◆ Legal · Sub-processors
Sub-processors
These are the third-party services Zayos uses to operate. Each has a Data Processing Addendum (DPA) covering the transfer of personal data; each is reviewed for security posture before we onboard them.
Last updated: 2026-05-11
| Provider | Role | Region | DPA |
|---|---|---|---|
Supabase Postgres database, magic-link authentication, file storage (menu photos, brand logos, media library). All customer and operator data, hashed credentials, file metadata. | Database + Auth + Storage | United States (AWS us-east region) | DPA → |
Vercel Runs the Next.js application across our four projects (marketing, storefront, admin, operator). Request/response logs, IP addresses, error traces. | Application hosting + edge | Global (edge); USA primary | DPA → |
Cloudflare Domain resolution, edge CDN, layer-7 DDoS + WAF. IP addresses, request metadata. | DNS + CDN + bot mitigation | Global | DPA → |
Stripe Card processing for customer orders; per-tenant Connect account flows funds to the restaurant. Card tokens, billing addresses, transaction metadata (never raw PAN). | Payments + payouts (Stripe Connect) | United States | DPA → |
Resend Magic-link emails, password reset, order receipts, review-request emails, customer survey invites, owner invitations. Recipient email, email body, delivery status. | Transactional email | United States | DPA → |
Twilio Order status SMS (received / ready / delivered), one-time passwords for customer auth. Recipient phone, message body, delivery status. | Transactional SMS | United States | DPA → |
Anthropic AI shift briefing, menu-item description generation, menu photo critique, review-response drafting, support-ticket triage, invoice OCR, PDF menu import. Operator-submitted text + images; never customer payment data. | AI model API (Claude) | United States | DPA → |
Google (Places + Business Profile) AI restaurant audit autocomplete, nearby competitor lookup, Google review polling for the operator inbox, eventual response posting. Operator-supplied place IDs; public business data returned by Google. | Business data + review polling | United States | DPA → |
Inngest Scheduled crons (Google review polling, expire stale announcements, post-delivery survey send, retention sweeps). Job metadata; minimal payload (org IDs, order IDs). | Durable job queue | United States | DPA → |
Otter When a tenant connects Otter, we receive marketplace order events (DoorDash, Uber Eats, Grubhub) + 86-list state + payout reports. Order data, fulfillment events, payout amounts. | POS + marketplace integration | United States | DPA → |
Sentry Captures unhandled exceptions + performance traces from our four Vercel projects. Stack traces, request metadata; we redact PII before send. | Error monitoring | United States | DPA → |
Notification of changes
We'll publish updates to this page before adding a new sub-processor. Enterprise customers can request advance notification (typically 30 days) via the DPA addendum.
Questions
Email abdallah@zayrev.com for DPA requests, sub-processor verification, or to flag a security concern.