Subprocessors

Last updated: July 6, 2026

1. What this page is

This page lists the third-party service providers ("subprocessors") that Dispatch Bros Inc. currently uses to operate the Platform. Each row describes the provider, the role it plays, the categories of data the provider may process on our behalf, where the provider operates at a high level, and a link to that provider's privacy policy.

For more on what data we collect and how we share it, see our Privacy Policy. For the broader rules of use, see our Terms of Service. To request deletion of an account, see our Account Deletion page.

This page lists Dispatch Bros Inc.'s current subprocessors for transparency. If a signed agreement, order form, or data processing addendum applies, that agreement controls. The exact data shared with any specific provider depends on the features a tenant has enabled and on how the tenant configures its workspace.

2. How subprocessors are used

Subprocessors process data only as needed to provide, secure, support, or improve Dispatch Bros and the features that depend on them. Different features rely on different providers, so the data each provider sees depends on which features are enabled and on how a tenant configures the Platform. For example, a tenant that has not enabled WhatsApp will not have any data flowing to Meta's WhatsApp Business Platform.

Each provider listed here also has its own privacy and data-handling practices, which apply to processing on the provider's side. Provider policies are linked in the table.

We do not sell personal information, and we do not share personal information with subprocessors for cross-context behavioral advertising.

3. Current subprocessors

ProviderPurposeData categoriesRegion / notesProvider policy
SupabaseAuthentication, database, realtime, and file storage for the Platform.Account and profile data; tenant customer, job, and finance records; communications metadata and content; uploaded files including job photos and call recordings; support tickets; activity and audit logs; device records; latest technician GPS rows.Provider-controlled / project-configured. See provider policy.supabase.com/privacy
VercelApplication hosting, edge delivery, and request infrastructure for the Platform.HTTP request and response metadata, application traffic, and operational logs.Provider-controlled hosting infrastructure. See provider policy.vercel.com/legal/privacy-policy
StripeSubscription billing for the Platform and (when enabled) Stripe Connect payment processing for tenants who collect payments from their own customers.Billing contact data, payment-method tokens, last four digits and brand of saved cards where applicable, Stripe customer IDs, payment intent IDs, charge IDs, subscription status, and transaction metadata. Card input is sent directly to Stripe; Dispatch Bros does not receive full card numbers.Payment processor; routing handled by Stripe and the payment networks.stripe.com/privacy
TelnyxSMS, voice, WebRTC, phone-number provisioning, call routing, delivery of voice call recordings, and U.S. 10DLC brand/campaign registration.Phone numbers, SMS message bodies and delivery events, voice call metadata, voice media and recording source, SIP / WebRTC credentials, telecom account details, and — for 10DLC registration — tenant business-verification data (legal business name, EIN, business address, and support contact).Telecom provider; carrier and network routing may vary by geography.telnyx.com/privacy-policy
Meta (WhatsApp Business Platform, Facebook Messenger, Instagram)WhatsApp Business Account onboarding, message delivery, templates, webhook events, and — for tenants who connect them — Facebook Messenger and Instagram lead-message delivery.WhatsApp phone numbers, WhatsApp Business Account identifiers, Messenger / Instagram sender identifiers, message bodies, message templates, delivery statuses, and provider payload data.Provider-controlled. Governed by Meta and WhatsApp policies.facebook.com/privacy/policy
Google Maps PlatformAddress geocoding, address autocomplete, mapping, distance / travel-time estimation, and route optimization for routing, ETA features, and dispatch.Customer addresses and typed address fragments, geocoding requests, resulting coordinates, customer / technician coordinates submitted for distance and route-optimization requests, and map / routing usage.Provider-controlled. See provider policy.policies.google.com/privacy
AnthropicAI text generation for in-product features (summaries, message drafts, insights, the AI assistant) and automatic processing: inbound-message closing detection, the AI lead assistant, and conversation summaries.Prompts and contextual payloads, which can include customer names, recent jobs, invoices, estimates, message content, service descriptions, and — for the AI lead assistant — the lead's conversation history and contact details assembled by the Platform.Provider-controlled. See provider policy.anthropic.com/privacy
UpstashRate-limiting infrastructure protecting public and abuse-prone endpoints.Request IP addresses processed transiently as rate-limit keys, together with the rate-limit policy identifier.Provider-controlled. See provider policy.upstash.com/trust/privacy.pdf
ResendTransactional email delivery.Recipient email address, subject line, email body, and metadata for transactional, billing, invoice, and support-related emails.Provider-controlled email infrastructure.resend.com/legal/privacy-policy
Apple Push Notification service (APNs)iOS push notification delivery.APNs device token, the notification payload to be delivered, and basic device / platform metadata required for delivery.Apple-controlled push infrastructure.apple.com/legal/privacy
Google Firebase Cloud Messaging (FCM)Android push notification delivery.FCM device token, the notification payload to be delivered, and basic device / platform metadata required for delivery.Google-controlled push infrastructure.firebase.google.com/support/privacy
Expo push service + browser Web Push servicesPush notification relay for the mobile app (Expo) and for browser notifications (Apple / Google / Mozilla Web Push endpoints).Device push tokens / push subscriptions and the notification payload to be delivered, which can include a sender name and a short message preview.Provider-controlled push infrastructure.expo.dev/privacy

Resend is the active email delivery provider identified in the codebase. SendGrid is not listed as a subprocessor: the `@sendgrid/mail` dependency was previously present in our package manifest with no runtime imports and has since been removed from the codebase. AI features currently use Anthropic; OpenAI is not listed because active production runtime usage of OpenAI was not verified in the application code at the time this page was prepared. We will update this page if either provider becomes actively used.

4. Provider changes

We may add, remove, or change subprocessors as the Platform and its features evolve. We will update this page when we do. The "Last updated" date at the top of the page indicates when the list was last reviewed. We recommend checking this page periodically for changes.

Material changes that affect specific tenants — for example, switching the AI provider or changing the email delivery provider — will also be reflected in our Privacy Policy where appropriate.

5. Questions and contact

If you have questions about this page, want clarification about a specific provider, or want to follow up on a data-related request, contact us:

Privacy / data requests: privacy@dispatchbros.ai

General contact: info@dispatchbros.ai

Mailing address: Dispatch Bros Inc., 2 Mockingbird Cir C1, Houston, TX 77074

Website: app.dispatchbros.ai

This page is informational only and is not legal advice. Tenants should consult their own counsel about their obligations under applicable communications, recording, payment, employment, consumer-protection, and privacy laws.