Subprocessors
Third-party services that process personal data on our behalf to operate Its My Site. This list is for transparency and may be referenced from our Data Processing Agreement when published.
Effective date: 3 August 2026
About this list
We use the vendors below as subprocessors (or equivalent service providers) to host the product, send email, process payments, and — when you choose — sync calendars or run platform analytics. Regions and transfer mechanisms are set by each vendor; see their own terms and data processing documentation for detail.
Related: Privacy Policy · Data Processing Agreement.
Current subprocessors
Supabase
- Purpose
- Authentication, database, and file storage
- Data that may be involved
- Account email and auth data; site and profile content; bookings; CRM contacts and notes; form answers; signed agreements metadata; calendar connection tokens (encrypted at rest); uploaded photos, favicons, and contract PDFs
- Notes
- Core infrastructure for the Service
Vercel
- Purpose
- Application hosting, serverless APIs, and scheduled jobs
- Data that may be involved
- Request and operational data needed to run the site and APIs; domain provisioning metadata when you use a custom domain
- Notes
- Production host for its-my-site.com
Cloudflare
- Purpose
- DNS for the platform domain and inbound email routing
- Data that may be involved
- DNS records; email routing metadata for platform addresses (for example hello@ and legal@its-my-site.com)
- Notes
- Platform operations; not used as an application SDK
Postmark
- Purpose
- Transactional and authentication email delivery
- Data that may be involved
- Recipient email addresses and message content (for example magic-link / OTP, booking confirmations, onboarding setup emails, contact enquiries)
- Notes
- Auth mail via Supabase SMTP; app mail via Postmark API
Stripe
- Purpose
- Platform subscriptions and optional client payments (Connect)
- Data that may be involved
- Billing account and transaction metadata; payment cards are handled by Stripe (we do not store full card numbers)
- Notes
- Used for Pro billing; Connect only when you enable client payments
Google
- Purpose
- Optional Google Calendar sync (availability and booking events)
- Data that may be involved
- OAuth connection data; busy/free intervals; booking events created when a client books (including Meet where supported)
- Notes
- Only when you connect Google Calendar
Microsoft
- Purpose
- Optional Outlook / Microsoft 365 calendar sync
- Data that may be involved
- OAuth connection data; busy/free intervals; booking events created when a client books (including Teams where supported)
- Notes
- Only when you connect Outlook / Microsoft 365
PostHog
- Purpose
- Product analytics on the Its My Site platform
- Data that may be involved
- Usage events and identifiers on marketing, sign-in, onboarding, and dashboard pages
- Notes
- Platform hosts only — not loaded on practitioner public sites. Used when analytics is enabled
Changes
We may update this page when we add, replace, or remove a subprocessor. The “Effective date” above shows when this list was last revised. Material changes may also be communicated by email or in-product notice where appropriate. Questions: hello@its-my-site.com.