Sub-processors.
Last updated: 30 August 2026
PitlaneHQ engages the third-party service providers ("sub-processors") listed below to deliver the Service. It is referenced by our Privacy Policy and the Customer Data Processing Addendum.
We maintain this page on a best-efforts basis and update it when we become aware of a change. We are deliberately not calling it authoritative or guaranteed complete: a page that claims that is wrong the first day a provider changes, and an accurate description of how it is kept is worth more than a stronger claim we cannot stand behind. If a provider looks missing or out of date, tell us at privacy@pitlanehq.com.au and we will correct it.
Sub-processors are categorised by the function they perform. Some are engaged for every workshop (infrastructure, payments, communications, observability); others are opt-in and are only engaged when a workshop activates the corresponding integration.
Infrastructure and storage
Engaged for every workshop. These providers host or back up the Service.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Microsoft Azure | Application hosting, primary database, secrets management | Australia (East — Sydney) | All workshop and customer data |
| Cloudflare Inc. | CDN, DDoS protection, Web Application Firewall | Global edge network | Request metadata, IP addresses |
| Amazon Web Services | Encrypted backup storage (S3) | Australia (ap-southeast-2 — Sydney) | Encrypted backup bundles |
| Backblaze Inc. | Secondary encrypted backup storage (B2) | United States | Encrypted backup bundles |
Payments and communications
Stripe and Twilio are engaged for every workshop. Global Payments and RingCentral are engaged only where a workshop turns the relevant feature on — taking card payments, or Pitlane Phones. Note that Stripe processes PitlaneHQ's subscription billing — it is not the payment processor your workshop uses to collect payments from your own customers.Pitlane Pay, which will run on Global Payments, is not yet available. Its row is listed below prospectively, so the register is complete for when it is switched on. The Twilio SendGrid row is listed on the same basis: forwarding supplier bills to a PitlaneHQ address for automatic reading is a feature we intend to run on SendGrid Inbound Parse, and it is not built yet. Nothing is being sent to SendGrid today. We are listing it now so the notice arrives before the engagement rather than after it.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Stripe Payments Australia Pty Ltd | Subscription billing for the PitlaneHQ platform itself | Australia + United States | Workshop billing contact, payment method, transaction history |
| Twilio Inc. | SMS delivery (booking reminders, quote approvals, customer communications) | United States | Phone numbers, message content |
| Resend (Anti-Spam Inc.) | Transactional email delivery | United States | Email addresses, message content |
| Twilio SendGrid (Inbound Parse) | Planned inbound email processing for supplier bills — receiving bills a workshop forwards to a PitlaneHQ address and handing them to the Service to be read and matched. Listed in advance of engagement: it is not in use yet, and no email is routed through it today. | United States | The forwarded email and anything attached to it: sender and recipient addresses, subject, message body, and the supplier bill document itself. |
| Global Payments (Pitlane Pay) | Planned card payment processing, once Pitlane Pay is enabled, where a workshop takes payment from its own customers, including in-person terminal and counter sales | Australia + New Zealand | Cardholder name, truncated card details, transaction amounts and references, settlement records. Full card numbers are handled by Global Payments and never reach PitlaneHQ systems. |
| RingCentral, Inc. | Business telephony where a workshop enables Pitlane Phones — call handling, voicemail, call recording, and speech-to-text transcription | United States | Caller and recipient phone numbers, call metadata, call recordings and their transcripts, voicemail audio and transcripts |
Observability and developer tooling
Engaged for every workshop. Used to detect and resolve service issues.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Application error tracking and performance monitoring | Germany (EU region) | Stack traces, request identifiers, user identifiers, browser metadata |
AI processing
