Subprocessors
Last updated August 12, 2026. This is our own document, written by the operator of BroomDesk. It is not legal advice from a law firm, and it is not a substitute for advice about your own business.
The short version
- These are the companies that see some of your data because they help run BroomDesk. There are nine of them and no others.
- Each is here because the product genuinely needs it: somewhere to run, somewhere to store data, a way to take payments, a way to send texts and email, maps, AI, error reports and rate limiting.
- We give account owners 14 days notice by email before adding or replacing one.
- Two more appear only if you connect them yourself: QuickBooks and Google Calendar.
The summary is here to be read. The full text below is what applies.
Current subprocessors
A subprocessor is a company we use to deliver BroomDesk that processes personal data on our behalf. Each one is bound to use the data only to provide its service to us. This list is part of the data processing addendum.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Vercel | Application hosting, edge network, scheduled jobs | All request traffic in transit, server logs including IP address | United States |
| Supabase | Postgres database, authentication, file storage | All stored customer data, login credentials as hashes, job photos | United States, AWS us-east-1 |
| Stripe | Subscription billing for BroomDesk, and Stripe Connect for the payments your clients make to you | Billing contact, card details, invoice and payment records | United States and Ireland |
| Twilio | SMS delivery and inbound voice for the toll-free numbers | Phone numbers, message content, call metadata | United States |
| Resend | Transactional email delivery | Recipient email addresses, email content, delivery events | United States |
| Anthropic | AI receptionist replies, photo quoting and other AI features, called server side only | The conversation text or photo the feature needs, and nothing else | United States |
| Google (Maps Platform) | Geocoding, drive times for routing, time zone lookup | Service addresses and coordinates | United States |
| Sentry | Error monitoring, configured not to attach personal data | Stack traces, request paths, release and browser metadata | United States |
| Upstash | Redis for rate limiting on sign-in, widgets and the API | IP addresses and request counters, held for the window length | United States |
Optional, only if you connect them
These process data only after you or one of your team authorises the connection, and only for as long as it stays connected. Disconnecting stops the flow. Once data reaches them it is governed by their own agreement with you.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Intuit (QuickBooks Online) | Accounting sync, only if you connect it | Customers, invoices and payments you choose to sync | United States |
| Google (Calendar API) | Calendar sync, only if a user connects their Google account | Visit times, titles and addresses for that user | United States |
Two things this list does not include
- Web push notifications. When a cleaner enables push on their phone, notifications travel through the push service run by their browser vendor, which is Google, Apple or Mozilla depending on the device. The payload is encrypted with keys only the browser holds, so the push service can see that a message went to a device but not what it said.
- Website analytics. Plausible is running today. It counts page views on the public pages of broomdesk.com for every visitor, on the live site only. It is deliberately not in the table above, and the reason is what a subprocessor is: a company that processes personal data on your behalf. Plausible processes none of yours. It is never loaded inside the application, so it does not run on a single screen where your clients, visits, invoices or messages exist. It sets no cookie and stores nothing on a visitor's device. What it receives is that a marketing page was viewed and which site linked to it. Listing it as a subprocessor of your data would misdescribe it, and would suggest we hand it something we do not. The cookie policy describes exactly what it does, and the data processing addendum records the same decision. If it is ever replaced by something that runs inside the app, sets a cookie or follows people across sites, that goes in the table above first and account owners get the usual 14 days notice.
Changes and objections
Before we add or replace a subprocessor, account owners get at least 14 days notice by email and this page changes. If you have a reasonable data protection objection, write to support@broomdesk.com within those 14 days. We will look for an alternative, and if there is not one you may terminate the affected part of the service, export your data, and have the unused portion of what you paid refunded.
Transfers outside the EEA and the UK are covered by the standard contractual clauses set out in the data processing addendum.
Questions
Questions about a provider on this list, or an objection to one. Email support@broomdesk.com, or use the contact form. We reply within one business day.
BroomDesk is operated by Amortoae Petru PFA (CUI 52361814), Romania. Postal address and registration details are on any invoice we issue you through Stripe.