Draft prepared: 2026-07-22
Baalr uses the following third-party service providers (subprocessors) to operate the product. Each is used only for the purpose listed, and only receives the data necessary for that purpose. "Planned" entries reflect providers being adopted as part of moving Baalrto production infrastructure — they don't yet process real data.
| Provider | Purpose | Data involved | Status |
|---|---|---|---|
| Stripe | Payment processing (Stripe Connect) | Payment method details, transaction amounts, payer name/email | Live |
| Resend | Transactional email (sign-in codes, receipts, notifications) | Recipient email address, message content | Live |
| Intuit (QuickBooks Online) | Accounting sync, only for Clubs that connect it | Invoice, payment, and fee records | Sandbox — production pending Intuit app review |
| Vercel | Application hosting | All application data, in transit and at rest on the platform | Planned |
| Postgres provider (Neon or Supabase) | Primary database | All application data | Planned |
| Object storage (Cloudflare R2 or AWS S3) | File storage for uploaded photos, documents, and club logos | Uploaded files | Planned |
| Sentry | Error monitoring | Error reports, which may incidentally include request context | Planned |
| Google Maps Platform | Address autocomplete for facility/event locations (optional) | Address text entered while typing | Live, optional |
We'll update this list before adding or removing a subprocessor that touches customer data. Questions can be sent to [privacy@baalr.ai — pending mailbox setup].