Sub-processors
These are the third parties Point Pass relies on to run the service. Each one is here because the product genuinely cannot work without it, and each is bound to handle data only as we instruct.
We will tell you before this list grows. If we add a sub-processor that touches customer data, existing customers hear about it in advance, not afterwards.
| Who | What they do | What they see | Where |
|---|---|---|---|
| Vercel | Application hosting and content delivery. Serves every page and API request. | Anything sent to the service in transit, plus request logs. | Global edge network |
| Supabase | Database, authentication and file storage. This is where customer records live. | All stored data: shops, customers, cards, stamps, artwork. | Chosen at project creation; stated here once fixed |
| Apple | Apple Wallet passes and the push notifications that tell a phone its card has changed. | What is printed on the card, plus a device identifier Apple issues. No phone numbers. | Apple’s global infrastructure |
| Google Wallet passes and their updates. | What is printed on the card. No phone numbers. | Google’s global infrastructure |
Not on this list, deliberately
We use no advertising networks, no analytics that profile individuals, and no data brokers. There is no email or SMS provider listed because we have not yet chosen one; the day we do, it appears here before it is used to send anything.
What Apple and Google actually receive
Worth being precise, because it is the question shops ask most. A wallet pass contains what you can see on the card: the shop name, the reward, the stamp count, and the cardholder name if the shop collects one. It does not contain a phone number, a birthday, or a visit history — those stay in our database and are never sent to a wallet provider.
Questions about any of this go through the contact form. See also the data processing agreement.