MatterPath privacy
Service Provider and Overseas Processing Schedule
Effective date: 25 August 2026.
This schedule accompanies the Privacy Notice. It lists only providers verified in MatterPath production code, deployment configuration or operating documentation.
1. Schedule status and approach
A provider appears here only where current production code, configuration or operating documentation verifies that MatterPath uses it. The country status concerns the actual MatterPath configuration, not merely the country where a provider is headquartered.
Potential overseas processing includes storage, transient processing, remote support or subprocessor access. MatterPath will update this schedule when configured regions and contractual subprocessor information are verified.
2. Supabase
- Services
- Hosted authentication, PostgreSQL database and Data API
- Purpose
- Account authentication, application records, assessment answers, matching records, consent and audit records, professional profiles and payment references.
- Information involved
- Account identifiers and contact details, authentication data, assessment and matter information, professional information, consent and disclosure records, transaction status and security/audit data.
- Overseas status
- Potential overseas storage, processing or support access
- Countries
- Not verified in repository production evidence. Overseas storage, processing or support access may occur. Contract and configured-region review is required before unrestricted launch.
- Verified production evidence
- Production deployment documentation and server-side Supabase clients in the application.
- Provider privacy information
- View Supabase privacy information
3. Vercel
- Services
- Web hosting, serverless application runtime, deployment platform and AI Gateway
- Purpose
- Deliver the public and authenticated application, process server requests, run scheduled application tasks and route fixed MatterPath-authored translation text to the configured model provider.
- Information involved
- Web request and network metadata, session-routing data, application request content processed by the runtime, operational diagnostics, and fixed MatterPath-authored question, option, heading and label text used for translation.
- Overseas status
- Potential overseas storage, processing or support access
- Countries
- Not verified in repository production evidence. Overseas storage, processing or support access may occur. Contract and configured-region review is required before unrestricted launch.
- Verified production evidence
- Vercel deployment configuration, Vercel OIDC and the Vercel AI Gateway endpoint in production code.
- Provider privacy information
- View Vercel privacy information
4. OpenAI
- Services
- Translation model accessed through Vercel AI Gateway
- Purpose
- Translate fixed MatterPath-authored assessment questions, options, headings and labels into supported languages.
- Information involved
- Fixed MatterPath-authored interface text only. Production code excludes consumer answers, free-text descriptions, stable answer identifiers and identifying matter details from translation requests.
- Overseas status
- Potential overseas processing or support access
- Countries
- Not verified in repository production evidence. Overseas storage, processing or support access may occur. Contract and configured-region review is required before unrestricted launch.
- Verified production evidence
- The production translation adapter defaults to an OpenAI model through Vercel AI Gateway.
- Provider privacy information
- View OpenAI privacy information
5. Stripe
- Services
- Professional membership, subscription and accepted-introduction payment processing
- Purpose
- Create Stripe customers, collect professional billing details and payment methods, process memberships and separately accepted introduction fees, issue invoices and report payment status.
- Information involved
- Professional organisation and payer details, billing address, tax identifier where supplied, payment method and card data held by Stripe, customer/subscription/payment identifiers, amount, currency, invoice and payment status. MatterPath receives limited card details such as brand and last four digits where Stripe supplies them.
- Overseas status
- Potential overseas storage, processing or support access
- Countries
- Not verified in repository production evidence. Overseas storage, processing or support access may occur. Contract and configured-region review is required before unrestricted launch.
- Verified production evidence
- Stripe payment adapter, Stripe.js recovery flow, signed webhook route and production deployment configuration.
- Provider privacy information
- View Stripe privacy information
6. Resend
- Services
- Application-generated transactional email
- Purpose
- Send account and service notifications requested or required by MatterPath workflows.
- Information involved
- Recipient email address, message subject and fixed template content, environment label outside production, delivery status and provider message identifier. Application-generated messages are designed not to include legal or matter details.
- Overseas status
- Potential overseas storage, processing or support access
- Countries
- Not verified in repository production evidence. Overseas storage, processing or support access may occur. Contract and configured-region review is required before unrestricted launch.
- Verified production evidence
- Production email adapter and deployment configuration select Resend.
- Provider privacy information
- View Resend privacy information
7. Services not configured or not established
- No SMS provider is configured in production code or deployment documentation.
- Analytics and error monitoring are disabled and no production provider adapter is connected.
- SiteGround is identified in deployment documentation as the DNS host. The repository does not establish that it processes MatterPath application records; any inbound mailbox role must be verified separately before it is added to this schedule.
- GitHub is used for source control and is not listed as a live customer-data processor in this schedule.
8. Schedule updates
MatterPath will review this schedule when a provider, material service, configured region or subprocessor changes. Each published version remains listed in the legal-document archive.
Questions about this schedule may be sent to info@matterpath.com.au.