Legal

Subprocessors

Last updated 3 September 2026 · Aventura Virtual Solutions Inc. (Canada), operating CloseRev

We keep this list short on purpose — every vendor is another party with access to your data. These are the ones we use and exactly what each one sees.

Current subprocessors

VendorPurposeData it can accessRegion
CloudflareHosting, database (D1), file storage (R2), session cache, and transactional emailAll application data, including uploaded files and the account emails we send youGlobal edge
StripeSubscription billing and payment processingBilling contact and payment details. Never sees uploaded customer dataUS / global
GoogleOptional "Sign in with Google" authenticationYour Google account identifier, name and email — only if you choose to use itUS / global
MetaAdvertising measurement on the marketing site — only if you accept advertising cookiesPages visited on our public site and approximate location. Never loaded on signed-in pages, so it sees no workspace or uploaded customer dataUS / global
LinkedInAdvertising measurement on the marketing site — only if you accept advertising cookiesPages visited on our public site and approximate location. Never loaded on signed-in pages, so it sees no workspace or uploaded customer dataUS / global
Google AnalyticsMarketing-site traffic measurement — only with your consentPages visited on our public site, approximate location and device. Loaded only after you accept, and never on signed-in pages, so it sees no workspace or uploaded customer dataUS / global

Planned, not yet in use

We list these for transparency because they appear in our roadmap. They are not currently processing any data, and this page will be updated with 30 days' notice before any of them goes live.

VendorPurposeData it would access
Error monitoringDiagnosing faultsDiagnostic data, with personal data scrubbed
Anthropic (Claude API)Optional assistance mapping unusual CSV column namesColumn headers and a small sample of rows, only where enabled

Account emails (verification and password reset) are sent by Cloudflare Email Sending rather than a separate email vendor — deliberately, so that using the product doesn't hand your email address to one more company.

What we don't use

No advertising networks, no data brokers, no third-party marketing or session-replay trackers. Our marketing analytics are cookie-free and don't identify individuals.

Changes

We give at least 30 days' notice before adding or replacing a subprocessor. To be notified, email privacy@closerev.com and we'll add you to the list. Your right to object is described in the DPA.