Legal

Sub-processors

This register lists the vendors that support the platform, for transparency. It is being finalized and is not legal advice. For any questions about how it applies to you, contact hello@cairahealth.ca.

Back

Vendors listed

7

Status

Being finalized

VendorPurposeData categoriesLocation

Supabase

Database, authentication, and application data storage.

Clinic account data, staff identity data, patient records, appointments, audit logs, and application configuration.

Production data is stored in Canada (ca-central-1).

Vercel

Application hosting, serverless functions, routing, and deployment.

Request metadata and minimal operational logs. Patient health information is not written to runtime logs.

Processing may occur outside Canada.

Stripe

Card-on-file setup, payment method tokenization, and no-show charge processing.

Payer/contact identifiers, Stripe customer and payment method IDs, card brand/last-4/expiry summary, and payment status metadata.

Payment processing may occur outside Canada. Raw card numbers are never stored in this application.

Resend

Transactional email delivery for staff invites and appointment messages.

Recipient email, message delivery metadata, and template content sent by the app. Clinical note content is not sent by email.

Processing may occur outside Canada.

Twilio

SMS delivery for appointment reminders and operational notifications.

Recipient phone number, message delivery metadata, and reminder text sent by the app.

Processing may occur outside Canada.

Sentry

Error monitoring and diagnostic event capture when configured.

Sanitized error messages, stack traces, route context, and operational metadata. Health information is scrubbed before telemetry is sent.

Processing may occur outside Canada.

Upstash

Rate limiting for public booking endpoints when configured.

Rate-limit keys derived from route, clinic identifier, and client IP. Patient record content is not stored.

Processing may occur outside Canada.