Subprocessor List
The service providers (subprocessors) that help us run the TravelBookingWidgets platform, what each one does, and the data involved. Referenced by our DPA, which explains how we give advance notice of changes to this list.
1. Current subprocessors
| Provider | Service / purpose | Data involved | Where |
|---|---|---|---|
| Vercel | Application hosting, CDN and tenant custom domains | All in-transit application data; function logs | Global edge network; primary region [to be recorded] |
| Supabase | Postgres database, authentication, file storage (documents, email attachments, rate sheets) and encrypted secrets vault | All product data, including traveller CRM records and documents | [Region to be recorded] |
| Microsoft (Microsoft 365 / Graph) | Mailbox sync ("Ops Import") and sending documents and campaigns through connected operator mailboxes | Emails and attachments (including supplier rate documents), sender addresses | The operator's Microsoft 365 tenant region |
| Operator mailbox providers (IMAP/SMTP) | Per-operator mail sync and sending fallback — each operator connects its own mailbox | Mailbox contents; connection passwords (stored encrypted) | Wherever the operator's chosen mailbox provider hosts. The operator selects this provider and is responsible for it |
| Pesapal | Payment processing: guests pay the tour operator via the operator's own Pesapal merchant account. TravelBookingWidgets' own Pesapal account is used only for platform subscription fees | Guest name, email and phone as billing details; amount, currency and status. Card data stays with Pesapal and never touches our servers | Kenya (+ regional) |
| Safaricom (M-Pesa Daraja) | M-Pesa payment prompts (STK push) into the operator's own shortcode or paybill | Guest phone number, amount, status | Kenya |
| Meta Platforms (WhatsApp Business Cloud API) | Approved support-template replies | Reply text, recipient phone number | Meta (US/global) |
| Google (Google Analytics 4) | Analytics on our public marketing site only — not the operator app, not widgets on operators' sites | Pseudonymous cookie-based identifiers, pages viewed, events | US/global — see the Cookie Policy for the consent status |
| OpenStreetMap tile servers | Map tiles in quote and itinerary views | IP address (standard web request only — no cookies, no personal records) | Global CDN |
| FX providers (open.er-api.com, frankfurter.dev) | Exchange rates for currency display | None — no personal data | Global |
2. Wired but not active
Microsoft Clarity (session recording) is present in our code but is NOT enabled — no Clarity script loads for visitors. It will not be enabled before a site-wide consent mechanism is live and an internal review is complete, and this page will be updated if that changes.
3. Change notice and objections
Before a new subprocessor processes operator personal data, we update this page and email workspace owners at least [30] days in advance. Operators may object on reasonable data-protection grounds per DPA section 5. Questions: privacy@travelbookingwidgets.com.
We review this list, provider regions and provider DPAs at least annually [regions shown as "to be recorded" are being confirmed with each provider before publication].