1. Current subprocessors
| Subprocessor | Purpose | Data categories | Location | When it applies |
|---|---|---|---|---|
| Supabase (database, authentication, storage) | Primary application database, account authentication, and file storage. | Account and login data, organization and location records, business profile data, run history, findings, reviews, content drafts, encrypted OAuth tokens. | United States | Whenever the related tool runs. |
| Cloudflare (application hosting / edge runtime) | Serves the web application and runs server-side functions and scheduled endpoints. | Request metadata (IP address, user agent), data in transit for each request. | Global edge network | Whenever the related tool runs. |
| Stripe | Subscription billing, checkout, credit-pack purchases, customer billing portal. | Billing contact, subscription and invoice records, payment card data (collected and stored by Stripe, never by us). | United States / EU | Whenever the related tool runs. |
| Google LLC — Google Business Profile API | Reads and updates the customer's Google Business Profile: hours, categories, posts, reviews, insights. | Business profile fields, posts, review content and replies, profile performance metrics. | United States | Only after the customer connects Google via OAuth. |
| Google LLC — PageSpeed Insights API | Core Web Vitals field data for site audit rules. | Customer website URLs. | United States | Whenever the related tool runs. |
| Google LLC — Google Analytics Data and Admin APIs | Reads aggregate traffic-by-source figures to count real clicks arriving from citations. | Analytics property identifiers and aggregate traffic metrics for the customer's website. | United States | Only after the customer connects Google Analytics and grants read access. |
| Google LLC — Google Places API | Competitor review counts and place verification for audit rules. | Business names, place IDs, public review counts. | United States | Whenever the related tool runs. |
| Google LLC — Gemini API | Generates draft content and prose explanations; answers AI-visibility test prompts. | Business profile details, audit findings, prompt text. No student data. | United States | Whenever the related tool runs. |
| OpenAI API | Draft content generation and AI-visibility measurement prompts. | Business profile details, prompt text, findings summaries. | United States | Whenever the related tool runs. |
| Anthropic API | Draft content generation and AI-visibility measurement prompts. | Business profile details, prompt text, findings summaries. | United States | Whenever the related tool runs. |
| Perplexity API | AI-visibility measurement and question mining. | Prompt text containing business name and service area. | United States | Whenever the related tool runs. |
| xAI (Grok) API | AI answer engine for visibility measurement: records whether Grok mentions the customer's school. | Prompt text containing business name, services, and service area. | United States | Whenever the related tool runs. |
| SerpApi | Search and Google Maps result measurement for local pack, grid, and keyword tools. | Search queries containing business name, services, and locality. | United States | Whenever the related tool runs. |
| Moz API | Domain authority and link metrics for competitor and link tools. | Customer and competitor domain names. | United States | Whenever the related tool runs. |
| Local Falcon | Geo-grid rank measurement across map points. | Business name, place ID, coordinates, keywords. | United States | Only when a Local Falcon key is configured. |
| Meta Platforms, Inc. (Facebook and Instagram) | Publishes scheduled posts and reads post insights for connected accounts. | Page/account identifiers, access tokens, post content, post metrics. | United States | Only after the customer connects the account via OAuth. |
| TikTok (TikTok for Business API) | Publishes scheduled content and reads post metrics. | Account identifiers, access tokens, post content, post metrics. | United States | Only after the customer connects the account via OAuth. |
| X (formerly Twitter) | Publishes scheduled posts and reads post metrics. | Account identifiers, access tokens, post content, post metrics. | United States | Only after the customer connects the account via OAuth. |
| LinkedIn API | Publishes scheduled organization posts and reads post metrics. | Organization identifiers, access tokens, post content, post metrics. | United States | Only after the customer connects the account via OAuth. |
| Pinterest API | Publishes scheduled pins and reads pin metrics. | Account and board identifiers, access tokens, pin content, pin metrics. | United States | Only after the customer connects the account via OAuth. |
| Google LLC — YouTube Data API | Publishes and reads video metadata and performance for the connected channel. | Channel identifiers, access tokens, video metadata, video metrics. | United States | Only after the customer connects the account via OAuth. |
The application sets no advertising, analytics, or cross-site tracking services. There is no separate marketing-email platform in the product; account emails (confirmation, password reset) are sent by the authentication provider listed above.
2. Change notification
We will update this page and email account owners at least 30 days before adding or replacing a subprocessor that processes personal data. Customers may object on reasonable data protection grounds as described in section 6 of the Data Processing Addendum.
Questions about this list: brad@driveredconsultants.com.