Subprocessor List
This page lists the third parties VERA relies on to run the Service. It forms part of the Data Processing Addendum. A service appears here when VERA sends it customer data in order to run the product. A platform that you connect yourself is not on this list, because you hold your own agreement with it; those are described further down.
- Version
- 2.0
- Effective
- August 12, 2026
- Last updated
- August 12, 2026
- Revisions
- 2
On this page (7 sections)
1. Infrastructure subprocessors
These process data for every customer because they host or serve the Service.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel (hosting) | Application hosting, edge delivery, and the scheduled jobs that run the product, plus the managed PostgreSQL database that holds all account data and is reached from it | All customer data, including uploaded files and generated images, which are stored in the database rather than with a separate file host | United States |
| Vercel (Web Analytics and Speed Insights) | Page view and performance measurement on public marketing pages | Page paths, performance timings, and a closed set of non-identifying custom event values | United States |
2. Core service subprocessors
These are engaged for functions every account uses or may use. Each payment processor appears twice, for two genuinely different purposes: billing you for VERA, and processing the payments your own customers make to you. Two processors are listed because Stripe is the one VERA uses and Finix is kept behind it as a fallback; an account set up on one stays on it.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Stripe (subscription billing) | VERA's own subscription billing: the hosted checkout page that collects your card, and the recurring charge that renews your plan. The invoices, the proration and the billing schedule are VERA's own | Name, email address, payment method, and the amounts VERA charges you. Card details are entered on Stripe's own hosted page and never reach VERA | United States |
| Stripe (Vera Payments) | A separate function from the row above: payments your own customers make to you, and payouts to the connected account you onboard. VERA is the platform, not the payee | Your business identity and bank details submitted during merchant onboarding, and your customers' names, email addresses, payment amounts and payment methods for the payments you request | United States |
| Finix (subscription billing) | The same processing as the Stripe row above, on the fallback processor. Used only where VERA is not configured for Stripe, and for any card that was stored on Finix before that changed: a stored card can only ever be charged by the processor that stored it | Name, email address, payment method, and the amounts VERA charges you. Card details are entered into Finix's own hosted fields and never reach VERA | United States |
| Finix (Vera Payments) | Contractor payments on the fallback processor. Used only where VERA is not configured for Stripe, and for any business already onboarded as a Finix merchant: an account never changes processor underneath itself, so its existing payments and payouts continue here | Your business identity and bank details submitted during merchant onboarding, and your customers' names, email addresses, payment amounts and payment methods for the payments you request | United States |
| Anthropic | AI text generation, analysis, classification, and the VERA assistant | The prompt and the business context relevant to the task, which may include customer records the user asked VERA to work with | United States |
| Resend | Transactional email: verification, password reset, sign-in links, team invitations, welcome and trial messages. Used when configured as the system mail transport | Recipient email address and message content | United States |
| Google (sign-in) | Google OAuth sign-in, where enabled | Email address, name, and profile image received from Google at sign-in | United States |
3. Conditional subprocessors
These process data only when the corresponding feature is configured for the deployment or used by you. If you never use the feature, they never receive your data.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| OpenAI | AI image generation, when configured and used | The image prompt and generation settings. VERA composes text and logo overlays itself, so brand copy is not required to leave our servers | United States |
| Google (Gemini) | AI image generation, when configured with Gemini and used | The image prompt and generation settings | United States |
| ElevenLabs | Text-to-speech for VERA's spoken replies, when the premium voice is enabled. Speech RECOGNITION is not sent here: it runs in your browser, and VERA receives only the transcript | The sentence of VERA's reply to be spoken, plus the selected voice and speed. No microphone audio is sent | United States |
| OpenAI (AI receptionist) | Speech-to-speech for Vera answering a business's phone calls, when the business has switched the receptionist on. The phone carrier bridges the call's audio directly to OpenAI; it does not pass through VERA's servers. Separate from image generation because it is a different kind of data: a live conversation with the business's caller | The audio of the call in both directions, the caller's and the business's phone numbers, the receptionist's instructions (the business's name, hours, services, tone and what it is allowed to do), the facts Vera looks up during the call to answer the caller, and the transcript, which VERA stores in the business's account | United States |
| Twilio | Sending and receiving SMS and MMS, and carrying phone calls to and from a business's VERA number, when messaging or the business phone is configured at the platform level or with your own credentials. Where a business turns on call recording, Twilio holds the recording until VERA's retention job deletes it | Recipient and sender phone numbers, message text, and MMS media; for calls, the caller's and the business's numbers, the call's audio while it is in progress, and, only where recording is switched on, the recording | United States |