Engaged only when a workshop activates Ask the Boss or an AI assistance feature. Data submitted for AI processing is drawn from the requesting workshop — together with the pooled repair records described in section 4 of the Privacy Policy, from which customer details are removed, where an AI estimation feature is used — and is not used to train models served to others. Licensed third-party technical data is excluded from any model training.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Amazon Web Services (Bedrock) | AI inference for Ask the Boss and AI assistance features - such as draft SMS and review replies, quote/invoice wording, technician-note cleanup, job estimation, recorded-call summarisation and vehicle image analysis - and text embedding — converting submitted text into numeric vectors so related jobs and past replies can be retrieved by meaning. Outputs are drafts for human review by default; a workshop can separately switch on automatic sending of SMS replies, which is off unless enabled and gated per message. No solely-automated decisions with legal effect. | Australia | Whatever workshop-scoped content the AI feature in use is given. That includes job, quote and message text; recorded-call transcripts; customer and staff contact details; and vehicle photographs, including bay camera captures read for number plates and exterior damage. Numeric vectors derived from submitted text are retained to support retrieval by meaning. Estimation prompts may also include pooled repair records — customer details removed — contributed by other workshops. |
Opt-in integrations
Engaged only when a workshop explicitly activates the corresponding integration in Settings. Data flows to these providers stop when the workshop disconnects the integration.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Xero Limited | Accounting integration — synchronises invoices and contacts | Australia / New Zealand | Customer contact details, invoice line items, payment records |
| Intuit Inc. (QuickBooks Online) | Accounting integration — synchronises invoices and contacts | United States | Customer contact details, invoice line items, payment records |
| Vehicle Visuals | Vehicle illustration / animation lookup for customer-facing quotes and inspections | United States | Vehicle make, model, and year (no personal identifiers) |
| MYOB Australia Pty Ltd | Accounting integration — synchronises invoices, contacts, and payments | Australia | Customer contact details, invoice line items, payment records |
| InfoAgent (NEVDIS / NHVR vehicle data) | Vehicle registration and VIN lookup against national vehicle registers, so a plate can populate a vehicle record | Australia | Registration plate or VIN submitted for lookup, and the vehicle record returned. Vehicle records can identify an owner indirectly. |
| Mapbox, Inc. | Address autocomplete and validation when entering a customer or site address | United States | Partial address text entered into an address field |
| Bapcor / Burson Auto Parts | Parts catalogue search and stock ordering where a workshop connects its Burson trade account | Australia | Vehicle details, parts requested, workshop trade-account identifiers, order records |
Advertising and marketing attribution
Correcting an earlier version of this page: it listed only the analytics used on our own marketing website, and our Privacy Policy said the product itself “carries no advertising or third-party tracking”. That was wrong, and it had been wrong since the marketing-attribution feature shipped. The platforms below have been able to receive end-customer data from inside the product, for workshops that connected them, without appearing on this register. They are listed now.
What this section covers. It is about a workshop's customers. Those records reach an advertising platform only where that workshop connects its own advertising accounts in the Marketing module and switches a platform on; nothing is sent for a workshop that has connected nothing. It is not a statement about PitlaneHQ's own advertising. When someone enquires through a form on pitlanehq.com.au, or starts a trial or begins paying for PitlaneHQ anywhere in our own signup and billing flow, we send that to our advertising accounts and our own Google Analytics 4 property, none of which a workshop controls — that flow is set out under our own website and advertising below. Without this carve-out the sentence read as an absolute, and it was not one.
No advertising or analytics tag is loaded inside the product itself — these are server-to-server sends. What is sent is a conversion event as an end customer moves through the funnel (an enquiry is created, a quote is sent, a quote is accepted, an invoice is paid), carrying the identifiers the platform needs to match that customer to an ad click. Where a workshop has separately accepted the platform's customer-data terms, hashed contact lists are also uploaded to Google Customer Match, Meta Custom Audiences and Microsoft Customer Match — connecting the account alone does not turn that on. Google and Meta receive a hashed email and a hashed phone number, each only where we hold it for that customer; Microsoft receives a hashed email and never a phone number, because its list format has no phone field. Two lists are built: customers with an invoice paid in the last 540 days, and customers sent a quote in the last 90 days that has not converted.
