Subprocessors

LedgerGuard uses subprocessors to run core infrastructure, billing, email and notifications, monitoring, optional analytics and identity providers, accounting integrations, and optional document-processing capabilities.

Subprocessor list

These providers may process or store data to deliver the service. Optional rows apply only when the corresponding feature or integration is enabled in your deployment or tenant configuration.

VendorPurposeData categoriesRegion / notes
Amazon Web Services (Textract)OCR for document text extractionDocument images and PDF content submitted for OCR
AppleIdentity provider for Sign in with Apple (via Supabase Auth)OAuth tokens and profile identifiers needed for authentication
Google (Analytics & Tag Manager)Website analytics and tag management (Google Analytics 4 / Tag Manager)Usage and device signals collected under your cookie/consent configurationLoaded in the browser only when permitted by consent settings.
Google (Sign in with Google)Identity provider for Sign in with Google (via Supabase Auth)OAuth tokens and profile identifiers needed for authentication
Hosting providerWeb, API, and worker runtime hostingRuntime environment data; Operational logs and telemetryDeployment-specific provider and region; add trust URL in your subprocessors addendum if required.
Intuit (QuickBooks)Accounting system sync and OAuth for QuickBooks OnlineOAuth tokens; Mapped vendors, bills, payments, and sync metadata your tenant authorizes
OpenAILLM-assisted structured extraction and embeddingsDocument-derived text; Extraction prompts; Embedding inputs where enabled
PagerDutyIncident routing for critical operator alertsAlert titles, descriptions, and routing metadata
Redis hosting providerQueue infrastructure for BullMQ jobsJob payload metadata (organization and document identifiers; processing pointers)Deployment-specific provider and region; add trust URL in your subprocessors addendum if required.
ResendTransactional email, weekly digests, and support inbox inbound/outbound mailEmail addresses; Message content; Inbound webhook metadata
SentryError monitoring and performance tracingApplication error telemetry; Operational trace metadata
SlackOperational alerts to a workspace webhookAlert summaries and diagnostic context posted to the configured channel
StripePayment processing, checkout, and subscription billingBilling identifiers; Payment method references; Subscription and invoice state
SupabaseDatabase, authentication (including SAML and OAuth flows), and object storageUser identity; Tenant metadata; Document files and extracted records

Contact

Questions about subprocessors or data handling can be sent to support. support@ledgerguard.io.