Legal

Sub-processors

Last updated: May 18, 2026

JourneyFuse uses the third-party service providers listed below to operate the Service. Each one is contractually bound to use customer data only to provide its service to JourneyFuse and to maintain commercially reasonable security practices.

We notify customers of material changes to this list via email (for account contacts) and by updating this page. Customers with a signed Data Processing Agreement can object to the addition of a new sub-processor within 30 days of notification.

Sub-processorPurposeDataRegion
SupabasePrimary database (Postgres), authentication, file storageWorkspace data, client records, trip data, account credentials, uploaded filesUnited States (AWS)
VercelWeb application hosting and edge deliveryApplication traffic, request logsUnited States and global edge
EvervaultPCI DSS Level 1 card tokenization for client payment authorizationsCredit card numbers, CVV (tokenized in-browser, never on JourneyFuse servers)United States and EU
StripeJourneyFuse subscription billing and planning fee collectionBilling contact, payment method tokensUnited States
ResendTransactional and outbound email deliveryEmail addresses, message contents sent through the ServiceUnited States
SentryApplication error monitoring (PII scrubbed before transmission)Error stack traces, anonymized request metadataUnited States
UpstashRate limiting and ephemeral cacheRequest fingerprints, short-lived session tokensUnited States and EU
MapboxMap tiles and geocoding for itinerary mapsLocation queries, IP addressUnited States
OpenAIAI features under no-training terms: proposal and itinerary generation, email drafting, passport photo OCR, commission-statement extractionOnly the specific text or image submitted for that request; not retained for model trainingUnited States
Google (Places API)Address autocomplete, place lookups, and place photos for itinerary planningSearch queries and place identifiers, no personally identifiable customer data sentUnited States

Infrastructure certifications

JourneyFuse delegates payment, hosting, and database security to providers that hold the following independent certifications:

  • Evervault: PCI DSS v4.0.1 Level 1 (audited by Prescient Security LLC, QSA #202-230)
  • Stripe: PCI DSS Level 1
  • Supabase: SOC 2 Type 2 (AWS-hosted infrastructure with ISO 27001, SOC 1/2/3)
  • Vercel: SOC 2 Type 2, ISO 27001

Each provider publishes its own current attestations on its trust or security page; we can point you to them on request at security@journeyfuse.com.