Email addresses and phone numbers are SHA-256 hashed before they leave our servers, and so are names, for every platform that receives them but one. What is not hashed differs per platform — it is named in each row rather than folded into a general claim about hashing, because the exceptions are the part that matters. Google Analytics 4 receives no name, email address or phone number. A customer who has opted out of marketing is excluded from conversion sends. The audience uploads exclude them too, and additionally exclude anyone who has asked to be erased. Getting out of a list already uploaded works differently by platform, and the difference is worth stating rather than averaging: for Google and Meta an erasure request sends an active removal instruction for the identifiers we had already uploaded; for Microsoft it does not, because the daily upload replaces the whole list, so that person drops out when the next daily replace runs rather than at the moment they asked — and if that sync stops first, because the workshop disconnects Microsoft or withdraws the terms, they stay in the list Microsoft already holds. Consent mode is on by default for workshops outside Australia, New Zealand and the United States, or whose country we do not hold, and any workshop can turn it on. Where it is on, a conversion event is suppressed unless the customer granted the matching consent — advertising consent for the advertising platforms, analytics consent for Google Analytics 4. It works differently for the audience uploads: consent mode does not stop them, it changes what we tell Google, which is that consent is unspecified rather than granted.
For end-customer records the workshop is the responsible entity (section 1, second role); connecting an advertising account is the workshop's decision and its customers' data is disclosed on its instruction. Each platform then receives that data under the advertising terms between the workshop and that platform, and decides where it stores it. The locations below are where the receiving company is established, so far as we can state it — not a commitment by us about where the data comes to rest. We do not name a country for TikTok: which group entity contracts with the workshop depends on the advertising terms it accepted, and a country we cannot verify is worse than none.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Google LLC (Google Ads) | Conversion measurement for a workshop’s own Google Ads account — reporting back which enquiries, quotes and paid invoices came from an ad — and, where the workshop has separately accepted Google’s customer-data terms, building Customer Match audiences | United States | SHA-256 hashed email, phone number and name. Country and postcode are sent in PLAIN TEXT, because Google’s address match will not accept them hashed. Sent UNHASHED: the Google click identifier (gclid, gbraid or wbraid) carried in from the ad click. Also the conversion value, currency, an invoice or lead reference used for de-duplication, the campaign, landing-page, submission-page and referrer details recorded with the enquiry, and the consent signals where consent mode applies. Customer Match uploads carry hashed email and phone only. |
| Meta Platforms, Inc. (Conversions API) | Conversion measurement for a workshop’s own Facebook and Instagram advertising, and, where the workshop has separately accepted Meta’s customer-data terms, building Custom Audiences | United States | SHA-256 hashed email, phone number, first and last name, city, state, postcode, country, and a hashed internal customer identifier. Sent UNHASHED, because Meta will not match them otherwise: the Meta click and browser cookie values (_fbc and _fbp) picked up from the page the customer came through, the customer’s IP address, and their browser user-agent string. Also the conversion value, currency, event time, and the page URL and referrer. Custom Audience uploads carry hashed email and phone only. |
| Microsoft Corporation (Microsoft Advertising) | Offline conversion measurement for a workshop’s own Microsoft Advertising (Bing) account, and, where the workshop has separately accepted Microsoft’s customer-data terms, building Customer Match audiences | United States | SHA-256 hashed email and phone number. Sent UNHASHED: the Microsoft click identifier (msclkid) carried in from the ad click. Also the conversion value, currency and event time. Customer Match uploads carry a hashed email ONLY — Microsoft’s bulk list format has no field for a phone number, so none is sent. Those uploads run daily and REPLACE the whole list each time, which is also the only way someone leaves it: we do not issue Microsoft a removal instruction the way we do for Google and Meta. So a person drops out when the next daily replace runs — and only then. If the sync stops before that, because the workshop disconnects Microsoft or withdraws the customer-data terms, no further replace happens and they stay in the list Microsoft already holds. |
