Last updated: 4 August 2026
A subprocessor is a third-party service we use to help run Invio - things like hosting the app, sending email, or processing a card payment. Our Privacy Policy explains how and why we share information with these providers; this page is the specific, current list of who they are, what each one does, and where they process data. We keep this list up to date here rather than inside the policy itself, so it can change without every update requiring a rewrite of the policy text.
We do not sell your personal data or share it with advertisers. Every provider below is used because it performs a specific function Invio needs to operate.
| Subprocessor | What it does | Data processed in |
|---|---|---|
| Xero | Accounting connector - if you choose to connect Xero, we read the organisations you authorise so your own AI assistant can answer questions about them, and we write back only changes you have explicitly approved. Data read to answer a question is not stored afterwards. A change your assistant drafts is kept, with its real amounts and contact details, only until you approve or reject it, or for up to 24 hours if you do neither; the financial detail of what happened is then cleared from our records within 90 days, whether or not it was ever approved. Your Xero refresh token is stored encrypted so the connection survives without asking you to sign in again. Disconnecting cuts off Invio's own access immediately, and also asks Xero to revoke the token on its side. | Determined by Xero under your own agreement with them, not by Invio. Invio does not retain your Xero accounting data after answering a request. |
| MongoDB Atlas | Database hosting - stores your account, business, client, invoice, quote and payment records. | Sydney, Australia. |
| Vercel | Hosts the Invio web application and its API, and runs our scheduled background jobs. | United States by default (Vercel's documented default function region, which our own configuration does not override), and potentially other countries where Vercel or its infrastructure partners operate. |
| Stripe | Processes card payments, manages subscriptions, and (for connected businesses) payouts. | Ireland and the United States, and other jurisdictions where Stripe operates. |
| Brevo | Delivers transactional email - invoices, quotes, reminders, receipts and account emails. | France, Germany and Belgium (Brevo's own published EU infrastructure). |
| Sentry | Error monitoring - captures unhandled errors so we can find and fix bugs. | Germany (our Sentry project is provisioned in Sentry's EU region). |
| PostHog | Product analytics - which pages and features are used, to help us improve the product. We also read aggregate figures back out of PostHog for our own reporting: visit counts, country and acquisition-channel breakdowns, and most-visited pages. That reporting is never per person, and covers nothing beyond what was already captured for the purpose above. | European Union (this project is provisioned on PostHog's EU Cloud). |
| Cloudflare R2 | File storage for uploaded logos, expense receipts and other attachments. | Cloudflare's global network - our configuration does not pin storage to a single country. |
| Google Cloud (Vertex AI) | AI processing for the optional voice-to-invoice feature and the Offsider chat assistant. Also address autocomplete on the client and business address forms (12 September 2026): the text you type is sent to Google Places to suggest matching addresses, and Google returns the address components (street, suburb/city, state, postcode) for the one you pick - nothing beyond the address you chose is stored afterwards, and no Google place id is kept. | The United States (us-central1) or Google's global network, depending on which AI model handles the request. Address autocomplete calls Google's Places API, which is not regionally pinned by this configuration. |
This list may change as we add, replace, or retire providers - we will update it here when it does. If you have questions about a specific provider or how your information is handled, contact us at support@invio.co.nz.