Subprocessors
Last updated: May 18, 2026
Zensus uses trusted third-party services to operate our platform. This page lists every external provider that processes data on our behalf, grouped by the role they play.
Cloud infrastructure and hosting
Amazon Web Services
United StatesPrimary application infrastructure: managed database, object storage, transactional email, log aggregation, and edge hosting for the product app.
Data shared: All customer data classes (encrypted in transit and at rest).
Vercel
United StatesHosting for the public marketing site at zensus.app.
Data shared: HTTPS request logs, build artifacts. No customer account data.
Identity and authentication
Supabase
United StatesIdentity provider for sign-in, sessions, and account recovery.
Data shared: Email address, hashed password, session tokens.
Google (Sign-In)
United StatesOptional Google OAuth sign-in.
Data shared: Email, name, Google sub identifier (only if you choose Google sign-in).
Apple (Sign in with Apple)
United StatesOptional Apple OAuth sign-in.
Data shared: Email or relay address, Apple sub identifier (only if you choose Apple sign-in).
Financial data and integrations
Plaid
United StatesBank account linking and read-only access to transactions and balances.
Data shared: Account metadata, balances, transactions. Your bank login is held by Plaid and never reaches Zensus.
Intuit (QuickBooks Online)
United StatesRead-only sync of accounting data: purchases, bills, payments, invoices, P&L, balance sheet.
Data shared: OAuth tokens, accounting object data (only if you connect QuickBooks).
HubSpot
United StatesRead-only sync of CRM data and subscription tracking for accounts-receivable forecasting.
Data shared: OAuth tokens, contacts, companies, line items, invoices, subscriptions, admin email (only if you connect HubSpot).
Stripe
United StatesSubscription billing and payment processing for Zensus itself.
Data shared: Stripe customer ID, billing email, subscription metadata. Card details are handled directly by Stripe and never reach Zensus.
Communications
Slack
United StatesDelivery of cash-flow alerts to a customer-selected Slack channel; processing of in-Slack actions (snooze, threshold adjust).
Data shared: Workspace metadata, channel IDs, alert message contents, interactivity payloads (only if you connect Slack).
AI and machine learning
Amazon Web Services (Bedrock)
United StatesHosted inference for the AI features used to generate scenarios, categorize transactions, and power the conversational assistants. In this configuration, Anthropic (the maker of the Claude models) does not access the data we send to Bedrock.
Data shared: User prompts, conversation history, financial context (cash, MRR, expense breakdown, billing timeline), sanitized transaction descriptors.
OpenAI
United StatesSpeech-to-text transcription for the voice assistant.
Data shared: Voice audio submitted to the voice agent.
Hugging Face
United StatesEmotion detection on audio-derived text snippets for adaptive voice output.
Data shared: Short text snippets derived from voice audio.
Security and abuse prevention
ipapi.co
United StatesVPN and proxy detection on integration connect, as a fraud signal.
Data shared: End-user IP address at the moment of integration connect.
Web fonts and embedded content
Google Fonts
United StatesDelivery of the Geist and Geist Mono webfonts used by the marketing site.
Data shared: Visitor IP and user-agent (transmitted to Google when fonts are fetched).
Google Maps
United StatesEmbedded city-level map of Austin, TX shown in the marketing-site footer.
Data shared: Visitor IP and user-agent (transmitted to Google when the embedded map loads).
Analytics and marketing intelligence
Apollo.io
United StatesMarketing-site visitor identification for outbound sales. Apollo matches visitor IP addresses against its database of company IPs and reports which businesses are browsing our site.
Data shared: Visitor IP, user-agent, pageview events.
Vercel (Web Analytics and Speed Insights)
United StatesFirst-party, cookieless marketing-site performance metrics.
Data shared: Aggregated page-load timings and route-level traffic counts. No persistent identifiers.
Bot and abuse protection
Cloudflare (Turnstile)
United StatesInvisible bot and abuse protection on the marketing-site support form (zensus.app/support), so the contact and acknowledgment flow cannot be used to send spam.
Data shared: Visitor IP, user-agent, and a verification token (transmitted to Cloudflare when the support form is submitted).
How we manage subprocessor changes
We update this page whenever we add, remove, or materially change a subprocessor. For changes that affect customer data, we aim to give reasonable advance notice (typically 30 days) through our changelog and, where appropriate, by email to account administrators.
All subprocessors are bound by data-processing terms with us that meet the requirements of applicable privacy regulations including GDPR Article 28 where it applies. We rely on the EU-US Data Privacy Framework, the UK Extension to the DPF, the UK International Data Transfer Addendum, and Standard Contractual Clauses for cross-border transfers as needed.
Questions
For questions about this list or any subprocessor, email hello@zensus.app.