VesselTwin Subprocessors
Last updated 2026-08-17
1. About this list
A "subprocessor" is a third party that processes personal data on VesselTwin's behalf to deliver the service to you. The list below names each subprocessor, what we use them for, what categories of data they receive, and the primary processing region.
VesselTwin has signed a data-processing agreement (DPA) or operates under an equivalent contractual arrangement (e.g., AWS's account-level DPA) with each subprocessor. Where applicable, EU-to-US transfers are covered by Standard Contractual Clauses or by the relevant data-privacy framework adequacy decision in force at the time.
2. Current subprocessors
| Subprocessor | Purpose | Data received | Region |
|---|---|---|---|
| Clerk, Inc. | User authentication, sign-in, session management, organization membership. | Email, name, avatar URL, password hash, OAuth identifiers, IP address, user agent, sign-in events. | United States (with EU residency option) |
| Svix, Inc. | Signed webhook delivery from Clerk (account events → VesselTwin backend). | Webhook event metadata (Clerk user IDs, event timestamps). No vessel data. | United States |
| Amazon Web Services, Inc. (AWS) | Application hosting (ECS), object storage (S3 + CloudFront CDN), transactional email (SES), SMS delivery (SNS), AI model inference (Bedrock), document database (DynamoDB). | All vessel records, uploaded photos and documents, transactional email content and recipients, SMS message content and recipients, AI inputs (document text + image excerpts sent to Bedrock). | United States (us-east-1 primary) |
| Google LLC (Google Cloud — Vertex AI) | AI model inference for document extraction and content understanding. | Document text and image excerpts sent for extraction. Configured with data-residency and no-training settings (see §3). | United States / EU (configurable per request) |
| Vercel, Inc. (AI Gateway) | AI model request routing — proxies inference requests to upstream model providers (e.g., Anthropic, OpenAI) under VesselTwin's account. | AI inputs in transit; logged for operational metrics only, not retained for training. | United States |
| Anthropic, PBC | AI model inference — applies when the AI Gateway routes a request to a Claude model. | Whichever AI inputs were routed to a Claude model (document text, image excerpts). Anthropic API terms prohibit using API inputs/outputs to train their models by default. | United States |
| Cloudflare, Inc. | Web app hosting (Cloudflare Pages) and CDN for static assets. | HTTP request metadata (IP address, user agent, requested path) for static asset and page delivery. No vessel content stored at Cloudflare. | Global edge network |
| PostHog, Inc. | Traffic and product analytics (which pages and features are used). Cookieless by default — nothing stored on your device; cookie-based measurement only after you enable Analytics in Privacy Choices. At permanent account deletion, VesselTwin deletes the person profile and queues deletion of linked events and session recordings. | Pageview/feature events with a domain-separated SHA-256 account identifier, IP address, and user agent. Event payloads are restricted by construction to IDs and bounded enums — no raw authentication identifier, vessel names, HIN/registration, locations, document contents, or free text. | United States (us.i.posthog.com) |
| Stripe, Inc. | Subscription checkout, recurring billing, tax calculation, invoices, payment processing, and billing-record privacy redaction. | Billing email and address, Stripe Customer/Checkout/subscription identifiers, payment and invoice metadata, and card details entered directly into Stripe Checkout. VesselTwin does not receive card numbers or security codes. | United States / global processing |
2.1 Advertising and measurement partners
Reddit, Inc. is used for consented advertising attribution and delivery optimization. After a visitor enables Marketing, Reddit Pixel may receive a page URL from a fixed set of non-record routes, referrer, IP address, user agent, Pixel cookie or browser identifier, and the PageVisit, SignUp, or VesselCreated event name. VesselTwin does not load the Pixel on boat-record or document-record URLs, disables Reddit advanced matching, and does not send email, phone, external account IDs, boat IDs, or boat-event properties. Reddit receives no boat records, uploaded documents, maintenance information, payment data, precise location, or free text. See Reddit's Privacy Policy and VesselTwin's Privacy Policy §9.3.
Meta Platforms, Inc. is used only for consented advertising measurement and delivery optimization. After a visitor enables Marketing while signing up, Meta may receive one completed-registration event containing an event time, signup URL, SHA-256-hashed email address, and separately hashed account identifier. Meta receives no vessel data, uploaded documents, maintenance information, payment data, precise location, or free text. VesselTwin does not load Meta Pixel or set Meta cookies. Depending on jurisdiction and purpose, Meta may act as an independent or joint controller rather than a VesselTwin subprocessor. See Meta's Privacy Policy and VesselTwin's Privacy Policy §9.3.
2.2 User-authorized AI apps
An AI app that you connect and direct to use VesselTwin's connector receives allowlisted record metadata at your direction. If an eligible customer enables the account-wide private-record setting, every supported AI app they connect may also receive private document text, notes, costs, identifiers, locations, and related structured fields for boats the customer owns. If the customer separately enables Inbox suggestions, the app may also submit proposed notes, checklists, maintenance entries, and measurements; they remain pending until the customer accepts them. For those transfers, the app provider is an independent third party governed by its own terms and privacy policy, not a VesselTwin subprocessor. This is distinct from an AI provider processing an inference request under VesselTwin's account, which is covered by the list and no-training commitments below. See the Privacy Policy §7 for the connector's consent and data boundary.
3. AI processing and "no training"
VesselTwin instructs each AI subprocessor to process inputs solely to generate the requested output and not to use them for training the provider's underlying models. Configuration today:
- AWS Bedrock — provider terms prohibit using customer inputs to train or improve foundation models.
- Google Vertex AI — Vertex AI customer data is not used to train Google's foundation models under the Vertex AI service terms.
- Vercel AI Gateway — passes requests through to the upstream provider; the upstream provider's no-training terms apply.
- Anthropic API — Anthropic does not use API inputs/outputs to train its models by default.
4. Notification of changes (GDPR Art. 28(2))
When we add a new subprocessor or replace an existing one, we will update this page and move the "Last updated" date. Customers under an enterprise or fleet-tier DPA may request advance written notification of new subprocessors with opportunity to object — email privacy@vesseltwin.io to be added to the notification list. We aim to provide at least 30 days' advance notice for material additions where reasonably practicable.
5. Contact
Questions about a specific subprocessor, our DPA, or data-residency options? Email privacy@vesseltwin.io. For security incidents, contact security@vesseltwin.io.