Subprocessors

Last updated: 2026-08-26

Venzato uses the third-party providers below to run the service. When you publish a site or an app with Venzato, you are the controller of the visitor data it collects and Venzato acts as your processor; these providers are the subprocessors behind that.

Used for every account

These providers are involved in running Venzato itself. You cannot use the service without them.

ProviderPurposeDataProcessed in
Fly.ioApplication servers. Every request to Venzato and to sites published with it runs here.All request traffic: account data, published-site visitor submissions, uploads, payment callbacks.Frankfurt (EU)
SupabaseDatabase, sign-in, and file storage.Accounts, projects, generated content, visitor records from your published site, uploaded and generated media.Frankfurt (EU)
CloudflareDNS and the TLS edge for published sites and custom domains, plus Turnstile bot protection on Venzato sign-up and sign-in.Visitor IP address, user agent, requested URL, and page content in transit; for Turnstile, the IP address and the browser and device signals of the person signing up or signing in.Global edge network
AnthropicGenerates and edits your design (Claude models).Your prompts and business brief, reference photos you upload, and the HTML of the site being edited.United States
OpenAIVoice assistant, image generation, and page planning.Microphone audio and its transcript, design descriptions, generated images.United States
ResendTransactional email: verification codes and notifications.Recipient email address and message content.United States
GoogleSign in with Google, push notifications, and the interface font.Identity token, device push token, and IP address when the font is fetched.United States
AppleSign in with Apple.Identity token and email address, or the relay address if you chose Hide My Email.United States
PolarWeb payments. Polar is the merchant of record and is the seller on your web purchase.Payment and billing details, entered on Polar's own checkout page.United States
RevenueCatKeeps app store subscriptions in sync with your account.Anonymous account identifier and subscription state.United States
CodemagicBuilds the mobile app when you publish one.App name, bundle identifier, and your own store signing credentials.European Union
Apple App Store / Google PlayPublishes your app to the stores and handles in-app purchases.App package and store listing details; purchase data for store subscriptions.United States

Only if you turn the feature on

These are not used unless you enable the matching feature on your published site or app. Turning the feature off stops the data flow.

ProviderPurposeDataProcessed in
Google AdSense / AdMobShows ads on your published site or app, if you add your ad account.Visitor IP address, advertising identifier, page viewed, ad interactions.United States
iyzico or StripeTakes payments on your published site, through your own account with them.Your customers' payment details, entered on the provider's own page.Depends on the provider you choose
ExchangeRate-API, BinanceLive currency and price data for sites that display it.None. Our server fetches the rates; visitors never contact these providers.No personal data
An AI or data endpoint you connectAnswers visitor chat messages or supplies live data, if you connect one.Visitor chat messages and whatever the module sends.Depends on the provider you choose
Google Play servicesThe "share my location" button, if your published app uses it.Visitor's device location, only when they press the button.United States

Data processing agreement

Venzato does not currently offer a signed Data Processing Addendum. If your organisation requires one before purchasing, write to info@venzato.com and say so.

Changes

This list changes as the product changes. The date above is the last time it was reviewed against the running code.

Stock photographs are downloaded once by our server and mirrored to our own storage. Visitors to your site never connect to the stock photo sources, so those sources receive no visitor data.