DealerDOH

DealerDOH Service Providers

Last reviewed: August 31, 2026 · Version 1.0 · The provider inventory behind the Privacy Policy's “Service providers” section. Regions are current configuration facts, not contractual residency guarantees.

Runtime providers — v1.1 stack

Providers, their roles, and honest current status.
ProviderRoleData it processesRegionStatus
VercelFrontend hosting/CDNServes the app to browsers; platform edge/request logs (connection metadata incl. IP)US/global edgeActive — production and development
RenderAPI hostingAll application traffic; service logs (request lines incl. client IP, structured app logs); production service disk (database file, uploaded report files, generated reports)Oregon, USActive — production and development
SupabaseSign-in (Auth) + PostgreSQL databaseStaff account identities (email, password credentials, session state, display name), authorization/membership rows, all operational business data; provider auth/audit logsus-west-2 (Oregon, US)Planned for v1.1 activation. A dedicated production project exists but is empty and not connected to anything; it begins processing real data only when v1.1 ships
SentryError monitoringError/exception events — configured to exclude user identity, request bodies, cookies; masked URLs; request references. Retention ~30 days on the current planUS (SaaS)Planned for v1.1 activation. Dedicated production projects exist but are empty and not connected
PostHogProduct analyticsNamed product events under an internal account identifier (never email/name); role/store identifiers; ingest-side connection metadata. Event retention ~1 year on the current planUS cloudPlanned for v1.1 activation. A dedicated production organization/project exists but is empty and not connected
Northwest Registered AgentDomain registrar, DNS, and email service for dealerdoh.comEmails sent to the support/privacy address (which may include staff names/addresses and whatever senders include); DNS recordsUSActive at publication — hosts support@dealerdoh.com (privacy@ forwards to it)

Today's actual production processors (pre-v1.1 beta): Vercel and Render only. Supabase, Sentry, and PostHog currently process synthetic development data. Their production projects have been provisioned in advance but are empty and wired to nothing; they begin processing real dealership/staff data only when v1.1 ships through its approved release process, at which point this page's status entries are updated (planned → active) after runtime verification.

Development infrastructure (not a subprocessor of dealership data)

GitHub hosts the private source-code repository and CI. It processes source code and synthetic test fixtures only — no real dealership operational data, no customer data, and no secrets are in the repository (full-history audit clean; real exports and databases are exclusion-listed and verified absent). CI runs against synthetic data and disposable containers.

Planned — not currently active

An inbound-email provider for scheduled vendor-report delivery is deferred and not active — the automated vendor-report acquisition it would serve is deferred pending pilot/contract authorization and required vendor evidence. No such provider processes anything today, and none activates in v1.1. If adopted later, this page and the Privacy Policy will be amended first.

Changes

Provider additions or changes that affect dealership data will be reflected here before they take effect, with this page's date updated.