This page identifies the third-party service providers ("Sub-processors") used by Twomiah Software Ventures to process Personal Data in connection with its services. This disclosure supports our obligations under our Data Processing Agreement and applicable data protection laws.
Our Approach
We carefully select Sub-processors and require each to:
- Process Personal Data only on our documented instructions
- Implement appropriate technical and organizational safeguards
- Enter into data processing agreements with us
- Provide adequate transfer safeguards (including Standard Contractual Clauses where applicable)
Payment Processing
| Provider | Purpose | Data Processed | Location |
| Stripe | Subscriptions, billing, checkout | Payment details, billing info, transaction history | US / EU |
| PayPal | Payment processing (BreakReturns) | Payment details, billing info | US / EU |
Hosting & Infrastructure
| Provider | Purpose | Data Processed | Location |
| Render | Application hosting, PostgreSQL databases | All application data, deployment configs | US |
| Supabase | Database hosting, authentication | All platform data (tenants, users, CRM records) | US |
| Amazon Web Services (S3) | File and media storage | Uploaded files, documents, images | US |
| Cloudflare | CDN, DNS, R2 object storage | Traffic data, cached content, media files | Global |
| Redis | Caching, job queues (Twomiah Ads) | Transient operational data | US |
Email & Communications
| Provider | Purpose | Data Processed | Location |
| SendGrid (Twilio) | Transactional emails, notifications | Email addresses, message content | US |
| Resend | Transactional emails | Email addresses, message content | US |
| Gmail SMTP | Transactional emails (BreakReturns) | Email addresses, message content | US |
SMS & Voice
| Provider | Purpose | Data Processed | Location |
| Twilio | SMS verification, notifications, voice, call recording | Phone numbers, message content, call audio | US |
Artificial Intelligence
| Provider | Purpose | Data Processed | Location |
| Anthropic (Claude) | Content generation, code generation, AI features | User inputs, generated content | US |
| OpenAI | Image analysis, receipt scanning, AI receptionist | User inputs, uploaded images, audio | US |
Advertising Platforms
| Provider | Purpose | Data Processed | Location |
| Meta Platforms | Ad campaign management (Twomiah Ads) | Campaign data, audience targeting, performance metrics | US / EU |
| Google Ads | Ad campaign management (Twomiah Ads) | Campaign data, audience targeting, performance metrics | US |
| TikTok | Ad campaign management (Twomiah Ads) | Campaign data, ad content | US |
Maps & Geolocation
| Provider | Purpose | Data Processed | Location |
| Google Maps / Places | Address autocomplete, mapping, satellite imagery | Addresses, geolocation data | US |
Analytics & Monitoring
| Provider | Purpose | Data Processed | Location |
| Sentry | Error tracking, performance monitoring | Device data, error context, stack traces | US |
| Google Analytics | Usage analytics (optional, admin-configurable) | Device data, usage behavior, IP address | US |
Code & Deployment
| Provider | Purpose | Data Processed | Location |
| GitHub | Source code hosting, automated deployment | Source code (no customer PII in repos) | US |
Push Notifications
| Provider | Purpose | Data Processed | Location |
| Firebase (Google) | Mobile push notifications | Device tokens, notification content | US |
| Web Push (VAPID) | Browser push notifications | Subscription endpoints, notification content | US |
Media & Image Storage
| Provider | Purpose | Data Processed | Location |
| Cloudinary | Image hosting (Card Shop) | Uploaded images | US |
Healthcare Integrations
| Provider | Purpose | Data Processed | Location |
| Sandata | Electronic Visit Verification, Medicaid compliance | Visit records, caregiver data, patient identifiers | US |
| Gusto | Payroll processing | Employee data, compensation, tax info | US |
Accounting
| Provider | Purpose | Data Processed | Location |
| QuickBooks Online (Intuit) | Invoicing, accounting sync | Financial data, invoices, customer records | US |
| QuickBooks Desktop | Desktop accounting sync (QBWC) | Financial data, invoices | On-premise |
Data Architecture & Isolation
Twomiah uses a multi-tenant architecture with strong data isolation:
- Each customer receives a dedicated, isolated database instance
- No customer data is commingled with another customer's data in the same database
- Data flows through: Supabase → Render (PostgreSQL) → isolated customer database
International Transfers
Where Personal Data is transferred outside the EEA/UK, Twomiah relies on Standard Contractual Clauses (SCCs) and equivalent safeguards provided by our Sub-processors.
Updates & Objections
We may update this list periodically. Where required by applicable law or contract, we will provide advance notice of new Sub-processors and allow customers to object.
To request more information or object to a Sub-processor, contact us at support@twomiah.com. We will review requests in good faith.