Venzato uses the third-party providers below to run the service. When you publish a site or an app with Venzato, you are the controller of the visitor data it collects and Venzato acts as your processor; these providers are the subprocessors behind that.
These providers are involved in running Venzato itself. You cannot use the service without them.
| Provider | Purpose | Data | Processed in |
|---|---|---|---|
| Fly.io | Application servers. Every request to Venzato and to sites published with it runs here. | All request traffic: account data, published-site visitor submissions, uploads, payment callbacks. | Frankfurt (EU) |
| Supabase | Database, sign-in, and file storage. | Accounts, projects, generated content, visitor records from your published site, uploaded and generated media. | Frankfurt (EU) |
| Cloudflare | DNS and the TLS edge for published sites and custom domains, plus Turnstile bot protection on Venzato sign-up and sign-in. | Visitor IP address, user agent, requested URL, and page content in transit; for Turnstile, the IP address and the browser and device signals of the person signing up or signing in. | Global edge network |
| Anthropic | Generates and edits your design (Claude models). | Your prompts and business brief, reference photos you upload, and the HTML of the site being edited. | United States |
| OpenAI | Voice assistant, image generation, and page planning. | Microphone audio and its transcript, design descriptions, generated images. | United States |
| Resend | Transactional email: verification codes and notifications. | Recipient email address and message content. | United States |
| Sign in with Google, push notifications, and the interface font. | Identity token, device push token, and IP address when the font is fetched. | United States | |
| Apple | Sign in with Apple. | Identity token and email address, or the relay address if you chose Hide My Email. | United States |
| Polar | Web payments. Polar is the merchant of record and is the seller on your web purchase. | Payment and billing details, entered on Polar's own checkout page. | United States |
| RevenueCat | Keeps app store subscriptions in sync with your account. | Anonymous account identifier and subscription state. | United States |
| Codemagic | Builds the mobile app when you publish one. | App name, bundle identifier, and your own store signing credentials. | European Union |
| Apple App Store / Google Play | Publishes your app to the stores and handles in-app purchases. | App package and store listing details; purchase data for store subscriptions. | United States |
These are not used unless you enable the matching feature on your published site or app. Turning the feature off stops the data flow.
| Provider | Purpose | Data | Processed in |
|---|---|---|---|
| Google AdSense / AdMob | Shows ads on your published site or app, if you add your ad account. | Visitor IP address, advertising identifier, page viewed, ad interactions. | United States |
| iyzico or Stripe | Takes payments on your published site, through your own account with them. | Your customers' payment details, entered on the provider's own page. | Depends on the provider you choose |
| ExchangeRate-API, Binance | Live currency and price data for sites that display it. | None. Our server fetches the rates; visitors never contact these providers. | No personal data |
| An AI or data endpoint you connect | Answers visitor chat messages or supplies live data, if you connect one. | Visitor chat messages and whatever the module sends. | Depends on the provider you choose |
| Google Play services | The "share my location" button, if your published app uses it. | Visitor's device location, only when they press the button. | United States |
Venzato does not currently offer a signed Data Processing Addendum. If your organisation requires one before purchasing, write to info@venzato.com and say so.
This list changes as the product changes. The date above is the last time it was reviewed against the running code.
Stock photographs are downloaded once by our server and mirrored to our own storage. Visitors to your site never connect to the stock photo sources, so those sources receive no visitor data.