To deliver Construct-it we use a small number of reputable third-party providers (“sub-processors”). Each one processes only the data needed for its function. Your project data is stored in Sydney, Australia (Supabase); some processing and data in transit occurs via the overseas providers below (primarily the United States) under contractual safeguards — a cross-border disclosure under Australian Privacy Principle 8.
This page complements our Privacy Policy. We'll update it when our sub-processors change.
| Provider | Purpose | Data handled | Location |
|---|---|---|---|
| Supabase | Database & authentication hosting | Your account and project data | Sydney, Australia |
| Vercel | Application hosting & compute | Request data in transit | United States |
| Anthropic (Claude) | AI parsing of PDFs you upload (materials, variations, schedules of values, payment summaries) | The document contents you submit for parsing — not used to train AI models | United States |
| Google (Places API) | Address autocomplete | Partial address text you type | United States |
| Resend | Transactional email (receipts, reminders, password resets) | Recipient email address + message content | United States |
| Stripe | Subscription payments | Billing details — we never see your card numbers | United States / global |
| Xero | Accounting sync — only when you connect it | Invoice / contact data, via OAuth, plus the invoice writes you confirm | Per Xero's hosting |
| Sentry | Error monitoring, to detect and fix faults | Diagnostic / error data | United States |
We do not sell your data, and we do not use it to train AI models. Payment card data is handled entirely by Stripe — it never touches our servers.
Questions about our sub-processors? Email info@construct-it.au.