VinReach

Sub-processors

Last updated: April 19, 2026

Current list of third-party sub-processors that may process Controller personal data on behalf of VinReach (Processor). Referenced by the DPA §5. Material additions are notified 30 days before go-live.

Core infrastructure

VendorPurposeData categoriesRegion
NeonPostgres hostingAll tenant data at restUS (East)
CloudflareEdge pixel + DNS + Worker runtimeEvent stream, IP, UA, cookieGlobal
VercelWeb + serverless hostingRequest/response, session cookiesUS
AWS KMSCredential envelope encryptionWrapped DEKs for vendor API keysUS

Delivery

VendorPurposeData categoriesRegion
Postmark (ActiveCampaign)Transactional + marketing emailTo/from email, subject, body, open + click eventsUS
SendGrid (Twilio)Email (BYO alternative)Same as PostmarkUS
TwilioSMS + 10DLC (TCR-mediated)Phone, message body, delivery receiptsUS

AI + content + crawling

VendorPurposeData categoriesRegion
AnthropicLLM generationPrompt + completion strings, PII-scrubbed pre-sendUS
Voyage AIText embeddings for brand corpusBrand voice chunks, PII-scrubbedUS
Bright DataWeb Unlocker + Crawl API + DCA for dealer-site inventoryPublic dealer-site HTML, VIN + price + photo URLsUS

Valuations

VendorPurposeData categoriesRegion
Black BookTrade-in valuationVIN, mileage, ZIP (3-digit prefix)US

Identity enrichment (opt-in per-purpose)

VendorPurposeData categoriesRegion
FullContactIdentity resolution (opt-in)SHA-256 hashed email; returns profileUS
AtDataEmail validation + EID (opt-in)Hashed email for resolve; plaintext for inbound verifyUS

Billing + auth

VendorPurposeData categoriesRegion
ClerkAuthenticationUser email, password hash, OAuth tokensUS
StripeSubscription + metered billingOrg billing email, card metadata (PCI-scoped via Stripe Elements), meter eventsUS

Change procedure

Adding a sub-processor is a material DPA change. We post the update here, email every signed Controller at the admin contact, and wait 30 days before routing any data to the new vendor. Controllers may object within the window; see the DPA §5 for the opt-out mechanism.