Subprocessors
Last updated: August 2, 2026
This page lists every vendor that may process personal data on our behalf, what each one receives, and the region it is processed in. We publish it so Restaurants can complete their own transfer assessments without asking us for a list. Changes are announced here and to account owners before a new subprocessor starts processing.
1. Always in the path
These run for every Restaurant. OwnTable contracts them directly and is responsible for their data-protection terms.
| Subprocessor | Purpose | Processing region | Personal data received |
|---|---|---|---|
| Supabase | Database, authentication, encrypted secret storage | United States — us-east-2 (Ohio) | All application data at rest: diner and staff records |
| Vercel | Application hosting and delivery | United States — iad1 (Virginia) | Same data in transit only; no persistent storage |
| Resend | Transactional email (confirmation, reset, reminders) | United States | Staff email address and message content |
| Sentry | Error monitoring | United States | Diagnostics only — personal data is stripped before sending |
| Stripe · PayPal | OwnTable subscription billing | United States / global | Restaurant billing contact and payment metadata. No diner data. |
2. Used only in Managed mode
Optional. These apply where a Restaurant uses OwnTable’s own AI credits or our onboarding SMS, rather than connecting its own accounts.
| Subprocessor | Purpose | Region | Personal data received |
|---|---|---|---|
| Anthropic (or OpenAI) | AI order-taking and support replies | United States | Conversation text: diner name, phone, address, order contents and notes |
| Twilio | Phone verification at signup | United States | Staff phone number |
3. Connected by the Restaurant (bring your own keys)
The platform is built so each Restaurant connects its own messaging, voice, AI, delivery and payment accounts. Where it does, data goes to that provider under the Restaurant’s agreement with them, not ours — and the Restaurant is responsible for the transfer basis. We list them for completeness.
| Provider | Purpose | Region | Personal data received |
|---|---|---|---|
| Meta (WhatsApp Business Platform) | Messaging, reorder, reminders | United States / global | Diner phone number and message content |
| Twilio | SMS status messages, voice | United States | Diner phone number, message content, call audio |
| VAPI · ElevenLabs · Deepgram | Voice ordering and transcription | United States | Call and voice-note audio, transcripts |
| Anthropic · OpenAI | AI order-taking (own key) | United States | Conversation text as above |
| Deliverect Dispatch · Roboost | Courier dispatch | European Union / regional | Diner name, phone, delivery address |
| Tap · Moyasar | Card, mada, Apple Pay, STC Pay | Kingdom of Saudi Arabia | Cardholder data — handled entirely by the processor; never stored by us |
4. Processing that stays in Saudi Arabia
Two flows never leave the Kingdom, by design: payment authorisation through Tap or Moyasar, and tax-invoice reporting to ZATCA (Fatoora). Card numbers never enter OwnTable systems — checkout is hosted by the payment processor and we keep only a payment reference.
5. Cross-border transfers
Our infrastructure is located in the United States. For Restaurants in the Kingdom of Saudi Arabia this is a cross-border transfer under the Personal Data Protection Law. Because SDAIA has not issued an adequacy decision, we rely on Standard Contractual Clauses together with a documented transfer risk assessment, and we minimise what leaves the Kingdom. A Restaurant may request the assessment summary and the applicable clauses at sales@owntable.io. For transfers out of the UK/EEA we rely on the equivalent approved mechanism with each subprocessor.
6. Changes
Before a new subprocessor begins processing personal data, we update this page and notify account owners. See the Data Processing Addendum for the objection process and the Privacy Policy for how we use data.