VinReach

Sub-processors

Last updated: April 19, 2026

Current list of third-party sub-processors that may process Controller personal data on behalf of VinReach, Inc. (Processor). Referenced by the DPA §5. Material additions are notified 30 days before go-live.

Core infrastructure

VendorPurposeData categoriesRegion
NeonPostgres hostingAll tenant data at restUS (East)
CloudflareEdge pixel + DNS + Worker runtimeEvent stream, IP, UA, cookieGlobal
VercelWeb + serverless hostingRequest/response, session cookiesUS
Google Cloud KMSCredential envelope encryptionWrapped DEKs for vendor API keys. Per-row DEKs never transit the key-management boundary in plaintext.US (us-east1)

Delivery

VendorPurposeData categoriesRegion
Postmark (ActiveCampaign)Transactional + marketing emailTo/from email, subject, body, open + click eventsUS
SendGrid (Twilio)Email (BYO alternative)Same as PostmarkUS
TwilioSMS + 10DLC (TCR-mediated)Phone, message body, delivery receiptsUS

AI + content + crawling

VendorPurposeData categoriesRegion
AnthropicLLM generationPrompt + completion strings, PII-scrubbed pre-sendUS
Voyage AIText embeddings for brand corpusBrand voice chunks, PII-scrubbedUS
Bright DataWeb Unlocker + Crawl API + DCA for dealer-site inventoryPublic dealer-site HTML, VIN + price + photo URLsUS

Valuations

VendorPurposeData categoriesRegion
Black BookTrade-in valuationVIN, mileage, ZIP (3-digit prefix)US

Identity enrichment (opt-in per-purpose)

VendorPurposeData categoriesRegion
FullContactIdentity resolution (Essential tier) — anonymous-visitor-to-identified-shopper matching for opted-in dealer rooftops. Loaded only when visitor grants analytics + marketing consent and has not asserted GPC / CPRA sale-share opt-out.FullContact PersonID cookie; enrichment returns email, phone, and postal location when a match exists. Raw response retained for audit. FullContact is not able to purge records from their identity graph on our request — dealer must suppress locally.US
Leadpipe, Inc.Identity resolution (Enhanced tier) — anonymous-visitor-to-identified-shopper matching for opted-in dealer rooftops. Same consent gate as FullContact; only loaded for rooftops on the Enhanced identity tier. DPA: TODO — pending legal review.Hashed email, hashed phone, IP address, user agent. Leadpipe is a separate data controller for its own identity graph; consumer-level deletions must be directed to Leadpipe. Dealer-side suppression enforced locally.US
AtDataEmail validation + EID (opt-in)Hashed email for resolve; plaintext for inbound verifyUS

Billing + auth

VendorPurposeData categoriesRegion
ClerkAuthenticationUser email, password hash, OAuth tokensUS
StripeSubscription + metered billingOrg billing email, card metadata (PCI-scoped via Stripe Elements), meter eventsUS

Change procedure

Adding a sub-processor is a material DPA change. We post the update here, email every signed Controller at the admin contact, and wait 30 days before routing any data to the new vendor. Controllers may object within the window; see the DPA §5 for the opt-out mechanism.