Subprocessors
Last updated: 2026-07-12
OneCount Pty Ltd · ACN 695 536 415 · ABN 29 695 536 415
This is the current operational list of named providers used by the OneCount website, mobile app, or backend functions. It is not a substitute for a signed data-processing agreement.
Contact-form submissions are stored in Supabase. They are not delivered as support email by an email provider in the current contact workflow.
Current providers
| Provider | What it does | Data boundary |
|---|---|---|
| Supabase | Authentication, Postgres data, storage, realtime sync, and backend functions. | Account identity and the organisation-scoped operating records needed by enabled OneCount workflows. |
| OpenAI | AI-assisted analysis, invoice parsing, and selected vision workflows. | The prompt, attachment, and task context needed for the selected AI workflow. API credentials remain server-side. |
| RevenueCat | Mobile subscription, purchase, restore, and entitlement management. | App user ID, product and entitlement identifiers, subscription state, and billing-event metadata — not stocktake line items. |
| Vercel | Website hosting, Next.js runtime, logs, and Web Analytics. | Website requests, anonymised and aggregated analytics, coarse custom events, runtime logs, and deployment metadata. |
| Sentry | Conditional mobile crash, performance, and diagnostic monitoring. | Mobile error messages, stack traces, release and device diagnostics, and nearby mobile workflow context when configured. There is no website Sentry runtime today. |
| Resend | Organisation invitation email and app-family owner-digest email where configured. | Recipient email address and the content and metadata needed for the configured email. |
Processing boundary
Direct customer operating data remains in Supabase unless a selected feature needs a specific provider call. AI requests should receive only the task context needed for the current request. Billing state is handled through RevenueCat rather than mixed into inventory records. Monitoring and hosting providers are not the source of record for customer stock data.