Patravo Subprocessor List
- Effective Date
- June 28, 2026
- Last Updated
- June 28, 2026
Contents
Patravo is operated by Venlorin LLC.
1. Plain-English Summary
Patravo uses trusted service providers to help operate the platform.
These providers help Patravo with hosting, compute, database services, authentication, file and media storage, email delivery, security, and related infrastructure.
Patravo is built for youth-serving organizations, so vendor transparency matters. troops, packs, crews, ships, posts, councils, chartered organizations, parents, guardians, adult volunteers, and other youth-serving groups should be able to understand who helps Patravo provide the service.
Patravo’s commitments are simple:
- Patravo uses subprocessors to provide, operate, support, secure, and improve Patravo.
- Patravo does not use subprocessors for advertising networks.
- Patravo does not use marketing pixels.
- Patravo does not use cross-site behavioral tracking.
- Patravo does not allow subprocessors to use Patravo data for their own advertising, marketing, data brokerage, or unrelated purposes.
- Patravo does not sell, rent, license, broker, or trade personal information.
- Patravo does not use AI features, AI providers, or customer content to train AI models.
- Patravo publishes this list so organizations and families know which service providers help operate Patravo.
This page identifies Patravo’s current subprocessors and explains what each one does.
2. What Is a Subprocessor?
A subprocessor is a third-party service provider that processes personal information, organization data, or customer content on Patravo’s behalf so Patravo can provide the service.
Subprocessors may help Patravo with things like:
- Hosting
- Compute
- Database services
- Authentication
- File and media storage
- Email delivery
- Security
- Reliability
- Support
- Infrastructure operations
A subprocessor may process information only as needed to provide services to Patravo.
3. What Is Not a Subprocessor?
Not every person, organization, or third-party service connected to Patravo is a Patravo subprocessor.
The following are generally not Patravo subprocessors:
- Youth members
- Parents and guardians
- Adult leaders
- Volunteers
- Organization administrators
- troops, packs, crews, ships, posts, patrols, dens, or committees using Patravo
- Chartered organizations using, supervising, or supporting a Patravo workspace
- Councils, districts, or national organizations using or overseeing their own Patravo access
- Scouting America or other national youth-serving organizations, unless they separately provide processing services to Patravo
- Public website visitors
- Emergency services
- Law enforcement
- Child protection agencies
- Regulators
- Courts
- App stores acting under their own terms
- Third-party websites linked from Patravo
- Customer-selected tools or accounts that an organization independently controls
These parties may receive or process information in some situations, but that does not automatically make them Patravo subprocessors.
4. How Patravo Uses Subprocessors
Patravo uses subprocessors to provide the service.
Subprocessors may process data such as:
- Account information
- Authentication information
- Contact information
- Youth member information
- Parent and guardian information
- Organization information
- Roster information
- Role and permission information
- Event and attendance information
- Message and communication content
- Photos, videos, and files
- Public website content
- Email delivery data
- Real-time communication data
- Device, log, and security information
- Technical diagnostics
The data processed by each subprocessor depends on the service that provider performs.
For example, an authentication provider may process login information, while a media storage provider may process uploaded photos, videos, and file attachments.
5. Patravo’s Vendor Commitments
Patravo makes the following commitments about subprocessors:
- Patravo uses subprocessors only to provide, operate, support, secure, or improve Patravo.
- Patravo does not use subprocessors for advertising networks.
- Patravo does not use subprocessors for marketing pixels.
- Patravo does not use subprocessors for cross-site behavioral tracking.
- Patravo does not allow subprocessors to use Patravo data for their own advertising, marketing, data brokerage, or unrelated purposes.
- Patravo reviews vendors based on the role they perform, the data they process, available security documentation, privacy documentation, and service need.
- Patravo publishes and updates this Subprocessor List.
- Patravo updates the Subprocessor Changelog when subprocessors are added, removed, or materially changed.
- Patravo does not use AI features, AI providers, or customer content to train AI models.
- Patravo treats vendors that process youth-related information with extra care.
6. Current Subprocessors
The table below lists Patravo’s current subprocessors.
| Provider | Service Provided | Data Categories Processed | Purpose | Status / Notes |
|---|---|---|---|---|
| Vercel | Hosting, deployment, and compute | Web/app traffic, request metadata, technical logs, application responses | Hosts and runs parts of the Patravo website, web app, and application infrastructure | Core provider |
| Convex | Database services and backend compute | Organization data, account-linked records, rosters, events, permissions, messages, settings, attendance, and related application data | Stores and processes core Patravo application data | Core provider |
| Clerk | Authentication and account management | Names, email addresses, phone numbers where used, login identifiers, authentication events, sessions, account protection signals, account metadata | Provides sign-in, account management, sessions, and Clerk Client Trust account protection signals where available | Core provider; Patravo plans to require multi-factor authentication for organization administrators |
| Cloudflare R2 | File and media storage | Uploaded files, photos, videos, attachments, thumbnails, storage metadata | Stores files and media | Core provider; private media is accessed through signed URLs or other controlled access methods |
| Resend | Email delivery | Email addresses, email content, delivery metadata, bounce/failure information | Sends service emails, account notices, organization notifications, support messages, and related email communications | Core provider; open tracking and click tracking are disabled |
7. Provider Details
7.1 Vercel
Service provided: Hosting, deployment, and compute.
