Worthic uses third-party providers to operate, secure, process, store, and support the Service. This page lists material subprocessors that may process personal information or customer content.
Current subprocessors
| Provider | Purpose | Data categories | Notes |
|---|---|---|---|
| Render | Application hosting, deployment/build infrastructure, managed database hosting, background jobs, runtime logging, infrastructure monitoring, and backup/recovery support. | Customer account and workspace data, application database records, uploaded or generated business records where stored in the application database, authentication/session/security event records, billing and subscription records, audit logs, request metadata, IP addresses, device/browser metadata, application runtime logs, deployment/build logs, background job logs, environment/runtime metadata, and secrets/environment variables used to operate the hosted services. | Render hosts Worthic staging and production services and the managed PostgreSQL database infrastructure used by the application. Production database access is restricted through Render/internal service access rather than public direct database exposure. Render is also used as the deployment target for GitHub-based CI/CD and may retain deployment records, service logs, build logs, database metadata, backups, and operational telemetry. Worthic restricts Render account access, stores secrets only as protected environment configuration, and avoids intentionally logging passwords, authentication tokens, payment credentials, full card data, or unnecessary customer document contents. |
| Cloudflare | DNS hosting, domain routing, content delivery/network acceleration, TLS termination, DDoS protection, web application firewall/security filtering, bot/rate-limit controls, caching, and edge/network logging. | DNS records and domain configuration, request metadata, IP addresses, user-agent/device/browser metadata, URL/path and routing metadata, TLS/certificate metadata, security event logs, firewall/WAF events, bot/rate-limit events, cache logs, geolocation/region metadata derived from network traffic, and limited application response metadata where routed through Cloudflare. | Cloudflare is used as an internet-facing infrastructure and security provider in front of Worthic services. It may process network traffic and security logs before requests reach the application hosting environment. Worthic configures Cloudflare to minimise unnecessary logging of customer content, avoid exposing secrets or authentication tokens in URLs, restrict administrative access, and retain Cloudflare logs only for operational, security, incident investigation, legal, and compliance purposes. |
| Cloudflare Analytics | Website and product usage analytics, traffic measurement, performance monitoring, feature usage reporting, and aggregated security/network insights. | Page and route events, feature usage events, request metadata, IP address or approximate location data, device/browser/user-agent metadata, referrer/source metadata, timestamps, aggregated traffic metrics, and limited account/workspace identifiers where analytics is linked to authenticated product usage. | Used to understand service usage, performance, and traffic patterns. Analytics is configured to minimise unnecessary personal information, avoid collecting secrets, payment credentials, authentication tokens, or document contents, and retain analytics data only for operational, product, security, compliance, and reporting purposes. |
| Cloudflare Workers AI | AI-assisted document extraction and analysis, categorization, AI assistant responses, and AI-generated insights within Worthic features. | User prompts, assistant responses, document text/images or extracted document data, accounting and workspace context supplied for the request, categorization inputs/outputs, AI insight inputs/outputs, technical request metadata, model/runtime logs, and AI usage/audit records. | Used through Worthic-controlled AI workflows and request logging. Authenticated AI requests are scoped to the requesting user’s workspace and permissions. Worthic does not send secrets, payment credentials, authentication tokens, or unnecessary personal/financial data, and processes AI inputs only as needed for the relevant feature. |
| OpenAI | AI-assisted document analysis and extraction, document categorization, financial insights, conversational assistants, reasoning, and related generative-AI functionality. | User prompts and instructions; conversation content; financial, account, transaction, reporting-line, and workspace information submitted for analysis; document text, extracted content, document images or page renders where vision processing is used; filenames and limited document metadata; generated outputs; and technical request metadata required to operate, secure, and monitor the service. | Used to provide Worthic’s AI-assisted features, including document understanding, categorization, financial insights, and conversational assistance. Worthic sends only the information required for the requested AI operation. Users and workspace administrators should avoid submitting unnecessary personal or sensitive information. Processing and retention are governed by Worthic’s agreement and applicable service terms with OpenAI. |
| Postmark | Transactional email delivery and inbound email processing for account verification, password resets, operational notifications, support/admin alerts, and user-submitted document ingestion. | Email addresses, recipient/sender names where provided, account/workspace identifiers, email subject and body content, verification/reset links or tokens, inbound email content, attachments and document metadata submitted for ingestion, delivery status, bounce/suppression data, timestamps, IP/device metadata where included in email events, and message logs. | Used for service emails and to receive user-submitted documents for ingestion and analysis. Worthic does not include passwords, full payment credentials, authentication tokens, or unnecessary sensitive information in email content. Inbound attachments may contain customer business, financial, or personal information and is routed only to the intended workspace/document-processing flow. Email logs and delivery records may be retained for account security, support, deliverability, audit, legal, and compliance purposes. |
| Lemon Squeezy | Merchant of Record; checkout hosting, payment processing and authorisation, subscription billing, tax calculation and collection, invoicing, transaction settlement, payment notifications, refunds, fraud prevention, and chargeback/dispute handling. | Customer name, billing email and contact details, billing address and country, tax/VAT identifiers where supplied, payer/customer identifiers, subscription and invoice references, transaction amount/currency/status, payment-method references or tokens, limited card/payment-network metadata such as brand and last four digits where provided, refund/dispute metadata, IP address, device/browser data, and fraud-prevention metadata. | Used to sell Worthic subscriptions, process and reconcile payments, calculate and remit applicable taxes, issue invoices/receipts, prevent fraud, and manage refunds and disputes. Lemon Squeezy acts as Merchant of Record. Worthic does not directly collect or store full card numbers, card security codes, or other sensitive payment credentials when Lemon Squeezy-hosted checkout and provider-side tokenisation are used. Billing records may be retained as required for accounting, tax, fraud prevention, chargebacks, legal obligations, and regulatory compliance. |
| Sentry | Application error monitoring, performance diagnostics, release health, issue triage, and operational alerting. | Technical logs, error events, stack traces, release and environment identifiers, affected routes, request metadata, device and browser metadata, IP address or approximate location data, user/account/workspace identifiers where included in diagnostic context. | Used to detect, investigate, and remediate staging and production application errors. Worthic has configured Sentry to avoid intentional collection of secrets, passwords, payment credentials, authentication tokens, full customer documents, or unnecessary customer financial content. |
| Google OAuth / Google Identity Services | User authentication, Google sign-in, account linking, identity verification, and authentication security checks. | Google account identifier, email address, profile name where provided, OAuth tokens or claims, sign-in metadata, account-linking status, device/browser metadata, IP address or approximate location data, timestamps, and authentication/security event records. | Used where users choose Google sign-in or account linking. Google OAuth is used for authentication and does not provide Google with customer workspace documents or financial records unless separately sent through another Google integration. Worthic requests only necessary OAuth scopes, protects OAuth credentials and tokens, and treats authentication records as security and account data. |
Updates
Worthic may update this page from time to time. Where required by contract or law, affected customers will be notified of material subprocessor changes.