HOA-OS Sub-Processors
Effective: May 27, 2026
Below is the complete list of sub-processors HOA-OS uses to operate the Service. Each is contractually bound by a Data Processing Agreement (DPA) with confidentiality and security commitments at least as strict as those in our Privacy Policy.
| Vendor | Category | Data handled | Region | Compliance |
|---|---|---|---|---|
| Vercel | Cloud hosting, edge networking | Request metadata, encrypted application traffic | Global edge; primary compute in US-East | SOC 2 Type II, ISO 27001 |
| Supabase | Managed Postgres, authentication, file storage, secrets vault | All persisted application data (encrypted at rest) | US-West-2 (preview), Oregon (prod) | SOC 2 Type II |
| Stripe | Payment processing (subscriptions + HOA dues) | Payment card metadata (full PAN never touches our servers) | Global | PCI DSS Level 1, SOC 2 |
| Plaid | Bank account linking and read-only transaction sync (opt-in) | Bank account metadata + transaction history for connected accounts | US | SOC 2 Type II, ISO 27001 |
| Anthropic | AI inference | AI prompts + responses. PII is pre-stripped only on the form-response and violation AI-review surfaces; chatbot, newsletter, and budgeting surfaces pass authenticated-user context through under Anthropic's Zero Data Retention agreement. | US | SOC 2 Type II |
| Resend | Transactional and newsletter email delivery | Recipient email addresses + message bodies | US + EU | SOC 2 Type II |
| Twilio | SMS notification delivery (opt-in) | Recipient phone numbers + message text | Global | SOC 2 Type II |
| Lob | Physical mail delivery (opt-in) | Recipient mailing addresses + letter contents | US | SOC 2 Type II |
| Cloudflare | DNS and bot protection (Turnstile) | Request headers, Turnstile challenge tokens | Global edge | SOC 2 Type II, ISO 27001 |
| Sentry | Error monitoring | Error stack traces, request context (with PII scrubbing) | US | SOC 2 Type II |
| Voyage AI | Embedding generation for vector search | Document text passages for embedding (no user account data) | US | Not publicly certified at time of writing |
| Pexels | Stock photography for community websites | Search query strings only; no customer data | Global CDN | Not publicly certified at time of writing |
| Upstash | Rate-limiting infrastructure (Redis) | IP addresses + request counters | Global | SOC 2 Type II |
| Meta Platforms | Advertising measurement (Meta Pixel) | Page views + Lead/Subscribe events from public marketing + post-checkout pages only (no PII passed; see Privacy Policy §11) | Global | SOC 2 Type II, ISO 27001 |
| Maps and Places APIs (address autocomplete + sponsor location data) | User-typed address fragments during autocomplete; no account identifiers attached | Global | ISO 27001, SOC 2, SOC 3 |