Sub-processors
Every company that can hold or transit your data. If it can see anything, it is here — an incomplete list would breach the agreement we ask you to sign.
Effective 13 August 2026 · Last updated 13 August 2026
The current list
| Company | Purpose | What it can see | Location |
|---|---|---|---|
| Railway | Application hosting, the Postgres database and object storage for uploaded images | All service data at rest and in transit — this is where the platform runs. | European Union |
| Channex.io | Connectivity to Booking.com, Expedia and other channels | Availability, rates and restrictions, plus the reservation details a channel sends us — guest name and contact for the booking it produced. Never folio or payment data. | European Union / United Kingdom |
| Stripe | Card guarantees on direct bookings, and card payments where a property enables them | Card details, which go to Stripe directly from the guest’s browser and never reach our servers. We hold a token and the last four digits. | Ireland / United States (EU Standard Contractual Clauses) |
| Resend | Transactional email — booking confirmations, invitations, password resets | Recipient address and the contents of the message we send. | United States (EU Standard Contractual Clauses) |
| Google Analytics 4 | Anonymous traffic analytics on this marketing website only | Website visitors who accepted cookies. IP anonymisation on. Never any hotel or guest data — this is not loaded by the products. | United States (EU Standard Contractual Clauses) |
Last updated 13 August 2026.
What is deliberately not on this list
Nothing that touches customer data. Two things that people sometimes expect to see here, and why they are absent:
- No analytics or session-recording tools inside the products. The analytics on this marketing website do not run in the software your staff use. Nobody is watching a receptionist’s screen.
- No AI or machine-learning provider. Your data is not sent anywhere to be processed by a model, and it is not used to train one — ours or anyone else’s.
How we change this list
We give customers 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object within that window we will try to find another way; if we cannot, you may cancel without penalty and we refund any prepaid, unused fees. The full terms are in the Data Processing Agreement.
Get told when it changes
Customers are notified automatically. If you are evaluating us and want to be told anyway, email privacy@reviosoft.app and we will add you to the notice list — no other mail comes with it.
Questions about anything on this page go to legal@reviosoft.app, and we will answer them in writing. If a clause here would stop you signing, tell us — most of it is negotiable and we would rather know.