We keep this list current. If we add, remove, or swap a processor, we update this page and — where the change materially affects your privacy posture — we notify you by in-app notification or email before it takes effect.

For each processor below: what they do, what data category they process, the purpose, where processing happens, and a link to their terms.

Subprocessor list maintained by Weld (RentalGuards engineering). When a processor is added, removed, or substituted, Weld updates the content and this page is refreshed.

Stripe, Inc.

Payments
Data Category
Payment instrument details (card number, security code, bank details) collected directly by Stripe. RentalGuards receives only a transaction identifier, last four digits, amount, and status.
Purpose
Process Credit pack purchases. Handle refunds, chargebacks, and reconciliation.
Processing Location
United States
Terms / DPA

Resend, Inc.

Email Delivery
Data Category
Email address, name (optional), message content for transactional and account-related emails (welcome, verification, waitlist, beta open, password reset).
Purpose
Send transactional email. No marketing automation beyond waitlist and beta-open notifications.
Processing Location
United States
Terms / DPA

OpenRouter

AI Gateway
Data Category
Redacted document images and analytical prompts from Guardian scans. Sensitive identifiers (SSN, bank account, DL numbers, faces on photo IDs) are redacted on-device before transmission.
Purpose
Route scan requests to the underlying vision-language model under a Zero Data Retention (ZDR) policy. Enforces that prompts and responses are not stored.
Processing Location
United States
Terms / DPA

Google LLC — Gemini 2.5 Flash

AI Inference
Data Category
Redacted document images and analytical prompts routed through OpenRouter. Sensitive identifiers and faces are redacted on-device before reaching this processor.
Purpose
Vision-language inference for Guardian scans under Google's paid-services terms. Google is prohibited from using this data to train or improve models.
Processing Location
United States
Terms / DPA

Hostinger International, Ltd.

Backend Hosting
Data Category
Account records (email, bcrypt password hash, verification/reset tokens), Credit ledger, scan metadata (scan IDs, timestamps, doc-type labels, verdicts, credit cost), and standard server logs (IP, user agent, request path). Scan source documents are processed transiently and deleted after the scan completes — they are not stored at rest.
Purpose
Host the FastAPI backend and PostgreSQL database. Operate the primary and warm-standby servers for service continuity.
Processing Location
United States (primary data center — Boston) and United Kingdom (warm-standby data center — Manchester). Database replication maintains parity between both regions for service continuity.
Terms / DPA

Tawk.to Inc.

Support Chat
Data Category
In-app support chat messages, sender email address, and any information you share in support conversations.
Purpose
Deliver the in-app support chat feature. Store chat history for service continuity across sessions.
Processing Location
United States
Terms / DPA

Cloudflare, Inc.

Registrar / Edge / Hosting
Data Category
Standard web request metadata (IP address, user agent, timestamps) for delivering the marketing site, app PWA, and API. Domain registration records for rentalguards.com.
Purpose
Domain registrar for rentalguards.com. DNS, TLS termination, and edge CDN for all rentalguards.com hostnames (apex, app PWA, API). Cloudflare Pages hosts the marketing site at rentalguards.com and the app PWA at staging.rentalguards.com.
Processing Location
Global edge network (primary United States)
Terms / DPA