On this page
1. How to read this list
A direct subprocessor is a third party FacturaOS engages to process Customer Personal Data on our behalf when providing the service. The direct-subprocessor list below is complete for providers currently engaged by FacturaOS in that role.
This page does not repeat every downstream provider engaged by a direct subprocessor; those relationships are governed by the direct subprocessor's data-processing terms and published subprocessor list. A provider listed in the separate role-dependent section is not a FacturaOS subprocessor when it determines its own purposes for the identified function.
The providers involved in a particular account depend on the feature, platform, authentication method, market, and configuration used. A listed provider receives personal information only when needed for the applicable service.
2. Current authorized direct subprocessors
The following providers may process Customer Personal Data on behalf of FacturaOS under written data-protection terms:
- Supabase Pte. Ltd. and applicable affiliates (Supabase) — managed application-backend services, including authentication, database, private file storage, and server-side processing. Typical data: account identifiers, workspace and operational Customer Data, files, permissions, and technical logs. Company location: Singapore. Primary customer-data processing occurs in the United States or the selected project region, with onward providers identified in Supabase's published data-processing materials.
- Vercel Inc. — application hosting, content delivery, request routing, web execution, and related security services for FacturaOS public sites and hosted software. Typical data: web requests, IP address, device and request metadata, application content processed in transit, and technical logs. Company location: United States. Processing may also occur across Vercel's disclosed network and subprocessor locations.
- Plus Five Five, Inc. (Resend) — transactional delivery of supported invoice and service emails and related delivery events. Typical data: sender and recipient email, business display information, message subject and body, invoice-related content selected for delivery, provider message identifier, delivery status, and technical metadata. Company location: United States. Processing may also occur in Resend's disclosed subprocessor locations.
- Google LLC — optional Google Analytics measurement and Firebase Analytics and Crashlytics mobile measurement and diagnostics, to the extent Google processes personal information on behalf of FacturaOS under applicable data-processing terms. Typical data: privacy-limited event values, app-instance or browser identifiers, device and browser information, approximate region, crash diagnostics, and IP address in network transmission. Company location: United States. Processing may occur in Google and disclosed subprocessor locations.
- Stripe, LLC and applicable Stripe affiliates — FacturaOS subscription billing and payment-platform functions, including supported customer-membership Online Checkout, only to the extent Stripe processes personal information on behalf of FacturaOS under applicable data-processing terms. Typical data: billing or membership customer contact, account, price, subscription, invoice and transaction identifiers, limited payment-method details, renewal and status information, device information, and technical or risk signals. Company location: United States. Processing may occur in Stripe and disclosed service-provider locations. Stripe's separate controller functions are described below.
- RevenueCat, Inc. — App Store transaction validation, subscription-entitlement management, purchase restoration, subscription lifecycle events, and related technical support for the iOS in-app purchase flow. Typical data: FacturaOS app user identifier; Apple product, transaction, original-transaction, purchase, expiration, renewal, cancellation, billing-issue, refund, revocation, storefront, and environment information; entitlement status; device and app metadata; IP address in network transmission; and technical logs. RevenueCat does not receive full App Store payment credentials. Company location: United States. Processing may occur in RevenueCat and its disclosed subprocessor locations.
3. Role-dependent and independently controlled services
For the functions below, the provider may act as an independent controller, a separate service selected by the user, or in another role defined by its own terms. These functions are not treated as subprocessing merely because the provider also appears above in a different role.
- Stripe, LLC and applicable Stripe affiliates — Stripe may act as an independent controller for regulated payments, connected-account onboarding, customer-membership recurring payments, identity and business verification, fraud prevention, disputes, reserves, compliance, and payouts. Payment credentials, recurring-payment authorization, identity documents, bank details, tax information, device information, and risk signals submitted through Stripe components are collected directly by Stripe under its terms.
- Evertec Group, LLC and applicable affiliates (Evertec / ATH Móvil) — when an eligible workspace activates ATH Móvil Business, Evertec owns and operates the selected payment service and may act independently under its terms. Merchant credentials, business and invoice identifiers, payer or phone information entered through the provider payment flow, transaction amount and description, device or network data, status, refunds, disputes, and risk signals may be processed to initiate, authorize, verify, settle, reconcile, secure, and support the transaction. Current ATH Business Terms and Conditions are published at https://ath.business/en/terminos.
- Google LLC — Google sign-in when selected and the external Google Maps handoff when a user chooses to open route directions. Google receives authentication information or route information needed for the selected service and handles it under Google's terms and privacy notices.
- Apple Inc. — Sign in with Apple when selected, application-store distribution, and App Store in-app purchases. For purchases, Apple independently handles the Apple Account, payment credentials, storefront, taxes, transaction and subscription records, billing, renewals, cancellations, refund requests, fraud prevention, and legal compliance under its terms and privacy notices. FacturaOS receives only the limited transaction and entitlement information described in the Privacy Policy.
4. Disclosure scope and security
This list provides the provider identity, processing purpose, typical data, role, and broad location needed for privacy and contractual transparency. It does not disclose FacturaOS credentials, account or project identifiers, private endpoints, software versions, exact system topology, or internal security configuration. A provider's inclusion does not authorize access beyond the applicable service and contractual purpose.
5. Locations, safeguards, and provider terms
Provider locations and downstream subprocessors may change under their published terms. Where Applicable Data Protection Law requires a transfer mechanism, the FacturaOS DPA governs the required cooperation and the provider's applicable transfer terms and safeguards also apply.
Business customers needing provider-specific processing, transfer, or safeguard documentation may contact privacy@facturaos.com. Each provider's current privacy notice, data-processing terms, and published subprocessor or service-provider list provide additional details.
6. Changes, advance notice, and objections
Before a new or replacement direct subprocessor begins processing Customer Personal Data, FacturaOS will actively notify the account owner or designated privacy contact by email at least 15 days in advance. Updating this page alone does not replace active notice. If advance notice is impracticable because of an emergency, security need, legal requirement, or provider replacement needed to avoid material service disruption, notice will be provided as soon as reasonably practicable.
A business customer may object during the notice period by writing to privacy@facturaos.com and explaining reasonable data-protection grounds. FacturaOS will address the objection as described in the Data Processing Addendum. Provider entity names, locations, infrastructure, and downstream subprocessors may change under provider terms without changing FacturaOS functionality.