Sub-Processors

Last updated: 13 July 2026

This page lists the third-party sub-processors that may process Customer Personal Data on behalf of HQ Parts UK Ltd (trading as Vectro) in connection with the Service. It supports our Data Processing Agreement. We notify subscribers by email or in-app notice at least 30 days before adding a new sub-processor.

Active Sub-Processors

Provider Service Categories of Data Location Transfer Mechanism
Railway Corp. Application hosting and managed PostgreSQL database Customer Personal Data held in the application database: account data, customer and lead records, quotes and orders, notes, the content of emails sent to and received from end customers, attachment metadata (file name, size, storage reference), OAuth tokens for connected integrations and two-factor authentication secrets (both encrypted at rest at application level), and usage logs. Uploaded file contents are not stored in the database — they are held by Cloudflare R2 (below). EU West (Amsterdam) Within UK / EEA — adequacy
Cloudflare, Inc. R2 object storage — every file uploaded to or received by Vectro, and encrypted database backups (30-day rolling retention) Encrypted database backups (full snapshot of personal data). All stored file contents: internal job files (measurement photos, signed terms and conditions), quote attachments, manufacturer order files (technical drawings, plans, photos), product datasheets and certificates, team message attachments, and attachments on emails sent to or received from end customers EU West Within UK / EEA — adequacy. Where Cloudflare's corporate access requires US transfers, UK IDTA / SCCs apply.
Stripe Payments UK, Ltd. / Stripe, Inc. Subscription billing and payment processing Customer billing contact details, payment method details (handled directly by Stripe — Vectro does not store full card numbers) UK / United States UK adequacy (UK entity); UK IDTA for transfers to Stripe Inc. (US)
Resend (Resend, Inc.) Transactional email delivery (quotes to end customers, appointment reminders, supplier order emails, account notifications) and inbound email receipt on in.vectro.uk, so that replies from end customers appear on the job in Vectro Outbound: recipient name and email address; subject and body of the message; any file attachments (such as quote PDFs or order attachments). Inbound: the sender's name and email address, and the subject, body and attachments of the message they send to us United States UK IDTA / SCCs; encryption in transit
Google LLC (optional, only if you connect) Google Calendar API for two-way appointment synchronisation; Google OAuth for sign-in Calendar event details that Vectro creates on the Customer's connected Google Calendar (date, time, customer name, location); OAuth tokens; basic Google profile (email, name) of the connecting user United States UK IDTA / SCCs; Google's Limited Use requirements
Xero, Intuit (QuickBooks), Sage (optional, only if you connect) Accounting synchronisation — creating or updating a contact and invoice in the accounting provider the Customer connects End-customer contact details (name, address, email) and the invoice / line data for the pushed quote Xero: New Zealand / UK · Intuit: United States · Sage: UK UK adequacy (UK / NZ entities); UK IDTA / SCCs for transfers to Intuit (US)
Pipedrive (optional, only if you connect) CRM synchronisation — Vectro mirrors a job's pipeline stage back to the deal in the Customer's connected Pipedrive account, and posts an order summary note on that deal. Deals and contacts are also read from Pipedrive into Vectro. The pipeline stage of a deal, and the order summary note Vectro writes to it (job reference, products, quantities and totals for the end customer's order); OAuth tokens EU / United States (AWS) UK IDTA / EU SCCs (Module 3); Pipedrive adheres to the EU-US Data Privacy Framework
Postcodes.io, OpenStreetMap (Nominatim), Ideal Postcodes Converting a postcode or address into map coordinates for the Day Planner and route mapping. Postcodes.io and OpenStreetMap are called directly from the user's browser; Ideal Postcodes (Republic of Ireland) is called server-side. The postcode or address being looked up (a customer or site address) UK / EU Within UK / EEA — adequacy
bunny.net (BunnyWay d.o.o.) Hosting and delivery of the tutorial videos in Vectro's Help tab. Videos are embedded as a player served directly by bunny.net, so a user's browser connects to bunny.net when a video is played. Vectro sends no account, customer or order data to bunny.net. When one of your users plays a tutorial video, their browser's connection to bunny.net carries the metadata inherent to any web request: IP address, user agent and referring page, together with playback performance metrics. bunny.net states that it anonymises IP addresses and does not permanently store identifiable information. No end-customer data is involved. EU (Slovenia); delivered from the nearest content delivery point of presence Within UK / EEA — adequacy. BunnyWay d.o.o. is an EU (Slovenian) company processing under the GDPR.

How to be notified of changes

By using the Service, you are subscribed to sub-processor change notifications, which we send to the email address registered to your account. You may also revisit this page at any time to see the current list. The "Last updated" date reflects the most recent change.

Objections

If you object to a new sub-processor on reasonable data-protection grounds, please contact us at support@vectro.uk within 30 days of the notice. We will work in good faith to address your concern. If we cannot reach a resolution and the new sub-processor is essential to the Service, you may terminate the affected portion of the Service in accordance with clause 6.2 of the DPA.