Subprocessors
Last updated: 5 June 2026
BossOps uses third-party providers to operate the service. Optional providers apply only when the related feature is configured or enabled for a customer workspace.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Hosting, Workers/Pages, database/storage, security and delivery | Workspace data, files, logs and account data |
| Stripe | Payments, billing and subscription management | Billing contact, plan and payment metadata |
| OpenAI | AI/OCR extraction for invoices, recipes, menus and document processing where enabled | Uploaded document content needed for extraction |
| Resend | Transactional email, invites, notifications and support messages where email is configured | Email addresses, message metadata and email content |
| OneSignal | Push notifications where enabled | Push subscription IDs, message metadata and notification content |
| Twilio | SMS notifications where enabled | Phone numbers, message metadata and SMS content |
| Xero | Optional accounting/payroll sync authorised by a customer | Approved invoices, contact/payment metadata and mapped timesheet data where configured |
| Customer-selected POS providers | Optional sales, stock, attendance or menu imports configured by a customer or reseller | Sales rows, menu/product data, stock movements, attendance rows and integration metadata |
| Mackintosh Projects support tools | Customer support and operational administration | Support messages and relevant account context |
Changes
New subprocessors may be added as BossOps develops. Customers may raise reasonable data protection objections by emailing [email protected].