Subprocessor and Service-Provider List
Effective date: 2026-08-02
This list identifies the third-party providers that may process personal data to run the Service. Actual use depends on the features a Venue uses. Each provider is engaged under a data-processing agreement and, where a restricted transfer is involved, an appropriate transfer mechanism.
Provider set
| Provider | Purpose | Data involved | Main processing/transfer note |
|---|---|---|---|
| Supabase, Inc. | Managed database, authentication, storage and realtime | Accounts, venue configuration, menus, orders, loyalty, chat and logs | Primary database configured in Frankfurt; provider support/operations may require transfer safeguards |
| Vercel, Inc. | Application hosting, edge delivery and security | Requests, IP/user-agent, cookies and application responses | Edge processing may occur globally; SCC/UK safeguards where required |
| Google LLC / Google Ireland Ltd. | Google OAuth | Name, email, provider identifier and sign-in metadata | Used only when the user chooses Google sign-in |
| Google LLC / applicable Google entity | Gemini live voice | Audio in transit, transcript/context, output and tool-call data | ExcuseMe does not store raw audio; regional routing and transfer terms depend on contracted configuration |
| Anthropic, PBC | Text ordering assistant | Prompts, menu/order context, typed messages, output and tool calls | Business API and transfer safeguards required; chat is retained by ExcuseMe for 30 days |
| OpenAI, L.L.C. | Menu import, menu/knowledge embeddings and translation | Venue-provided menu/knowledge text or images and derived vectors/translations | Not authorised for chat or Realtime voice; business API/transfer safeguards required |
| Resend / Plus Five Five, Inc. | Transactional email | Recipient address, name and message contents | Invites, receipts, security, billing and rights-request messages |
| Google Workspace / applicable Google entity | Company email and document operations | Support/legal correspondence and business documents | Access restricted to authorised ExcuseMe personnel |
Billing provider
None. EXCUSEME DOO invoices Venue subscriptions itself and is paid by bank transfer, so no third-party merchant of record, payment processor or checkout provider receives Venue billing data. Our bank executes the transfer as an independent controller under its own terms, in the same way it would for any supplier invoice; it is not a subprocessor of the Service.
If a card-payment option is introduced, the provider will be listed here before it is enabled.
A feature not enabled for a Venue's plan or market, and any integration not listed above, does not receive production data.
Representatives
A GDPR Article 27 representative, where ExcuseMe appoints one, is a statutory contact point — not a subprocessor, a Data Protection Officer, or a Digital Services Act representative. Any appointed representative's details are published in the Privacy Policy.
Changes and objections
We normally give business Controllers at least 30 days' notice before a new/replacement subprocessor begins processing, except an urgent legal/security replacement. A Controller may make a reasoned data-protection objection under the DPA. Removed providers are taken out of the production registry and data is deleted/returned under contract and retention rules.
Questions and notification requests: privacy@excuseme.pro.