Archived Subprocessor list
QueueRove Subprocessor List
The repository identifies the approved provider boundaries below. It cannot prove that a provider is contracted, configured, or receiving production data.
- Version 2026-07-17-draft.1
- Effective date: Pending Texas counsel approval
- SHA-256
8023a53bd90eca0f8c796a9aedb2833b55d137ce9d2b6057eca1bf94af432899
Archived draft status
Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.
This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.
The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.
View the current stable route → · View all archived documents
1. How to read this list
No production activation claim
Every listed provider is an approved technical candidate or boundary in the v1 plan. Production contracts, regions, security terms, transfer mechanisms, configuration, and smoke evidence remain external gates. Until those records exist, this page does not label any candidate an active production subprocessor.
2. Approved v1 provider candidates
| Provider | Proposed service/data | Evidence status |
|---|---|---|
| Auth0 (Okta) | Authentication, MFA, external identity, and account security identifiers | SDK boundary implemented; production tenant/configuration/contracting not evidenced |
| Stripe | Hosted Checkout/billing management and billing object/event references; no complete card data stored by QueueRove | Adapter and test-safe code may exist; production collection/charging disabled and provider evidence pending |
| Resend | Transactional account, invitation, security, billing, privacy, and support-routing email | Adapter/outbox work may exist; verified production sender/domain and delivery evidence pending |
| Hosting, PostgreSQL, backup, and monitoring providers | Application, account/organization administration, logs, database, encrypted backups, and operational telemetry | No provider identity, production region, or contract approved for publication from repository evidence |
3. Scope limit
The proposed DPA scope is QueueRove-controlled account, technician identity, organization, membership, assignment, billing-administration, legal-acceptance, security/audit, support, privacy, and sales data. This list does not claim that these providers receive customer HaloPSA tickets or customer records through the website control plane.
4. Changes and questions
A production list must be updated from executed provider and deployment evidence, assigned a new immutable version/hash when material, and follow the notice and objection terms in the executed DPA. Questions may be sent to support@itecsonline.com with the subject QueueRove privacy request.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.