Legal
Subprocessors
Renaro uses a small set of vetted vendors to run the platform. This page lists every subprocessor that can touch personal data, what it does, and how operators are told before anything on this list changes.
What this list is
Renaro processes personal data on behalf of the transportation operators who use the platform, as described in the Privacy Policy and the Data Processing Addendum. To provide the service, Renaro engages the third-party vendors below as subprocessors. Each one is bound by a written agreement with data-protection obligations at least as protective as Renaro's own commitments, and each processes only what its role requires.
Vendors an operator connects on their own initiative - accounting ledgers, calendar sync, their own webhook endpoints, or their own messaging providers - act on the operator's instructions rather than Renaro's and are listed separately at the end of this page.
How changes are announced
Before adding a new subprocessor or materially changing what an existing one does, Renaro updates this page and notifies operators with active accounts through the platform or by email at least 30 days in advance, except where an emergency replacement is needed to keep the service secure or available - in which case notice follows as soon as reasonably possible. Operators with a signed Data Processing Addendum may object on reasonable data-protection grounds as described there.
Infrastructure subprocessors
These vendors host the platform and store data at rest. Renaro's production database and compute run in United States regions; data is encrypted in transit everywhere.
| Vendor | Role | Data involved | Location |
|---|---|---|---|
| Neon | Primary PostgreSQL database - the platform's source of truth | All platform records, including operator, driver, passenger, booking, payment, and audit data | United States (AWS us-east-1) |
| Railway | Compute hosting for the API and background workers | All data in transit through the platform's services | United States (us-east4) |
| Upstash | Redis cache, realtime pub/sub, and rate limiting | Short-lived operational state, including live driver GPS buffers | United States |
| Cloudflare | Web hosting (Pages), content delivery, and object storage (R2) | Web assets; stored files such as driver documents, trip signatures, generated PDFs, imports, and data-export archives | Global edge network; storage per deployment configuration |
Product subprocessors
These vendors provide specific product capabilities. Where a capability is optional or operator-enabled, data flows only when it is in use.
| Vendor | Role | Data involved | Location |
|---|---|---|---|
| WorkOS | Authentication for operator staff and drivers (AuthKit, sessions, MFA) | Account email, name, profile image, organization membership; sign-in IP and user agent | United States |
| Stripe | Payments, subscriptions, bank-debit collection, and payouts (Stripe Connect) | Payer name, email, phone; tokenized card and bank references; charge and payout records. Card and bank numbers go directly to Stripe and never touch Renaro's servers | United States and global |
| Twilio | SMS, WhatsApp, voice calls, phone-line booking (IVR), and number masking | Phone numbers, message content (which can include names, addresses, fares, and links), call metadata, speech-to-text of spoken addresses, and call recordings where an operator enables recording | United States and global |
| Resend | Transactional and operator-configured email delivery | Recipient email addresses; message content including booking details, receipts, sign-in links, and attached documents | United States |
| Expo | Mobile push-notification delivery and app updates | Device push tokens and notification content such as trip status and message previews | United States |
| Google (Maps Platform) | Address search, geocoding, routing, and time zones - called from Renaro's servers | Typed address text and precise trip coordinates; no account identity is attached by Renaro | United States and global |
| Google / Apple (sign-in) | Optional passenger sign-in with a Google or Apple account, where enabled | Account email and name returned by the chosen provider | United States and global |
| Mapbox | Map rendering in the dashboard and passenger app; static map images | Map viewport and trip coordinates; static-map images in emails embed pickup and dropoff coordinates; viewer IP when tiles or images load | United States |
| Sentry | Error and crash reporting across the platform and apps | Technical error context and internal account identifiers; the operator dashboard also attaches the signed-in operator's email | United States |
| PostHog | Product analytics and feature flags in the operator dashboard | Pseudonymous usage events keyed to internal account and organization identifiers; request IP received server-side | United States |
| AviationStack / AeroDataBox (via MagicAPI) / Flightradar24 | Flight-status tracking for airport pickups | Flight number and date only - never passenger details | United States and global |
Services your operator connects
Some destinations receive data because an operator connects them and instructs Renaro to send it. These act on the operator's behalf, under the operator's own agreements with those vendors, and are not Renaro subprocessors:
- Accounting ledgers - QuickBooks, Xero, and Sage receive invoice records containing the customer name, booking reference, dates, and amounts when an operator connects accounting sync.
- Calendar sync - Google Calendar and Microsoft Outlook receive booking events containing the passenger name, pickup and dropoff addresses, and times when an operator connects a calendar.
- Operator webhook endpoints - operators can subscribe their own systems to platform events; depending on the events selected, payloads can include passenger name, phone, email, and trip coordinates. Securing those endpoints is the operator's responsibility.
- Operator-configured providers - where an operator brings their own messaging or delivery provider, data flows to it under the operator's agreement with that provider.
- Partner operators - where an operator farms a booking to a partner operator, trip details and the passenger fields permitted by the operator's sharing settings are disclosed to that partner.
What is deliberately absent
Renaro sends no personal data to advertising networks, data brokers, or AI model providers. There is no third-party session recording. The marketing site at renaroapp.com uses no third-party services at all. Malware scanning of uploaded files runs on Renaro-controlled infrastructure rather than a third-party service. Integrations that exist in the product but are not yet functional - for example the NetSuite connector and the GNET partner-network gateway - send nothing externally; if they go live, this page changes first under the notice process above.
Questions
Questions about this list, vendor agreements, or international-transfer safeguards: support@renaroapp.com, or write to Renaro, Privacy Desk, London, United Kingdom.