixel's automatic event detection is switched off. The Pixel's requests to Meta's servers (facebook.com, facebook.net) also carry, and may set, Meta's own cookies on Meta's domains, which Meta controls. If the business has turned on automatic advanced matching in its own Meta account, the Pixel may also send a hash of contact details entered into the website's forms. From our servers, once a day, per attributed booking: a SHA-256 hash of the customer's email/phone, the campaign click id (fbclid), the booking time and an internal booking reference — contact details never leave in the clear and the hash is never stored | Global |
| Microsoft Ads | OAuth integrations and connected platform operations | OAuth tokens, connected account identifiers, campaign and conversion metadata | Global |
| Yelp | OAuth integrations and connected platform operations | OAuth tokens, connected business identifiers, review and listing metadata | US |
| TikTok | OAuth integrations and connected platform operations | OAuth tokens, connected account identifiers, post and engagement metadata | Global |
| Nextdoor | OAuth integrations and connected platform operations | OAuth tokens, connected business identifiers, post and reply metadata | US |
| X (Twitter) | OAuth integrations and connected platform operations | OAuth tokens, connected account identifiers, post and engagement metadata | Global |
| OAuth integrations and connected platform operations | OAuth tokens, connected organization Page identifiers, post and engagement metadata | Global |
We update this list as vendors and subprocessors change.