Trust

Subprocessor & service-provider list

Expoalb uses the providers below to operate server-backed parts of the product. A provider only receives the categories of information needed for the feature in which it participates. Client-side PDF tools that run locally do not send the selected file to these providers merely to perform the local tool operation.

Vercel

Purpose
Application hosting, server runtime, deployment delivery and related infrastructure operations.
Data involved
Request and application data needed to serve server-backed Expoalb features.
When used
Used for the hosted Expoalb application and server routes.

Supabase

Purpose
Authentication, PostgreSQL database services and server-backed file storage.
Data involved
Account, organization, workflow, audit, property, integration metadata and stored-file data used by server-backed features.
When used
Used for authenticated and other server-backed Expoalb features.

Resend

Purpose
Transactional and configured email delivery.
Data involved
Recipient email address and the content/metadata needed to send the requested service email.
When used
Used when Expoalb sends supported email messages such as reminders or invitations.

Stripe

Purpose
Subscription, payment and billing operations.
Data involved
Billing identifiers, subscription/invoice metadata and payment information supplied directly to Stripe.
When used
Used when a customer starts or manages paid Expoalb billing.

Anthropic

Purpose
Commercial AI processing for explicitly invoked AI-assisted Expoalb features.
Data involved
The user request and limited relevant Expoalb record context needed to perform the requested feature. Connected-account data is included only when needed for that customer workflow.
When used
Used only when an AI-assisted feature backed by Anthropic is invoked.

Intuit QuickBooks Online

Purpose
Customer-directed accounting data exchange through Intuit OAuth and the official QuickBooks Online API.
Data involved
Authorized company identifiers and supported accounting records such as customers, contact details, invoices, items and related metadata made available by the connected account.
When used
Used only after an authorized Expoalb organization connects QuickBooks. Disconnecting revokes Expoalb API access; Intuit remains subject to its own terms and retention practices.

Customer-directed integrations

An authorized organization may choose to connect an external service. Data exchanged through a customer-directed integration is transferred because the customer enabled that connection and approved the provider's authorization flow. Expoalb does not treat connected accounting services as general-purpose archives, does not sell connected-account data, and does not use QuickBooks-originated data to train a shared/general Expoalb AI model.

Contract boundary

This page is a product disclosure, not a signed Data Processing Addendum or service-level agreement. Customers that require negotiated data-processing, notice, residency or security commitments should complete that review before placing regulated data in Expoalb.

Last reviewed: August 25, 2026. Provider use may change as Expoalb adds or removes product capabilities; material changes should be reflected in Expoalb's legal disclosures and customer acceptance flow.