Subprocessor List

Last updated: 28 July 2026

1. About this list

To provide FreightVIS, we engage trusted third parties ("subprocessors") to perform certain functions on our behalf. Some of these may store or process personal information that we handle for our customers. This page lists those subprocessors, the function they perform, and the location(s) where they may process data.

This list supports our Privacy Policy and, for customers who require one, our Data Processing Addendum. We require each subprocessor to commit to data-protection obligations substantially equivalent to those we owe our customers, and we take steps reasonable in the circumstances for any overseas disclosure, consistent with Australian Privacy Principle 8.

2. How we notify of changes

We update this page when we add or replace a subprocessor. Customers can request advance notification of changes by contacting support@freightvis.com.

3. Infrastructure subprocessors

  • Supabase — database hosting (PostgreSQL), authentication, and file storage. Processes account, operational, and Customer Data.
  • Vercel — application hosting and cookieless usage analytics. Processes technical and aggregated usage data; global edge network.

4. Service subprocessors

  • Stripe — payment processing for subscriptions and client invoice payments (PCI DSS-compliant). Processes billing and payment data.
  • Xero — accounting integration, enabled only when you connect your Xero account. Processes invoice and timesheet data at your direction.
  • MYOB — accounting integration, enabled only when you connect your MYOB account. Processes invoice data at your direction.
  • Google Maps Platform — address autocomplete, geocoding, routing, and distance calculations. Processes address and location data.
  • Resend — delivery of transactional and notification email. Processes recipient email addresses and message content.
  • Upstash — rate limiting to protect the Service against abuse. Processes technical request metadata.
  • Sentry (Functional Software, Inc., trading as Sentry): error tracking and application performance monitoring. Processes diagnostic telemetry only, namely error messages, stack traces, browser and operating-system metadata, the page address, and an opaque account identifier.

Before any diagnostic event is sent to Sentry, it passes through four scrubbing layers. First, the software development kit is configured to collect no personal information by default, so cookies, request headers and request bodies are never gathered. Second, every event is rewritten before it leaves the platform: user details are reduced to an opaque identifier, cookies, request bodies and local variables are deleted, and credentials, email addresses, payment card numbers and access tokens are redacted. Third, Australian identifiers are redacted specifically, including ABNs, ACNs, mobile numbers and GPS coordinates. Fourth, this scrubbing cannot be switched off by an account administrator: it is locked on in the database, in the settings interface, and again in the browser.

Error tracking is off by default and is enabled per organisation. Session replay (video-style recording of a user's screen) is not enabled.

5. Where data may be processed

Personal information may be processed in Australia and overseas — including in the United States, where several of these providers operate, and in other countries where our subprocessors maintain infrastructure. Processing locations are indicative and may change as providers update their infrastructure. Before disclosing personal information overseas, we take steps that are reasonable in the circumstances to ensure recipients handle it consistently with the Australian Privacy Principles.

To be specific about one distinction that matters: your operational records (jobs, clients, drivers, timesheets, invoices, documents and location history) are held in our primary database, authentication and file storage, which are hosted in Australia. That has not changed. Diagnostic telemetry is different. Error events sent to Sentry are processed outside Australia, principally in the United States. We keep that data to the minimum needed to diagnose a fault, and we scrub it as described in section 4, but we do not want to leave the impression that every category of data stays onshore.

6. Contact

Questions about this list can be sent to:

  • Email: support@freightvis.com
  • Post: FreightVIS, Australia