Finacra
Sub-processors
Last updated 25 June 2026
This is the complete list of third parties that process customer data on Finacra's behalf, or that customer data flows through during normal product operation. Material additions are notified to customers 30 days in advance via email + a banner on this page, per our Data Processing Agreement. To object before the change takes effect, email ibrahim@finacra.com.
Infrastructure
| Sub-processor | Purpose | Region | Data | DPA |
|---|---|---|---|---|
| Vercel Inc. | Application hosting + edge network (app.finacra.com, api.finacra.com, app.itr.finacra.com, www.finacra.com, itr.finacra.com) | United States (iad1 primary) | All request payloads in flight; nothing persisted beyond function lifetime. | Link |
| Supabase Inc. | Postgres database (every customer record), object storage (Vault documents) | AWS Seoul (ap-northeast-2) | All persisted customer data. | Link |
| GitHub Inc. | Source code + CI runners (no customer data) | United States | Source code only; CI builds run against synthetic fixtures. | Link |
AI / LLM providers
Every LLM endpoint we use is pinned to a zero-retention configuration (no prompt logging, no training). The router (OpenRouter) is configured to pass our zero-data-retention header to downstream providers.
| Sub-processor | Purpose | Region | Data | DPA |
|---|---|---|---|---|
| OpenRouter (OpenRouter Inc.) | LLM router for OCR + chat (Ask / Forecast / Critic / ITR canvas / vault classify) | Routes to provider endpoints in US / EU per model; all endpoints pin zero-retention | Per-request prompts. No training on prompts. No persistence beyond the response stream. | Link |
| Microsoft Azure OpenAI | Structured extraction + embeddings (when routed via Azure) | East US 2 (Azure) | Per-request prompts. Microsoft no-training clause applies; 30-day abuse-monitoring buffer disabled on our subscription. | Link |
| Perplexity AI Inc. | Regulatory research (MCA / ICAI / CBDT lookups) via Sonar API | United States | Per-request prompts (typically a CIN or statute reference; no customer PII). | Link |
Communications
| Sub-processor | Purpose | Region | Data | DPA |
|---|---|---|---|---|
| Resend (Drei AI Inc.) | Transactional email (magic-link sign-in, reminders, exports, deletion confirmations) | United States | Recipient email, sender domain, subject, body, delivery webhook events. | Link |
| Twilio Inc. (planned, Phase B) | SMS + WhatsApp reminder delivery (currently stub-logged) | United States | Recipient phone number (E.164), message body. | Link |
Customer-authorised integrations (per-tenant OAuth)
These vendors aren't our processors in the strict sense — they're your books platforms, and the integration is opt-in per company. We list them here for transparency. You can disconnect any of these from the Integrations tab; tokens are deleted on disconnect.
| Sub-processor | Purpose | Region | Data | DPA |
|---|---|---|---|---|
| Intuit Inc. (QuickBooks) | Customer-authorised read of books data for compliance computation | United States | Per-customer OAuth-scoped access to invoices, bills, banking, contacts. No data shared back to Intuit beyond the OAuth round-trip. | Link |
| Zoho Corporation Pvt Ltd | Customer-authorised read of Zoho Books data | India + global (zoho.in / zoho.com) | Per-customer OAuth-scoped access to invoices, bills, banking, contacts. | Link |
| Tally Solutions Pvt Ltd | Local desktop-agent bridge (no Tally Solutions data exchange — agent runs in-customer) | India (customer machine) | No vendor-side data flow; the agent is paired locally. | Link |
| Marg ERP Ltd | Local desktop-agent bridge | India (customer machine) | No vendor-side data flow. | Link |
| Razorpay Software Pvt Ltd | Subscription billing + verification charges | India | Customer name, email, billing address, payment-method metadata (Razorpay holds card data, not Finacra). | Link |
Ancillary
| Sub-processor | Purpose | Region | Data | DPA |
|---|---|---|---|---|
| Google LLC (Workspace + OAuth) | Finacra-employee email/calendar; customer sign-in (OAuth identity only) | United States + EU (Google global) | Customer side: email + name only (OAuth profile + email scopes). Employee side: internal communications. | Link |
| Anthropic PBC (planned model option) | Alternative LLM endpoint for high-context reasoning when routed via OpenRouter | United States | Per-request prompts via OpenRouter (Anthropic does not log when called through OR with the appropriate header). | Link |
Change log
| Date | Change |
|---|---|
| 25 Jun 2026 | Initial publication. |