Sub-processors
Effective 26 July 2026
KARG uses the following third parties to deliver the platform. We notify customer administrators by email at least 30 days before adding or replacing a sub-processor that processes personal data.
Core infrastructure
Used for every workspace.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase Privacy | Primary PostgreSQL database, authentication, file storage | All workspace data, account credentials, uploaded documents | EU (Frankfurt) |
| Vercel Privacy | Frontend and API hosting, edge network, image optimisation | HTTP requests, IPs, request logs | EU — set in the Vercel project settings; not pinned in this repository (`vercel.json` declares no `regions`) |
| Upstash Privacy | Redis cache and QStash scheduled jobs (matching cycle) | Cached responses, idempotency keys, queued job payloads | EU (Frankfurt / Ireland) |
| Sentry Privacy | Application error and performance monitoring | Error stack traces, request metadata (scrubbed of secrets) | EU |
| Brevo Privacy | Transactional email: the invitation that creates every new user account, and the authentication emails Supabase sends on our behalf (invitation and password reset) — Brevo is the SMTP provider behind them | Recipient email address, the name typed by the administrator who invites them, and a single-use invitation or password-reset link. No marketing email is sent through KARG. | EU (France) |
| OpenRouteService Privacy | Routing, distance and toll estimation, and place-name lookup for fleet positions | Pickup/delivery addresses and place names; vehicle positions rounded to ~1 km (no plate, vehicle or tenant identifier) | EU (Germany, HeiGIT / Heidelberg University) |
Messaging
Used to send and receive driver and dispatcher messages, and to run KARG's own operations channel.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Telegram (Bot API) Privacy | Driver and dispatcher notifications; and KARG's internal operations channel: admin events, error alerts, automatic delivery of loading-list PDFs | To the driver's or dispatcher's own chat, addressed by the Telegram chat ID we store for them: the truck's registration plate, the country it is currently in and the countries the trip expected, the load or route reference and dates, origin and destination cities, the dispatcher's name, fuel level and the litres judged missing, how long the truck has been stopped, fuel-card transactions listed one by one (date, product, litres, amount in EUR, country) under the heading “card used outside a load”, document-expiry warnings (document type, country, expiry date), matching alerts that pair a plate with the driver's name and current city, return-load offers including a third party's contact phone number, and any free-text message a dispatcher sends. The channel is two-way: what a driver types back also passes through Telegram. On KARG's operations channel — read by our team, not by you — additionally: user email addresses, workspace name and VAT number, support-ticket subjects and message previews, the reason given for an impersonation session, ERROR/CRITICAL log lines (which can quote whatever data caused the error), and complete loading-list PDFs (consignments, customers, weights). | Outside the EEA — country not established. Telegram's Bot API is a single public endpoint with no region to choose, and we will not name a jurisdiction we cannot evidence. No Chapter V transfer safeguard (Standard Contractual Clauses or equivalent) is recorded for this transfer. This is an open point we are working on, stated rather than omitted. |
| Twilio Privacy | WhatsApp / SMS channel for driver messages — built, but not switched on: production runs on Telegram | None today. Kept in this register in advance of any such switch, at which point it would receive driver phone numbers and message contents. | United States (EU SCC in place) |
AI document extraction
Used to parse PDF road documents into structured data.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Google Gemini API Privacy | Structured extraction from PDF road documents (CMR, T1, invoices) | Document text only — page images never leave KARG, the OCR runs locally. Sent with the text: your workspace's earlier manual corrections on the same document type (the wrong value and the value you replaced it with), used as examples. | Google Cloud, EU SCC in place |
External integrations (only when you connect an account)
These providers receive data only because you, as a carrier, have an existing relationship with them and have authorised KARG to act on your behalf.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| FomCo Privacy | Telematics and freight-exchange access (only if connected) | Vehicle IDs, GPS positions, load search criteria | Romania |
| TimoCom Privacy | European freight and tender exchange (only if connected) | OAuth tokens, load search and offer payloads | Germany / EU |
| NextUp Telematics | Fleet tracking (only if selected as your telematics provider — the choice is offered in Settings → Integrations) | The API key and tenant token of your NextUp account, plus vehicle identifiers and fleet/history queries. NextUp returns positions, plate, driver name and odometer. | Operated by NextUp — the region follows your NextUp account |
Customs authorities
Public bodies, not commercial sub-processors: they act as independent controllers and we transmit to them because the law requires it, not on our own account. Listed here so you can see exactly what leaves the platform. Data flows only for workspaces with the corresponding border feature enabled.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| HMRC (UK Government) Privacy | UK customs declarations and notifications (where the carrier opts in) | Declaration data: EORI numbers; the names and full addresses of the consignee, the carrier, the notify party, the representative and the person lodging the declaration; itinerary, goods items, gross mass, seals and containers; vehicle and trailer registration numbers; OAuth tokens. No driver identity — the declaration schemas have no driver field. | United Kingdom |
| DGDDI — French Customs (douane.gouv.fr) Privacy | Enveloppe Logistique Obligatoire (ELO) for Channel crossings — live, for workspaces with the French border feature enabled | The customs declaration references travelling in the truck (MRN / Delta G numbers), the crossing direction (import/export), whether the truck is empty or loaded, and the regime flags (TIR/ATA, postal, empty packaging, SPS, fishery products, transport contract); plus the username and password of your own DGDDI customs account, used to obtain an access token. DGDDI returns the envelope file number, its status and the ELO PDF. | France |
User-initiated links
No automatic transfer happens here: data reaches these providers only when someone in your workspace clicks a link, and only what that link contains. Declared because the posture is different, not because the disclosure is optional.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Google Maps Privacy | Opening a stop address or a truck position on a map — a link somebody clicks, never an automatic transfer | Only what is in the link that is opened: the pickup or delivery address of a load (which can be a customer's address), or the truck's exact, un-rounded GPS coordinates. Nothing is sent unless the link is clicked. | Google (United States / global) |
| WhatsApp (Meta) Privacy | “Send to driver” on a route opens WhatsApp with the message pre-filled — a direct link to Meta, not the Twilio channel above, and the one actually in use today | The whole itinerary, in the link's query string: route name, origin, via points, destination, map link and the driver instructions. KARG puts no phone number in the link — the dispatcher picks the recipient inside WhatsApp. | Meta Platforms Ireland / United States |
Notifications & objection
To subscribe to sub-processor change notifications or to object to a new sub-processor, write to privacy@karg.to. If we cannot accommodate a reasonable objection we will give you the option to terminate the affected service for a pro-rata refund of pre-paid fees.