The third parties that process personal data on FleetFixer's behalf. This page is the authoritative list and is kept up to date whenever anything changes.
When you give us personal data we are the controller. Some of that data has to touch infrastructure we do not run ourselves (hosting, email, payment billing, wearable APIs, and so on). Those providers are our sub-processors. We list every one here so you can verify the chain of custody for your information and raise objections if you disagree with any of them.
We notify existing customers by email at least 30 days before adding a new sub-processor or replacing one, where that new party would process personal data on your behalf.
| Sub-processor | Purpose | Region |
|---|---|---|
| Google LLC (Firebase and Google Cloud) | Authentication, Firestore database, Cloud Storage for media, Cloud Functions runtime, Cloud Tasks for queued jobs. | EU multi-region (europe-west) for Firestore; europe-west / us-central1 for Cloud Functions. |
| Google Fonts | Web font delivery. | Global CDN. |
| Cloudflare | Font Awesome icon CDN. | Global CDN. |
| Self-hosted Open Wearables | Unified API between wearable vendors and the race app. Runs on our own infrastructure (the provider is set on this page once the environment is live). | Single region per environment, disclosed here before launch. |
| Sub-processor | Purpose | Region |
|---|---|---|
| Google Workspace (Gmail SMTP) | Transactional email delivery (contact replies, consent requests, parent notifications). | Global; transit encrypted via TLS. |
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe, Inc. | Subscription billing, customer portal, invoice delivery. | United States (SCCs in place for EEA and UK transfers). |
When an athlete links a wearable account, the provider below acts as an independent controller in its own relationship with the athlete. For data it passes to us under the athlete's authorisation, it is a source and processor, and we are the controller of the copy on our infrastructure.
| Provider | Linked via | Their privacy policy |
|---|---|---|
| Garmin Ltd. | OAuth through Open Wearables. | garmin.com/privacy |
| Polar Electro Oy | OAuth through Open Wearables. | polar.com/privacy |
| Suunto Oy | OAuth through Open Wearables. | suunto.com/privacy |
Apple Health, Samsung Health and Google Health Connect are not currently supported on the web and therefore do not appear in the list.
If you object to any sub-processor listed above, write to hello@fleetfixer.io. We will explain the role the sub-processor plays, discuss alternatives where they exist, and make a reasonable accommodation where we can. If we cannot, you have the option to stop using the affected part of the Service and request erasure of the data concerned.