In plain terms
Plain language: a list of every third-party service Lefover uses to run, what each one has access to, and what each one cannot see.
What this document is
A subprocessor is a third-party service that processes user data on behalf of Lefover. Our Privacy Policy describes how we handle your data in general; this document lists every subprocessor we use, what data they handle, and why we use them.
We maintain this list separately from our Privacy Policy because subprocessors may change more frequently (as we add new tools or replace providers). Material changes to our subprocessor list trigger a notification as described below.
If you have questions about any subprocessor, contact us at [email protected].
How we choose subprocessors
We only use service providers that:
- Are essential to operating Lefover (we don’t add tools for convenience)
- Have strong privacy and security practices, documented publicly
- Accept contractual obligations to protect your data (data processing agreements where applicable)
- Respect data residency requirements, so that each region’s member data stays in that region
We evaluate each new subprocessor before adopting them and periodically review our existing list.
Current subprocessors
This is the complete list of subprocessors used by Lefover as of the “Updated” date at the top of this document.
1. Plaid, Inc.
| Attribute | Details |
|---|---|
| Purpose | Bank account linking, transaction history, account balances |
| Data shared | User identifiers (Lefover user ID), bank account access tokens |
| Data received | Account identifiers, balances, transaction history, institution metadata |
| Data location | United States (the region open today). Each further region we open is served from that region. |
| Website | https://plaid.com |
| Privacy policy | https://plaid.com/legal/ |
Plaid is the intermediary between Lefover and your bank. When you link an account, Plaid handles the connection and securely passes your bank data to Lefover.
2. RevenueCat, Inc.
| Attribute | Details |
|---|---|
| Purpose | Subscription management, entitlement verification, cross-platform subscription sync |
| Data shared | User identifiers, subscription tier, platform (iOS/Android) |
| Data received | Subscription status, renewal events, billing status |
| Data location | United States |
| Website | https://www.revenuecat.com |
| Privacy policy | https://www.revenuecat.com/privacy |
RevenueCat manages our subscription infrastructure across Apple and Google platforms. We do not handle payment details directly.
3. Apple Inc.
| Attribute | Details |
|---|---|
| Purpose | App distribution (iOS), in-app purchases, Sign in with Apple, push notification transport (APNs, used by Expo on our behalf) |
| Data shared | Push notification payloads (forwarded by Expo), subscription product IDs |
| Data received | Authentication token (Sign in with Apple), subscription events |
| Data location | Per Apple’s global infrastructure |
| Website | https://www.apple.com |
| Privacy policy | https://www.apple.com/legal/privacy/ |
Apple handles App Store distribution, iOS in-app purchases, and Sign in with Apple authentication. The Apple Push Notification service (APNs) is the underlying transport Expo uses to deliver iOS pushes; Lefover sends pushes to Expo, never directly to APNs.
4. Google LLC
| Attribute | Details |
|---|---|
| Purpose | App distribution (Android), in-app purchases (Google Play Billing), Google Sign-In, push notification transport (FCM, used by Expo on our behalf) |
| Data shared | Push notification payloads (forwarded by Expo), subscription product IDs |
| Data received | Authentication token (Google Sign-In), subscription events |
| Data location | Per Google’s global infrastructure |
| Website | https://www.google.com |
| Privacy policy | https://policies.google.com/privacy |
Google handles Google Play distribution, Android in-app purchases via Google Play Billing, and Google Sign-In. Firebase Cloud Messaging (FCM) is the underlying transport Expo uses to deliver Android pushes; Lefover sends pushes to Expo, never directly to FCM.
5. DigitalOcean, LLC
| Attribute | Details |
|---|---|
| Purpose | Infrastructure hosting: compute, databases, object storage, container orchestration |
| Data shared | All data Lefover stores and processes |
| Data location | United States (NYC3) for the region open today. Each further region we open gets its own isolated infrastructure in that country. |
| Website | https://www.digitalocean.com |
| Privacy policy | https://www.digitalocean.com/legal/privacy-policy |
DigitalOcean provides our Kubernetes clusters, managed PostgreSQL databases, managed Valkey caches, and object storage (Spaces). Regional deployments keep member data in the region it was created in.