| Google LLC (Google Analytics 4 — the workshop’s own property) | Sending funnel events to a workshop’s own GA4 property so its analytics reflect the enquiries, quotes and paid invoices recorded in PitlaneHQ. Separate from the GA4 property we run on our own marketing website, listed further down | United States | The pseudonymous GA4 client identifier recorded when the customer visited, the event name, value, currency, a transaction reference, the page URL and referrer, and the campaign parameters (source, medium, campaign, term, content). No name, email address or phone number is sent to GA4. |
| TikTok (TikTok Pte. Ltd. and affiliates) | Conversion measurement for a workshop’s own TikTok advertising, via the TikTok Events API | Outside Australia (TikTok group entities) | SHA-256 hashed email, phone number and a hashed internal customer identifier. Sent UNHASHED: the TikTok click identifier (ttclid) and the _ttp cookie value picked up from the page the customer came through, the customer’s IP address, and their browser user-agent string. Also the conversion value, currency and event time. |
| LinkedIn Corporation | Conversion measurement for a workshop’s own LinkedIn advertising, via the LinkedIn Conversions API | United States | SHA-256 hashed email, and the LinkedIn first-party ad tracking identifier (li_fat_id) sent unhashed. Where we hold neither, first and last name are sent in PLAIN TEXT, so the event still carries an identifier. Also the conversion value, currency and event time. |
Our own website and our own advertising
These providers receive data about visitors to and enquirers on pitlanehq.com.au, and about people who start a trial or subscribe with us. They do not receive workshop records or a workshop's customers' personal information from inside the product, and they are not engaged to deliver the Service. They are listed here because they still receive personal information about people who come to us.
Two different mechanisms are in this table. Some of it is tags running in your browser: the Google Analytics 4 tag and the Meta Pixel. The rest is sends that run on our servers: when you submit an enquiry or demo request on this website, start a trial, or become a paying subscriber, we report that to PitlaneHQ's own advertising accounts, and to our own Google Analytics 4 property, so we can tell which of our ads worked. To the three advertising accounts your email address goes too, SHA-256 hashed before it leaves our servers, and your phone number as well where you gave us one on an enquiry form — the trial and subscription events carry the email alone. Google Analytics 4 gets none of that: its send carries the event, its value and a reference only, with no email address, phone number or name.Google Analytics 4 is in both halves: it has a browser tag AND receives these same server-side events, so it is the one row where the split runs through the row rather than between rows.
We are separating them out because the difference decides what you can do about it. Blocking cookies or trackers in your browser can stop the two browser tags; it does not touch the server-side sends, which do not run in your browser at all — including the server-side half of the Google Analytics 4 row. There is no self-service switch for the server-side rows; the route is to ask us at privacy@pitlanehq.com.au. We handle that by hand rather than through a switch in the system, and we will stop sending further events about you. An event already sent cannot be recalled, which is the honest limit of that. An earlier version of this page listed only the browser tags, which understated what our own advertising receives; how to control the browser side is explained in our Cookie & Tracking Notice.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Google LLC (Google Analytics 4) | Aggregate traffic measurement on the pitlanehq.com.au marketing website, and — from our servers rather than your browser — recording an enquiry, trial start or subscription against that same property | United States | Pseudonymous visitor identifier, pages viewed, referrer, approximate location, device and browser. The server-side events carry the event name, value, currency and a reference, with a synthetic identifier standing in for the browser one — no email address, phone number or name is sent to GA4. |
| Meta Platforms, Inc. (Meta Pixel) | Measuring the effectiveness of our own advertising on Facebook and Instagram, and building advertising audiences | United States | Pseudonymous visitor and event identifiers, pages viewed, and whether a form was submitted. Meta may match this to an existing Meta account. |
