Last updated July 17, 2026
This page lists third-party service providers that ShiftDispatch uses to provide, secure, monitor, support, bill for, and improve the Services. These providers may process customer data, personal information, operational data, metadata, or usage data depending on the features a customer uses.
Additional contact information is available upon request by emailing [email protected].
Current Subprocessors
| Provider | Purpose | Data Involved |
|---|---|---|
| Render | Production application hosting, infrastructure, and primary database hosting | Application traffic, logs, environment metadata, account, workspace, worker, schedule, chat, invoice, billing reference, notification, public schedule, and operational data |
| Stripe | Checkout, customer portal, subscription billing, payment processing, and billing webhooks | Billing contact data, customer identifiers, subscription identifiers, checkout metadata, payment status, invoice/payment metadata, and payment details processed directly by Stripe |
| Twilio Verify | SMS one-time verification codes for staff access and workspace admin verification | Phone numbers and verification request, response, and delivery metadata |
| Supabase Realtime | Chat realtime presence, typing, and invalidation broadcasts | Realtime channel metadata, short-lived authorization token claims, worker identifiers, typing events, presence metadata, and chat invalidation events |
| Google Drive/Docs APIs | Optional invoice connector and generated invoice document workflows | OAuth tokens, connected account email, authorized scopes, file/folder IDs, document URLs, invoice document content, generated PDFs, and connector configuration |
| Google Analytics 4 | Product and website analytics | Usage events, page view metadata, device/browser metadata, and sanitized campaign parameters |
| PostHog | Product analytics | Usage events, page view metadata, feature/event metadata, and server-side product analytics identifiers |
| Sentry | Error monitoring and diagnostics | Error events, stack traces, release/environment metadata, scrubbed request context, and diagnostic metadata |
| Browser/web push providers | Staff and workspace push notifications through browser Push APIs | Push subscription endpoints, public keys, auth keys, notification payloads, delivery metadata, and browser/device notification metadata |
Feature-Specific Notes
Stripe processes payment card details directly. ShiftDispatch stores billing references and subscription status, but does not store full payment card numbers or card security codes in the application database.
Twilio Verify is used for staff-access and workspace-admin verification codes. Browser push providers deliver configured operational notifications such as schedule updates, reminders, shift confirmations, open shift notices, and chat or schedule notices. These features are not intended for marketing messages.
Supabase Realtime is used for realtime chat behavior. Durable chat records are stored in ShiftDispatch's primary application database.
Google Drive/Docs access is used only for invoice connector workflows that a workspace authorizes. Disconnecting or changing Google access may affect invoice generation features.
Analytics providers are used for product and website analytics. The current PostHog browser configuration disables autocapture, pageleave capture, and session recording.
Changes To This List
We may update this list as our infrastructure, product features, or vendors change. If a new subprocessor is added for a material product function, this document should be updated before or near the time that provider begins processing production customer data.