Subprocessors
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
Ollify uses the following subprocessors to deliver our platform. Subprocessors are third-party service providers that may process customer data on Ollify's behalf as part of providing the Service. All subprocessors are contractually bound to process customer data only as necessary to provide services to Ollify and are subject to strict confidentiality and security requirements consistent with Ollify's Data Processing Agreement.
This list is maintained in accordance with Ollify's Data Processing Agreement and Privacy Policy. Ollify provides thirty (30) days' advance notice before adding or replacing a subprocessor that may materially affect the processing of customer data. See the Change Notification Policy below. This list includes only vendors that Process Customer Data and are "Subprocessors" under the Data Processing Agreement's defined terms; every commercial vendor listed below is included in DPA Annex C. One entry, NHTSA, is a U.S. government agency rather than a commercial vendor and does not enter into data processing agreements; it is included here for transparency because it receives a VIN entered by Customer. Vendors used solely for Ollify's own internal operations, which do not Process Customer Data, are not included here.
1. Active Subprocessors
Subprocessor | Purpose | Data Accessed | Location | DPA |
Amazon Web Services (AWS) — aws.amazon.com/privacy | Cloud infrastructure, hosting, storage, compute (including Amazon SES for transactional email delivery), and backups. All Ollify platform data is hosted on AWS in the us-east-1 region. | All customer data — includes Customer Data, account information, logs, and backups. | United States (us-east-1) | Yes |
Mapbox, Inc. — mapbox.com/legal/privacy | Mapping, routing, and geolocation features. Mapbox processes location queries to return map tiles, geocoding results, and routing data. | Location data: addresses, coordinates, and routing queries submitted when using mapping features. Mapbox does not receive account information or general Customer Data. | United States | Yes |
Stripe, Inc. — stripe.com/privacy | Payment processing. Stripe handles all subscription billing, payment card processing, and invoicing. | Billing information: payment method details (processed by Stripe directly), billing address, transaction history. Stripe does not receive general Customer Data. | United States | Yes |
Expo (Expo, Inc.) — expo.dev/privacy | Mobile application delivery. Expo Application Services (EAS) builds, distributes, and updates the Ollify mobile app, including over-the-air update channels; Expo's push service delivers push notifications. | Application build artifacts and update bundles (application code — not Customer Data). Device push-notification tokens are processed to support this feature. | United States | Yes |
AWS End User Messaging (Amazon Web Services) | Text message (SMS) delivery. Powers the Text Messaging Feature within the Service, through which Customer sends text messages to its own clients, drivers, contractors, or other contacts. | Processes recipient phone numbers, message content, delivery status, and opt-out ("STOP") replies. | United States | Yes |
National Highway Traffic Safety Administration (NHTSA) — vpic.nhtsa.gov | VIN decoding. NHTSA's vPIC service decodes Vehicle Identification Numbers (VINs) entered by Customer to return vehicle specifications, powering the Auto Glass Pack add-on. | The VIN itself only. No personal or customer-identifying information is transmitted; NHTSA returns vehicle make, model, year, and similar technical specifications, never information about any person. | United States | N/A (U.S. government agency; does not offer a data processing agreement) |
DPA Column: The "DPA" column indicates whether Ollify has a signed Data Processing Agreement in place with that subprocessor. Enterprise customers may request copies of relevant subprocessor DPAs by contacting privacy@ollify.app.
2. Planned Subprocessors (Not Yet Active)
One integration is built but not yet active: Anthropic, PBC (anthropic.com/privacy), the AI provider for the AI Agent add-on, which is not available in production. When AI features launch, using them will transmit to Anthropic: the customer's business name; an overview of the customer's configured data structure (workflow, entity, schedule, and task type names); the name and role of the user interacting with the AI; the user's prompts; and the records returned by tools in answer to the request — under a single Ollify API credential shared across all customers. Customer Data is not used to train Anthropic's models. This integration will be activated with customer notice per the Change Notification Policy. When Ollify plans to add or replace any other subprocessor, it will be listed here with the same advance notice.
3. Change Notification Policy
Ollify is committed to transparency about changes to our subprocessor list. When Ollify intends to add a new subprocessor or replace an existing subprocessor that may materially affect the processing of customer data, Ollify will:
Update this subprocessor list with the planned change at least thirty (30) days before the change takes effect, noting the intended effective date.
Send written notice to the Customer's designated privacy contact on file. Where a new or replacement subprocessor supports a specific add-on or feature, this notice is sent to Customers whose current subscription includes that add-on or feature, rather than to all Customers regardless of relevance.
Send notification to all subscribers to the subprocessor update list (see Subscribe to Updates below).
Customers who have executed a Data Processing Agreement with Ollify may object to a new subprocessor in writing within thirty (30) days of receiving notice by emailing privacy@ollify.app or support@ollify.app. Upon receiving a timely objection, Ollify and the Customer will negotiate in good faith for up to thirty (30) days to find a mutually acceptable resolution. If no resolution is reached within thirty (30) days, Customer may terminate the Agreement with a pro-rata refund of any prepaid fees for the unused subscription period, as set forth in the DPA.
Continued use of the Service after the thirty (30) day objection period constitutes acceptance of the new subprocessor.
4. Subscribe to Subprocessor Updates
Email Notification | Send an email to privacy@ollify.app with subject "Subscribe: Subprocessor Updates" and we will add your privacy contact to our notification list. |
DPA Customers | Enterprise customers with a signed DPA are automatically notified at their designated privacy contact address. No additional subscription required. |
5. Contact
Privacy & Subprocessor Questions | privacy@ollify.app |
DPA Inquiries / Enterprise | privacy@ollify.app — subject: "DPA Inquiry" |
Subprocessor Objections | privacy@ollify.app — subject: "Subprocessor Objection" |
Mailing Address | Ollify LLC, 901 N State St. STE N, Jackson, MS 39202 |
Subprocessor List URL | ollify.app/legal/subprocessors |
6. Change Log
This log records all additions, removals, and changes to Ollify's subprocessor list. Ollify maintains a complete version archive of this document for a minimum of seven (7) years.
Date | Change | Effective Date |