Skip to content
R Renaro
ProductSolutionsComparePricingDocsResources
Book a 20-min walkthrough
ProductSolutionsComparePricingDocsResources Book a 20-min walkthrough
  1. Home
  2. Legal
  3. Subprocessors

Legal

Subprocessors

Renaro uses a small set of vetted vendors to run the platform. This page lists every subprocessor that can touch personal data, what it does, and how operators are told before anything on this list changes.

Effective 2026-07-18 · last updated 2026-07-18

What this list is

Renaro processes personal data on behalf of the transportation operators who use the platform, as described in the Privacy Policy and the Data Processing Addendum. To provide the service, Renaro engages the third-party vendors below as subprocessors. Each one is bound by a written agreement with data-protection obligations at least as protective as Renaro's own commitments, and each processes only what its role requires.

Vendors an operator connects on their own initiative - accounting ledgers, calendar sync, their own webhook endpoints, or their own messaging providers - act on the operator's instructions rather than Renaro's and are listed separately at the end of this page.

How changes are announced

Before adding a new subprocessor or materially changing what an existing one does, Renaro updates this page and notifies operators with active accounts through the platform or by email at least 30 days in advance, except where an emergency replacement is needed to keep the service secure or available - in which case notice follows as soon as reasonably possible. Operators with a signed Data Processing Addendum may object on reasonable data-protection grounds as described there.

Infrastructure subprocessors

These vendors host the platform and store data at rest. Renaro's production database and compute run in United States regions; data is encrypted in transit everywhere.

Infrastructure
VendorRoleData involvedLocation
NeonPrimary PostgreSQL database - the platform's source of truthAll platform records, including operator, driver, passenger, booking, payment, and audit dataUnited States (AWS us-east-1)
RailwayCompute hosting for the API and background workersAll data in transit through the platform's servicesUnited States (us-east4)
UpstashRedis cache, realtime pub/sub, and rate limitingShort-lived operational state, including live driver GPS buffersUnited States
CloudflareWeb hosting (Pages), content delivery, and object storage (R2)Web assets; stored files such as driver documents, trip signatures, generated PDFs, imports, and data-export archivesGlobal edge network; storage per deployment configuration

Product subprocessors

These vendors provide specific product capabilities. Where a capability is optional or operator-enabled, data flows only when it is in use.

Product capabilities
VendorRoleData involvedLocation
WorkOSAuthentication for operator staff and drivers (AuthKit, sessions, MFA)Account email, name, profile image, organization membership; sign-in IP and user agentUnited States
StripePayments, subscriptions, bank-debit collection, and payouts (Stripe Connect)Payer name, email, phone; tokenized card and bank references; charge and payout records. Card and bank numbers go directly to Stripe and never touch Renaro's serversUnited States and global
TwilioSMS, WhatsApp, voice calls, phone-line booking (IVR), and number maskingPhone numbers, message content (which can include names, addresses, fares, and links), call metadata, speech-to-text of spoken addresses, and call recordings where an operator enables recordingUnited States and global
ResendTransactional and operator-configured email deliveryRecipient email addresses; message content including booking details, receipts, sign-in links, and attached documentsUnited States
ExpoMobile push-notification delivery and app updatesDevice push tokens and notification content such as trip status and message previewsUnited States
Google (Maps Platform)Address search, geocoding, routing, and time zones - called from Renaro's serversTyped address text and precise trip coordinates; no account identity is attached by RenaroUnited States and global
Google / Apple (sign-in)Optional passenger sign-in with a Google or Apple account, where enabledAccount email and name returned by the chosen providerUnited States and global
MapboxMap rendering in the dashboard and passenger app; static map imagesMap viewport and trip coordinates; static-map images in emails embed pickup and dropoff coordinates; viewer IP when tiles or images loadUnited States
SentryError and crash reporting across the platform and appsTechnical error context and internal account identifiers; the operator dashboard also attaches the signed-in operator's emailUnited States
PostHogProduct analytics and feature flags in the operator dashboardPseudonymous usage events keyed to internal account and organization identifiers; request IP received server-sideUnited States
AviationStack / AeroDataBox (via MagicAPI) / Flightradar24Flight-status tracking for airport pickupsFlight number and date only - never passenger detailsUnited States and global

Services your operator connects

Some destinations receive data because an operator connects them and instructs Renaro to send it. These act on the operator's behalf, under the operator's own agreements with those vendors, and are not Renaro subprocessors:

  • Accounting ledgers - QuickBooks, Xero, and Sage receive invoice records containing the customer name, booking reference, dates, and amounts when an operator connects accounting sync.
  • Calendar sync - Google Calendar and Microsoft Outlook receive booking events containing the passenger name, pickup and dropoff addresses, and times when an operator connects a calendar.
  • Operator webhook endpoints - operators can subscribe their own systems to platform events; depending on the events selected, payloads can include passenger name, phone, email, and trip coordinates. Securing those endpoints is the operator's responsibility.
  • Operator-configured providers - where an operator brings their own messaging or delivery provider, data flows to it under the operator's agreement with that provider.
  • Partner operators - where an operator farms a booking to a partner operator, trip details and the passenger fields permitted by the operator's sharing settings are disclosed to that partner.

What is deliberately absent

Renaro sends no personal data to advertising networks, data brokers, or AI model providers. There is no third-party session recording. The marketing site at renaroapp.com uses no third-party services at all. Malware scanning of uploaded files runs on Renaro-controlled infrastructure rather than a third-party service. Integrations that exist in the product but are not yet functional - for example the NetSuite connector and the GNET partner-network gateway - send nothing externally; if they go live, this page changes first under the notice process above.

Questions

Questions about this list, vendor agreements, or international-transfer safeguards: support@renaroapp.com, or write to Renaro, Privacy Desk, London, United Kingdom.

Related documents

  • Privacy Policy
  • Data Processing Addendum
  • Terms of Service

On this page

  • What this list is
  • How changes are announced
  • Infrastructure subprocessors
  • Product subprocessors
  • Services your operator connects
  • What is deliberately absent
  • Questions
R Renaro

Transparent dispatch software for taxi, limo, and private hire operators.

Product

  • Live dispatch
  • Booking management
  • Payments and ledger
  • Analytics

Solutions

  • Taxi fleets
  • Limo operators
  • Airport transfers
  • Corporate transport

Docs

  • Platform overview
  • Dispatch scoring
  • Payments and ledger
  • API and webhooks

Explore

  • Compare software
  • Integration guides
  • Market pages
  • Buying guides

Company

  • About
  • Security
  • Book demo
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Acceptable use
  • All legal documents
© 2026 Renaro Terms Privacy Cookies Dispatch, accounted for.