| bundle.social | Publishing and scheduling posts to the social platforms you connect, relaying their status back, and reporting the audience and engagement numbers those platforms return for your accounts | Post captions, images and video you submit for publication, the connected social account, the schedule, and the follower and engagement counts the platform reports for that account | European Union |
| Check Technologies | Payroll processing for businesses that turn on VERA Payroll: calculating employee withholding and employer taxes, debiting the business's payroll bank account, paying employees and contractors, filing payroll tax returns, and issuing W-2s and 1099s | The business's legal name, EIN, address and tax registrations; each worker's name, email, start date, work location, Social Security number, date of birth, home address, withholding elections and bank account details, all collected through Check's own onboarding; and the hours, earnings, reimbursements and pay dates VERA sends for each payroll | United States |
| Pipedream Connect | Brokering connections to third-party platforms for providers routed through it: it runs the authorization flow, holds the resulting credential, and proxies authorized API calls | Your VERA account identifier as the external user id, the provider being connected, and the request and response content of calls VERA makes to that provider on your instruction | United States |
| Google Maps or Mapbox | Geocoding addresses and computing routes and distances for the Mileage Log, when a maps key is configured. Whichever is configured is the one that receives data; with neither, routing falls back to a labelled local simulation | Trip origin and destination coordinates or addresses. Results are cached under a hash of the normalized request, never the raw address | United States |
| 1build | Localized construction cost data for estimates, when enabled | Material and labor descriptions and the postal code or region being priced. No customer records are sent | United States |
| An SMTP provider you or the operator configures | Email delivery when sent over SMTP rather than Resend | Recipient email address and message content | Depends on the provider |
| GNews | Industry Radar news retrieval | Search topics derived from your business profile. No customer records are sent | European Union |
4. How connecting to a platform works
Some third-party platforms are connected through Pipedream Connect rather than directly. Where that is the case, authorization happens on Pipedream's hosted flow, Pipedream holds the resulting credential, and VERA reaches the platform through Pipedream rather than holding the token itself. VERA identifies you to Pipedream by your account identifier, and the content of the calls VERA makes on your instruction passes through it.
Not every provider is brokered. Several are pinned to a direct connection and are never routed through a broker, in which case VERA holds the credential itself, encrypted at rest with AES-256-GCM. Which route a given provider takes depends on the deployment's configuration; the Integrations area shows the state of each connection.
5. Platforms you connect
When you connect a third-party platform, data flows between VERA and that platform on your instruction. Those platforms are not VERA's subprocessors: you have your own relationship and your own agreement with each of them, and VERA acts on your authorization to reach them.
VERA's catalog covers roughly 150 providers across accounting, payments, CRM, scheduling, email, communication, marketing, social, ecommerce, shipping, analytics, field service, hospitality, real estate, HR, documents, and developer tools. Each provider's card in the Integrations area states what VERA reads and writes before you connect it. Notable ones include Stripe, Shopify, Square, WooCommerce, QuickBooks Online, Jobber, HubSpot, Xero, Meta (Facebook and Instagram), X, TikTok, LinkedIn, Pinterest, YouTube, Google (Analytics, Ads, Calendar, Gmail, Business Profile), Mailchimp, Klaviyo, and Calendly.
You can review and disconnect any connection at any time in Integrations. Disconnecting removes VERA's stored credential and stops future access.
6. Changes and notification
VERA gives at least 30 days' notice before adding or replacing a subprocessor, by updating this page and notifying account holders. Business customers may object on reasonable data protection grounds under section 6 of the Data Processing Addendum.
To be notified of changes, or to raise an objection, write to support@meetmyvera.com.
7. A note on deployment configuration
VERA is built so that most third-party services are optional and are enabled by configuration. A deployment with no AI key, no SMS credentials, and no email transport runs against local mocks and sends nothing to any of them.
This list therefore describes the maximum set of subprocessors that the production Service may engage. If you need a definitive statement of which are active for your account, ask us at support@meetmyvera.com and we will confirm in writing.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v2.0August 12, 2026
Rebuilt from a maintained registry. Added Stripe Connect as a separate entry from subscription billing, ElevenLabs, Twilio, bundle.social, Pipedream Connect, Google Maps or Mapbox, and 1build, and added a section explaining how connection brokering works. A connection broker that is no longer part of VERA was removed.
- v1.0July 28, 2026
Initial Subprocessor List published.
Questions about this document?
Legal and contracts: legal@meetmyvera.com. Privacy and data rights: support@meetmyvera.com. Security reports: support@meetmyvera.com.
Related
- Privacy Policy
- Cookie Policy
- SMS Opt-In Policy
- GDPR Rights
- California Notice
- DPA
- Data Retention
- Account Deletion
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.