Legal
Subprocessors
Effective August 15, 2026
Ready-to-Inspect uses a small number of third-party providers to run the Service. Each one is bound by contract to process data only as needed to provide their service to us, and each is listed here so you can review them before you sign up and at any time afterward.
This page is the current version of Annex C to our Data Processing Addendum. If the two ever differ, this page is authoritative.
Providers that process customer content
These providers handle inspection records, photographs, signatures, and the personal information contained in them.
| Provider | What it does for us | What it processes | Where |
|---|---|---|---|
| Supabase, provided through Lovable Cloud | Database, file storage, and authentication | All Customer Data — inspection records, photographs, signatures, activity log, user accounts | United States |
| Cloudflare, Inc. | DNS, content delivery, and video hosting | Network request metadata; delivery of static assets | Global edge network |
Providers that process account data only
These providers never receive inspection content.
| Provider | What it does for us | What it processes | Where |
|---|---|---|---|
| Stripe, Inc. | Payment and subscription processing | Billing contact details and payment method. Stripe holds card data; we do not. | United States |
| Resend | Transactional email delivery | Recipient name, email address, and message content of notification emails | United States |
| Google LLC | Optional "Sign in with Google" | Email address and name, only for users who choose this sign-in method | United States |
Integrations you turn on yourself
If an administrator in your workspace connects an optional integration, data is transmitted to that provider at your direction, under your own agreement with them. Those providers are not our subprocessors and we do not control what they do with the data.
| Integration | Status |
|---|---|
| Smartsheet | Available, off by default |
Changes
We give customers at least 30 days' notice before adding or replacing a provider that processes inspection content, by email to the account administrator and by updating this page. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the Service without penalty and receive a pro-rated refund.
Adding or replacing a provider that processes account data only does not trigger the notice period, but this page is still updated.
Certifications
Ready-to-Inspect does not hold SOC 2, ISO 27001, FedRAMP, or any comparable third-party security attestation, and we will not claim one. What we will do is tell you exactly how the product is built — see Security and Annex B of our Data Processing Addendum — and let you export every record and walk away with it at any point.