Legal
Subprocessors
Effective 3 August 2026
Everyone who can touch data on our behalf. Several are conditional — a store that never switches on waivers has no data at SignWell at all, and saying so is more useful than a list that implies otherwise.
| Who | What for | What they see | When |
|---|---|---|---|
| Supabase | Database, authentication and file storage | Everything the product stores | Always |
| Vercel | Application hosting and delivery | Requests in transit; server logs | Always |
| Stripe | Subscription billing, and card payments for stores that use it | Billing contact and card details — card numbers never reach us | Always for billing; per store for payments |
| Resend | Transactional and marketing email | Recipient address and message content | When an email is sent |
| SignWell | Electronic signature on rental waivers | Signer name, email and the signed document | Only for stores running the waivers module |
| Plivo | Text messages — booking reminders, pickup notices | Recipient number and message content | Only for stores that switch on SMS |
| Intuit (QuickBooks) | Accounting sync | Sales, refunds and customer names, as posted to the ledger | Only for stores that connect QuickBooks |
| Anthropic | The back-office assistant | The question asked and the store data needed to answer it | Only when a staff member uses the assistant |
We will give 30 days’ notice by email before adding a subprocessor that handles personal data, so a store that objects has time to say so.
Questions about any of this go to legal@deckpos.com. To see or delete what we hold about you, use Manage my data.