6. Postmark (Wildbit, LLC / ActiveCampaign)
| Attribute | Details |
|---|---|
| Purpose | Transactional email delivery (subscription-related notifications, support ticket replies, trial reminders, dunning notices, account communications) |
| Data shared | User email addresses, email subject lines, email body content |
| Data received | Email delivery status (sent, delivered, bounced, opened) |
| Data location | United States |
| Website | https://postmarkapp.com |
| Privacy policy | https://postmarkapp.com/eu-privacy |
Postmark is our transactional email provider. Every email Lefover sends you, including subscription notifications, support replies, and trial reminders, is delivered through Postmark’s infrastructure.
Postmark also delivers the one waitlist email described in §3.7 of our Privacy Policy: a single message telling you Lefover has opened in the place you asked about. That is the only email we send to anyone who is not a Lefover member, and there is no mailing list behind it. We run no marketing email program.
7. Expo (650 Industries, Inc.)
| Attribute | Details |
|---|---|
| Purpose | Push notification delivery (Expo Push Notifications service); mobile build infrastructure (EAS Build, EAS Submit, EAS Update) |
| Data shared | Expo push tokens, push notification payloads (title, body, structured data, never financial details), mobile build artifacts and signing credentials |
| Data received | Push delivery receipts (success or token-invalidation signals) |
| Data location | United States |
| Website | https://expo.dev |
| Privacy policy | https://expo.dev/privacy |
Expo handles push notification fan-out so Lefover doesn’t integrate with Apple Push Notification service or Firebase Cloud Messaging directly. When notification enqueues a push, we hand the message to Expo’s push API; Expo routes it to APNs (iOS) or FCM (Android) on our behalf. Tokens stored on user records are Expo push tokens, and we never see, store, or transmit raw APNs device tokens or FCM registration IDs. Expo also runs our mobile build pipeline (EAS).
Subprocessor summary by category
| Category | Subprocessors |
|---|---|
| Banking data | Plaid |
| Subscription management | RevenueCat, Apple, Google |
| Authentication | Google, Apple |
| Infrastructure | DigitalOcean |
| Push notifications | Expo (Expo Push Notifications service); Apple (APNs transport), Google (FCM transport) |
| Mobile build pipeline | Expo (EAS) |
| Postmark |
What each subprocessor does NOT have access to
For clarity, we want to spell out what each subprocessor does not receive:
- Plaid does not receive aggregated Lefover data, classification results, or derived product metrics
- RevenueCat does not receive your bank data, transactions, or balances, only subscription-related information
- Apple and Google do not receive your bank data or transaction history, only subscription events and the push payloads forwarded by Expo through their respective transports (APNs for Apple, FCM for Google)
- DigitalOcean has physical custody of all data as our infrastructure provider, but does not access, inspect, or use our data beyond providing infrastructure services
- Expo does not receive bank data, transactions, or balances, only Expo push tokens and push payloads (title, body, structured data without financial values), plus mobile build artifacts
How we update this list
Notifications of material changes
When we add a new subprocessor or replace an existing one, we consider this a material change that may affect your data.
For material changes:
- We will update this document and update the “Updated” date at the top
- We will email you at least 30 days before the new subprocessor begins processing your data
- We may also show an in-app banner if the change affects your experience
You will have time to delete your account before any new subprocessor processes your data if you disagree.
Non-material changes
If a subprocessor changes ownership, name, or corporate details without a change in function, we will update this document without a notification.
Data residency across subprocessors
| Region | Status | Primary data location | Subprocessor locations |
|---|---|---|---|
| United States | Open | United States (NYC3) | Plaid (US), RevenueCat (US), DigitalOcean (NYC3), Postmark (US), Expo (US), Apple (global), Google (global) |
| Canada | Planned, waitlist open | Canada, at launch | Confirmed in this document before the region opens |
| United Kingdom | Planned, waitlist open | United Kingdom, at launch | Confirmed in this document before the region opens |
Apple and Google operate globally, and their handling of user data is governed by their own policies and regional infrastructure.
Contact
Questions about our subprocessors? Email [email protected].
Mail: Lefover LLC 4505 Kenny Road #1021 Columbus, OH 43220 United States
End of document.