DealerDOH Service Providers
Runtime providers — v1.1 stack
| Provider | Role | Data it processes | Region | Status |
|---|---|---|---|---|
| Vercel | Frontend hosting/CDN | Serves the app to browsers; platform edge/request logs (connection metadata incl. IP) | US/global edge | Active — production and development |
| Render | API hosting | All application traffic; service logs (request lines incl. client IP, structured app logs); production service disk (database file, uploaded report files, generated reports) | Oregon, US | Active — production and development |
| Supabase | Sign-in (Auth) + PostgreSQL database | Staff account identities (email, password credentials, session state, display name), authorization/membership rows, all operational business data; provider auth/audit logs | us-west-2 (Oregon, US) | Planned for v1.1 activation. A dedicated production project exists but is empty and not connected to anything; it begins processing real data only when v1.1 ships |
| Sentry | Error monitoring | Error/exception events — configured to exclude user identity, request bodies, cookies; masked URLs; request references. Retention ~30 days on the current plan | US (SaaS) | Planned for v1.1 activation. Dedicated production projects exist but are empty and not connected |
| PostHog | Product analytics | Named product events under an internal account identifier (never email/name); role/store identifiers; ingest-side connection metadata. Event retention ~1 year on the current plan | US cloud | Planned for v1.1 activation. A dedicated production organization/project exists but is empty and not connected |
| Northwest Registered Agent | Domain registrar, DNS, and email service for dealerdoh.com | Emails sent to the support/privacy address (which may include staff names/addresses and whatever senders include); DNS records | US | Active at publication — hosts support@dealerdoh.com (privacy@ forwards to it) |
Today's actual production processors (pre-v1.1 beta): Vercel and Render only. Supabase, Sentry, and PostHog currently process synthetic development data. Their production projects have been provisioned in advance but are empty and wired to nothing; they begin processing real dealership/staff data only when v1.1 ships through its approved release process, at which point this page's status entries are updated (planned → active) after runtime verification.
Development infrastructure (not a subprocessor of dealership data)
GitHub hosts the private source-code repository and CI. It processes source code and synthetic test fixtures only — no real dealership operational data, no customer data, and no secrets are in the repository (full-history audit clean; real exports and databases are exclusion-listed and verified absent). CI runs against synthetic data and disposable containers.
Planned — not currently active
An inbound-email provider for scheduled vendor-report delivery is deferred and not active — the automated vendor-report acquisition it would serve is deferred pending pilot/contract authorization and required vendor evidence. No such provider processes anything today, and none activates in v1.1. If adopted later, this page and the Privacy Policy will be amended first.
Changes
Provider additions or changes that affect dealership data will be reflected here before they take effect, with this page's date updated.