Subprocessors
Last updated: July 9, 2026
Korent uses the third-party service providers ("subprocessors") listed below to deliver the Service. Each processes data only for the purpose described, under a data-processing agreement or equivalent contractual terms. This page is the authoritative, current list.
| Provider | Purpose | Data processed | Region / transfer basis | Terms |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing and subscription billing | Names, email addresses, payment amounts and transaction records. Card numbers go directly to Stripe and never touch Korent. | United States — EU-US Data Privacy Framework (DPF) certified | Stripe DPA |
| Supabase, Inc. | Managed database (Postgres), authentication, and file storage | All application data, including operator accounts and the customer records operators enter. | Hosted in the region configured for our deployment; Standard Contractual Clauses where applicable | Supabase DPA |
| Vercel, Inc. | Application hosting and edge network | Request data that reaches our servers (IP addresses, request logs). | United States / global edge — DPF certified | Vercel DPA |
| Resend, Inc. | Transactional email delivery | Recipient email addresses and the content of transactional emails (order confirmations, receipts, reminders). | United States — Standard Contractual Clauses | Resend DPA |
| Twilio, Inc. | SMS and WhatsApp notification delivery | Recipient phone numbers and the content of rental notification messages. | United States — DPF certified | Twilio DPA |
| OpenAI, LLC | AI Copilot and Storefront AI Booking Desk — primary model provider | Operator Copilot messages, conversation history, and business-context snapshots, which can include order details and customer names, emails, and message excerpts. The Storefront AI Booking Desk additionally processes anonymous website visitors' typed messages — their questions about availability, products, and delivery, plus any contact details they choose to share. Not used to train OpenAI's models per their API terms. | United States — DPF certified | OpenAI DPA |
| Anthropic, PBC | AI Copilot and Storefront AI Booking Desk fallback, email-template translation, and marketplace listing categorization | Same categories as OpenAI when used for the Copilot or the Booking Desk; operator-authored email template copy; listing titles and descriptions. Not used to train Anthropic's models per their commercial terms. | United States — DPF certified | Anthropic commercial terms |
| PostHog, Inc. | Product analytics — loads only after affirmative cookie consent | Usage events, page views, and the account's user ID. Nothing is collected from visitors who have not accepted analytics cookies. | United States (us.i.posthog.com) — DPF certified | PostHog DPA |
| OpenStreetMap Foundation (Nominatim) | Geocoding postal codes for delivery-distance checks | Postal codes and country codes only — no names, street addresses, or identifiers. | European Union — public geocoding service | OSMF privacy policy |
| Open-Meteo | Weather forecasts for upcoming event dates | Geographic coordinates only — no personal data. | European Union — public weather API | Open-Meteo terms |
| Intuit Inc. (QuickBooks) / Xero Limited | Accounting synchronization — active only when an operator connects their own accounting account | Invoice and payment records, including customer names as they appear on invoices, synced to the operator's own QuickBooks or Xero account. | Per the operator's own accounting provider and account region | Intuit privacy statement |
Changes to This List
When we plan to add a subprocessor that will process customer personal data, we update this page and notify operators via the dashboard at least 14 days before the new subprocessor begins processing. If you object to a new subprocessor, contact us at privacy@korent.app within that window and we will work with you in good faith on a resolution, including cancellation without penalty if we cannot resolve your objection.
Contact
Questions about our subprocessors or data-processing practices: privacy@korent.app.