Subprocessors
The third parties that process information to help us operate Kavvim. This is the full list, not a summary. Each is bound by a written agreement limiting it to processing on our instructions.
Always active
These providers are engaged for every studio, because the Service cannot run without them.
| Vendor | Purpose | Personal information received | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Application and database hosting (Lightsail, us-east-1), object storage (S3), and key management (KMS) | All Customer Data at rest and in processing; all uploaded files, images and exports. KMS receives no personal information, only wrapped encryption keys | United States |
| Stripe, Inc. | Subscription billing and client invoice payment processing | Card details captured directly in the browser; billing name and email; customer and account identifiers; transaction amounts and descriptions; identity verification information collected by Stripe directly for connected accounts | United States |
| Mailjet SAS | Transactional email delivery | Recipient email addresses; message subject and body, which may contain names, invoice numbers, amounts, and booking details; invoice PDF attachments | European Union |
| Functional Software, Inc. (Sentry) | Error and crash monitoring, and release health | Diagnostic reports when a fault occurs: the error, stack trace, browser and operating system, user identifier, and the actions preceding it, plus a count of sessions started. Configured to exclude request contents, form values, cookies, and IP addresses. No session replay and no page contents | United States |
| Mapbox, Inc. | Address autocomplete | Partial address strings as typed, with a session identifier. Where you have granted browser location permission, an approximate location rounded to roughly 100 meters, sent as a ranking hint only. No names or account identifiers | United States |
Active when the feature is used
These providers receive information only when someone in your studio uses the feature that depends on them.
| Vendor | Purpose | Personal information received | Location |
|---|---|---|---|
| Anthropic, PBC | Studio assistant, and part of presentation generation | Your display name; questions asked; data retrieved to answer them, which where enabled may include client names, contact details, addresses, and notes | United States |
| Google LLC | Presentation generation, image captioning, image editing (Gemini) | Presentation content and instructions; image files, which where enabled may include photographs of client properties and interiors | United States |
| Photoroom SAS | Background removal from product and project images | The single image submitted for processing, typically a photograph of furniture, a product, or a project interior | European Union |
| Ship24 | Parcel tracking | Tracking number, destination country code, courier code, and an internal reference. No names, addresses, or client identifiers | European Union |
Each AI provider is configured so that submitted content is not used to train its models. For Anthropic and Google this is a term of their commercial agreements with us. For Photoroom it is an account-level setting we have enabled and maintain.
AI providers receive only what a specific request needs, and only when someone in your studio makes that request. If you would rather no client data reached an AI provider at all, turn the relevant features off yourself in Settings → AI, or turn off AI entirely. You do not need to ask us.
Optional integrations you connect yourself
These are not engaged by Kavvim. They process information only if a studio explicitly connects the integration, and only for the bookings that use it. Disconnecting the integration stops it.
| Vendor | Purpose | Personal information received | Location |
|---|---|---|---|
| Zoom Communications, Inc. | Meeting links for bookings, when connected | Booking title, time, and the attendee list for that booking | United States |
| Google LLC (Calendar/Meet) | Google Meet links for bookings, when connected | Event details, booking time, and attendee email addresses | United States |
| 8x8, Inc. (Jitsi Meet) | Fallback meeting rooms where no provider is connected | A generated room name and URL only. Meeting content is handled on Jitsi’s infrastructure | Depends on the instance configured |
Notice of changes
We will give at least 30 days’ notice by email to the studio owner before we add or replace a subprocessor, and this page will be updated on the same day the change takes effect. You may object on reasonable data-protection grounds within 15 days. If we cannot resolve the objection, you may terminate the affected portion of the Service and receive a prorated refund of prepaid fees, as set out in Section 4 of the Data Processing Addendum.
Where a subprocessor becomes unavailable or suffers an incident, we may substitute immediately and will notify you promptly afterward.
To be added to the notification list, or to raise an objection, email privacy@kavvim.com.
Changelog
| Date | Change |
|---|---|
| September 18, 2026 | Initial published list. |
Questions: privacy@kavvim.com.