Skip to content

Legal record / effective August 12, 2026

Subprocessor record

Service-provider categories and purposes relevant to Invarent production infrastructure, billing, security, communications, and optional analytics.

Direct answer

Invarent limits service providers to defined operational purposes and does not authorize them to use customer data for their own advertising. The exact providers enabled for a customer can depend on the order, deployment, region, and optional features.

01

Supabase

Managed PostgreSQL, authentication, backup, and recovery infrastructure. Account, tenant, identity, configuration, financial, audit, workflow-support, and recovery records may be processed as needed for the service.

02

Production compute and networking

A contracted infrastructure host runs the API, web, worker, workflow, cache, proxy, monitoring, and operational services. Tailscale supports restricted operator networking and Let's Encrypt provides public TLS certificates.

03

Stripe

When billing is enabled, Stripe processes customer and subscription identifiers, checkout, payment methods, invoices, and metered billing events. Invarent does not store complete card numbers.

04

Sentry

Sanitized API and worker error telemetry may be processed to detect and repair failures. In-process controls remove application user, request, payload, and sensitive accounting context before transmission.

05

Google Analytics

When a visitor affirmatively allows public analytics and the property is configured, GA4 processes public page and limited conversion events. GA4 is excluded from authenticated financial portal views and must not receive personal or financial event parameters.

06

Change notice

Material subprocessor additions will be published here or communicated through the contracted channel before use when required. Questions or objections may be sent to privacy@invarent.com.

Next action

Put the record in front of the right owner.