Subprocessors
The third parties that help run CareVerify, and exactly what each one can see.
Last updated 2 August 2026
How to read this
In short: Every vendor we use is listed. The last column tells you whether it can touch protected health information.
We do not run our own data centers. Like every small software company we build on other people's infrastructure, and you are entitled to know whose. Each vendor below processes data only to provide its service to us.
Every vendor marked Yes under PHI operates under a business associate agreement with us, with obligations at least as strict as those in our own BAA with you.
Current subprocessors
In short: 9 vendors. 4 can touch PHI, 5 cannot.
| Vendor | What it does | Data it touches | Location | PHI |
|---|---|---|---|---|
| Supabase | Database, authentication and file storage | All application data, including client and visit records | United States | Yes |
| Cloudflare | Application and website hosting, DNS, network security | All traffic to the service in transit | Global edge network | Yes |
| Twilio | SMS visit reminders and missed-visit alerts to the office | Phone numbers and message content | United States | Yes |
| Resend | Transactional email and exported reports | Email addresses and message content | United States | Yes |
| Sentry | Error and crash reporting | Technical diagnostics. We exclude client names and health information from error payloads by design | United States | No |
| Paddle | Subscription billing, as merchant of record | Billing contact and payment details. We never see full card numbers | United Kingdom and United States | No |
| PostHog | Product analytics for the application | Usage events. We exclude client names and health information from events by design | United States | No |
| Expo | Mobile app builds and push notification delivery | Device push tokens and notification content, which never names a client | United States | No |
| Google (Tag Manager) | Tag management on the marketing website only | Website visit data. It has no access to the application or to any client record | United States | No |
What we keep out of the vendors that do not need it
In short: Error tracking and analytics never receive client names or health information. That is a design rule, not a preference.
Sentry, PostHog and push notification payloads are deliberately kept free of protected health information. Error reports carry technical diagnostics, analytics events carry usage patterns, and a push notification says "Your 2pm visit" rather than naming a client. A notification naming a client on a lock screen would itself be a disclosure.
Google Tag Manager runs on the marketing website only. It has no access to the application, to any account, or to any client record.
Changes to this list
In short: Thirty days' notice before we add a vendor that will handle PHI.
We will give customers at least 30 days' notice before adding a new subprocessor that will handle protected health information, and you may object. To be notified of changes, email legal@getcareverify.com and ask to be added to the list.
Other policies: Privacy, Terms, BAA, Subprocessors, Data retention, Cookies, Acceptable use, Accessibility, Refunds
