How to use this overview
This overview explains the providers named in Soffyt’s published privacy policy and the information involved in their service functions. The processing that applies to your organization depends on the features and connections you use. Provider names here identify services; they do not establish a complete contractual inventory, a contracting legal entity, or a processing location.
Read the full privacy policyHosting, database, and file storage
These services support delivery of the application and storage of workspace information:
- Vercel — application hosting. Application requests can involve information submitted to or retrieved from Soffyt, alongside network, request, and operational information needed to serve and troubleshoot the application.
- Supabase — database, authentication, and private file storage. These functions involve account and organization information, authentication records, customer and job records, enabled live-location and time records, vehicle and service history, documents, attachments, and associated metadata stored in the workspace.
Service email delivery
Resend supports service email delivery. Delivery involves the recipient address, sender details, message content, and delivery information for messages sent through that service. This service is separate from a Google or Microsoft mailbox that a user or organization connects to Soffyt.
Uploaded-file scanning
Where scanning is enabled, the configured scanning provider receives uploaded content for threat checks. Soffyt supports Scanii as a scanning provider. The information involved includes the file content and technical information required for the scan; file contents can themselves contain customer or personal information.
- Scanning depends on the service configuration. Listing Scanii here does not confirm that scanning is active for every deployment or file path.
- The actual scanner and applicable processing locations must be confirmed in the processing inventory for your service.
Email and document connections
Your organization or an authorized user chooses whether to connect these accounts. Access follows the permissions presented by the provider and the features used in Soffyt.
- Google email and Microsoft email — authorized account identity, mailbox content, participants, attachments, message metadata, and connection credentials support the connected email features. Review mailbox sharing and workspace permissions before connecting an account containing personal or confidential correspondence.
- Google Drive and Docs — a separate authorization supports document templates. The integration handles selected or created documents, account identity, document identifiers and content, previews, and connection credentials. Publishing a template stores a version in Soffyt for use in customer documents.
- Disconnecting stops future access through the connection. It does not automatically delete records already stored in Soffyt or originals retained by the connected provider.
Payments and maps
These services support enabled payment and map features:
- Stripe — connected payment accounts and online customer payments. Payment flows involve connected-account identifiers, invoice amounts and references, transaction status, and related payment information. Customers enter card details through Stripe-hosted checkout; Soffyt uses the resulting references and transaction information.
- Google Maps — address and map features where configured. Searches, addresses, or location information used in those features, including coordinates used for a live dispatch map, and browser/network information can be sent to Google to provide the requested result. Loading a map is separate from authorizing an email or document account.
Provider roles and processing locations
A provider can process information on Soffyt’s behalf for one activity and independently for another. For example, a provider may administer its own account or payment service under its own terms. Calling a service an integration does not remove subprocessor obligations for processing it actually performs on Soffyt’s behalf.
- A United States customer relationship does not mean all hosting, provider operations, or remote support takes place only in the United States.
- Review the applicable schedule for provider identity, purpose, data categories, and processing locations, including relevant remote access. Establish any required location restrictions in writing before the affected processing begins.
Your processing schedule and provider changes
When the published data processing agreement is accepted, its terms require a written subprocessor schedule before processing begins. That schedule identifies the providers, purposes, data categories, and locations applicable to the agreed service. This public overview supplies context and does not replace that schedule.
- The published DPA provides at least 30 days’ written notice before a new or replacement subprocessor processes customer data, with an opportunity to raise reasonable data-protection objections. The accepted agreement governs the notice and objection process.
- A change to this webpage alone does not replace an agreed notification or acceptance procedure.
- For a processing review, email privacy@soffyt.com with your legal business name, intended features, authorized contact, and any location or vendor requirements. Request the current schedule and relevant supporting information before approving processing.