Last updated: June 13th 2026
Last Mile Strategies engages the following third-party service providers ("sub-processors") to operate the Client Portal. Each vendor receives only the data necessary for their function and is contractually obligated to handle it in accordance with our agreements and applicable law.
We notify customers at least 30 days before adding a new sub-processor that processes customer data. Notifications go out via the in-app announcement banner and to email addresses subscribed to the Sub-processor Notifications list (subscribe via the in-app preference toggle or by emailing privacy@lastmilestrategies.com).
Current sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Customer business info, account data, invoice metadata, encrypted QBO and Ramp token/connection records, and imported QBO and Ramp payable records | United States |
| Cloudflare | Compute (Workers), edge hosting (Pages), object storage (R2), email routing, DNS, CDN | All portal traffic; invoice files in R2; inbound email forwarding; QBO and Ramp OAuth callbacks and scheduled QBO and Ramp sync traffic | United States |
| Anthropic | AI invoice extraction and covered categorization workflows when explicitly invoked | Invoice files (PDF/JPEG/PNG) for OCR and structured extraction. QBO structured imports are not automatically sent to Anthropic and QBO data is not used to train models. | United States |
| Brandfetch | Company logo retrieval | Customer website domain | Switzerland |
| Logo.dev | Fallback logo retrieval | Customer website domain | United States |
| Mapbox | Address autocomplete during onboarding | Address fragments typed by customer | United States |
| SMTP2GO | Outbound transactional email (referral notifications, account invitations, password resets) | Recipient email addresses and email content | United States |
| HaveIBeenPwned | Leaked-password check during password creation/change | Password hash prefix (k-anonymity); no plaintext passwords transmitted | United Kingdom |
| PostHog | Product analytics — event capture and user-behavior insights | Pseudonymous user UUIDs, page and event metadata; no email or name | United States |
Changes to this list
We will update this page when sub-processors are added, removed, or replaced. The "Last updated" date at the top reflects the most recent change.
Contact
Questions about sub-processors or to subscribe to change notifications: privacy@lastmilestrategies.com