| Google LLC (Google Ads — PitlaneHQ’s own account) | Measuring our own Google advertising: reporting back from our servers when someone enquires through a form on pitlanehq.com.au, starts a trial, or becomes a paying subscriber. This is our advertising, not a workshop’s, and no workshop controls it | United States | A SHA-256 hashed email address, plus the conversion value, currency, event time and a reference used for de-duplication. A hashed phone number is sent ONLY for an enquiry made through a form on our website, because that is the only one of the three events where we hold a phone number — the trial-signup and subscription events carry the email alone. No name, address or message text is sent. |
| Meta Platforms, Inc. (Conversions API — PitlaneHQ’s own account) | The same three events sent to our own Meta advertising account from our servers. SEPARATE from the Meta Pixel row above: the Pixel runs in your browser, where a tracking blocker can stop it; this does not run in your browser, so a tracking blocker cannot reach it at all | United States | A SHA-256 hashed email address, plus the conversion value, currency, event time and a de-duplication reference. A hashed phone number is sent only for a website enquiry, as above. No name, address or message text is sent. Meta may match the hashed values to an existing Meta account. |
| Microsoft Corporation (Microsoft Advertising — PitlaneHQ’s own account) | The same three events sent to our own Microsoft Advertising account from our servers, as offline conversions. We load no Microsoft advertising tag on our website, so this recipient exists because of the server-side send rather than anything running in your browser | United States | A SHA-256 hashed email address, plus the conversion value, currency and event time. A hashed phone number is sent only for a website enquiry, as above. No name, address or message text is sent, and no de-duplication reference: the Microsoft offline-events call has no field for one. |
Cross-border disclosure (APP 8)
Primary hosting, the production database, and encrypted backups (Microsoft Azure and Amazon Web Services — S3) are located in Australia (Sydney). AI inference (AWS Bedrock), including text embedding, is also carried out in Australia. The following sub-processors process some or all data outside Australia under contractual safeguards equivalent to Australian Privacy Principle 8. Specifically:
- Sentry (Germany) — GDPR-equivalent jurisdiction, Standard Contractual Clauses in place.
- Stripe, Twilio, Resend, Backblaze, Cloudflare, Intuit, Vehicle Visuals (United States) — contractual safeguards under the relevant Data Processing Addendums; reliance on APP 8.2(b) (recipient bound by substantially similar law) and APP 8.2(c) (your consent, where applicable).
- Twilio SendGrid (United States) — same basis as Twilio, once the supplier-bill inbound feature is engaged. Not in use today.
- Google, Meta, Microsoft and LinkedIn (United States), and TikTok (outside Australia) — for a workshop's customers, only where that workshop has connected its own advertising accounts or its own Google Analytics 4 property, and the disclosure is then made on that workshop's instruction. A workshop switching this on should tell its own customers what it means for them. The send itself is performed by our servers and we choose the fields; what the workshop controls is whether the connection exists at all. Disconnecting the platform stops further sends; it does not by itself remove anyone from an audience already uploaded. An erasure request sends an active removal to Google and Meta; for Microsoft the person drops out when the next daily upload replaces the list, and stays in the list Microsoft already holds if that sync stops before then.
- Google (both Google Ads and Google Analytics 4), Meta and Microsoft (United States), for our own advertising — a separate disclosure on the same basis, made on PitlaneHQ's own instruction rather than a workshop's, and covering people who enquire through our website, and people who start a trial or begin paying for PitlaneHQ through our own signup and billing flow. No workshop is involved and no workshop can switch it off. See our own website and advertising above.
Notification of changes
We will provide workshops with at least 30 days' notice before engaging a new sub-processor that will process workshop or customer personal information. Notice will be provided by:
- An in-product banner visible to workshop administrators
- An update to this page (this date in "Last updated" will change)
- For material changes, an email to the workshop's registered billing contact
If your workshop objects to a new sub-processor for a good-faith reason, contact us at privacy@pitlanehq.com.au within the 30-day notice window and we will work in good faith to either resolve the concern or, if unable to do so, permit you to terminate the affected Service component.
Contact
Questions about sub-processors or our supply chain:
- Email: privacy@pitlanehq.com.au
- General enquiries: hello@pitlanehq.com.au