Subprocessor List
Last updated: 2026-07-26
This is the list of third-party services FabWise uses to host, deliver, support, or protect the product. When a subprocessor is added, removed, or materially changes, we update this page and notify subscribed customers where feasible.
To subscribe to subprocessor change notices, email [email protected].
Active subprocessors
| Vendor | Role | Data processed | Region | Security posture |
|---|---|---|---|---|
| Render | Application hosting + PostgreSQL database | Customer account data, users, time records, jobs, customers, operational records, audit logs, and sessions | Oregon (US-West) | SOC 2 Type II attested; Render's posture: https://render.com/security |
| Stripe | Payment processing + subscription management | Billing contact (name, email, address), payment method tokens (cards never stored on FabWise), subscription history, invoice records, webhook events | US (Stripe Inc., Delaware) | PCI DSS Level 1; SOC 1 + SOC 2 attested; Stripe's posture: https://stripe.com/docs/security |
| Postmark (ActiveCampaign) | Email delivery (sending + inbound processing) | Recipient email addresses and email content for transactional, account, billing, product, and marketing communications; inbound support/sales email | US (ActiveCampaign LLC, Chicago) | SOC 2 attested; Postmark's posture: https://postmarkapp.com/eu-data-protection |
| Google Cloud Platform | Object storage for database backups | Encrypted production database backups | US | SOC 1 + SOC 2 + ISO 27001/27017/27018 attested; GCP's posture: https://cloud.google.com/security |
| Cloudflare | CDN / edge proxy + access controls for supporting infrastructure | HTTP request metadata and traffic routed through Cloudflare services | Global edge | SOC 2 Type II + ISO 27001 attested; Cloudflare's posture: https://www.cloudflare.com/trust-hub/ |
| Apple Push Notification Service | iOS push notification delivery | Notification payloads for supervisor mobile workflows | US | Apple's enterprise posture documented at https://www.apple.com/legal/privacy/ |
| Sentry | Application error tracking | Error reports, stack traces, request paths, and diagnostic context needed to investigate production errors | US (Sentry Inc., San Francisco) | SOC 2 Type II attested; Sentry's posture: https://sentry.io/security/ |
| Anthropic | AI features inside the product (Foreman in-app assistant, support email auto-response, daily briefing generation, conversation summarization) + AI-assisted engineering workflows | In-product: the content of messages you send to Foreman, account records the assistant reads to answer you (jobs, customers, shifts, users, settings), inbound support email content, and the operational data summarized into a daily briefing. Personal information is redacted before support conversations are sent. Engineering: limited customer context when manually provided for support or debugging. No direct production database access. | US | Anthropic's trust posture: https://trust.anthropic.com/ |
| OpenAI | Knowledge-base search embeddings; selectable alternative provider for the AI features above | Support questions and help-article text converted to embeddings so the assistant can find the right help article. Personal information is redacted before embedding. If selected as the active AI provider in FabWise's configuration, also processes the in-product content described in the Anthropic row. | US | OpenAI's posture: https://openai.com/security-and-privacy/ |
| xAI | Selectable alternative provider for the AI features above | Only when selected as the active AI provider in FabWise's configuration; then processes the in-product content described in the Anthropic row. | US | xAI's posture: https://x.ai/legal/privacy-policy |
Marketing-website vendors (visitor data only, not customer data)
These vendors operate only on the public marketing website (fabwise.app) for traffic measurement and advertising. They process anonymous marketing-website visitor identifiers and cookie data — no Customer account data and no employee Personal Information, and they never run within the authenticated application or customer shop portals.
| Vendor | Role | Data processed | Region | Security posture |
|---|---|---|---|---|
| Google (Analytics 4 + Google Ads) | Marketing-website traffic analytics + advertising / remarketing | Marketing-website visitor identifiers, cookie data, page-view events | US | Google's posture: https://safety.google/ |
| Meta Platforms (Meta Pixel) | Marketing-website advertising / remarketing | Marketing-website visitor identifiers and cookie data | US | Meta's posture: https://www.facebook.com/privacy/policy/ |
Notification Policy
When a subprocessor is added, removed, or has its scope materially changed, FabWise notifies subscribed customers via email at least 30 days before the change takes effect, where feasible. Customers can subscribe by emailing [email protected].