Patravo uses Vercel to host and run parts of the Patravo website, web app, and application infrastructure.
Vercel may process:
- Web and app traffic
- Request metadata
- Technical logs
- Application responses
- Infrastructure metadata
- Security and reliability information
Patravo designs application logs to avoid storing customer content, youth roster details, message contents, media contents, and other unnecessary personal information.
Vercel is a core provider needed to operate Patravo.
7.2 Convex
Service provided: Database services and backend compute.
Patravo uses Convex for application database services and backend compute.
Convex may process:
- Organization data
- Account-linked records
- Roster records
- Youth member records
- Parent and guardian relationships
- Roles and permissions
- Events
- RSVP and attendance records
- Messages and communications
- Settings
- Related application data
Convex is a core provider needed to operate Patravo.
7.3 Clerk
Service provided: Authentication and account management.
Patravo uses Clerk for authentication and account management.
Clerk may process:
- Names
- Email addresses
- Phone numbers where used
- Login identifiers
- Authentication events
- Session information
- Account protection signals
- Account metadata
Patravo uses Clerk Client Trust and session protections where available. Patravo plans to require multi-factor authentication for organization administrators, but that requirement is not active in the current MVP.
Clerk is a core provider needed for user sign-in, sessions, account management, and account protection.
7.4 Cloudflare R2
Service provided: File and media storage.
Patravo uses Cloudflare R2 to store files and media.
Cloudflare R2 may process:
- Uploaded files
- Photos
- Videos
- Attachments
- Thumbnails
- Storage metadata
- Access-related metadata needed to store, retrieve, and secure files
Private files and media are stored privately and accessed through signed URLs or other controlled access methods.
Media intentionally published publicly may be stored or served separately from private organization media, including through a special bucket, public storage path, or other separation method.
Cloudflare R2 is a core provider for file and media storage.
7.5 Resend
Service provided: Email delivery.
Patravo uses Resend to deliver email.
Resend may process:
- Email addresses
- Email message content
- Delivery metadata
- Bounce information
- Failure information
- Related email delivery data
Patravo does not use email open tracking or click tracking.
Resend may deliver:
- Account notices
- Security notices
- Service emails
- Organization notifications
- Event reminders
- Support messages
- Policy notices
- Billing-related notices, where applicable
Resend is a core provider for email delivery.
8. Core Providers and Feature-Specific Providers
Some providers are necessary for Patravo to operate. Others are used only when certain features are enabled.
Core Providers
Core providers currently include:
- Vercel
- Convex
- Clerk
- Cloudflare R2
- Resend
These providers support the basic operation of Patravo.
Feature-Specific Providers
Patravo does not currently list any feature-specific subprocessors.
If Patravo adds feature-specific subprocessors later, they will be listed here and will process data only when the related feature is used or enabled.
9. Optional Integrations and Customer-Selected Providers
Patravo may support optional integrations in the future, such as calendars, file storage, payments, identity services, communication tools, reporting tools, or other connected services.
An optional integration may be:
- A Patravo subprocessor
- A platform provider
- A customer-selected provider
- An independent controller
- A separate service controlled by the organization or user
The classification depends on how the integration works.
Organizations should review the terms and privacy policies of optional integrations before enabling them.
Where an organization chooses, controls, or authorizes a third-party service outside Patravo, that service may process data under the organization’s own relationship with that provider, not as Patravo’s subprocessor.
10. Platform Providers
Platform providers may process data under their own terms.
Examples may include:
- Apple
- Mobile operating system providers
- App stores
- Device manufacturers
- Payment platforms controlled by an app store
- Browser providers
These providers are not automatically Patravo subprocessors.
For example, Apple or Google may process information when a user downloads an app, manages app permissions, receives mobile platform services, or makes an app-store purchase. That processing may occur under Apple’s or Google’s own terms and privacy policies.
Patravo’s App Store privacy details and Google Play Data Safety disclosures should match the actual behavior of the Patravo apps and included SDKs.
11. Youth Data and Subprocessors
Patravo is designed for youth-serving organizations.
Some subprocessors may process youth-related information when needed to provide Patravo.
Youth-related information may include:
- Youth names or display names
- Guardian relationships
- Organization membership
- Group or patrol membership
- Event participation
- RSVP and attendance records
- Messages and communications
- Photos, videos, and files
- Role or position information
- Permission or consent records
- Related organization records
Patravo does not allow subprocessors to use youth information for advertising, marketing, data brokerage, or unrelated purposes.
Organizations should avoid storing unnecessary sensitive youth information in Patravo or any connected service.
12. Message, Media, and Communication Data
Some providers may process message, media, or communication data because those providers are needed to deliver Patravo’s communication and media features.
Examples:
- Convex may process message and application data.
- Cloudflare R2 may store photos, videos, files, and attachments.
- Resend may process email content needed to deliver emails.
Patravo does not use message, media, or communication content for advertising.
Patravo does not use AI features, AI providers, or customer content to train AI models.
13. Public Media and Private Media
Patravo may support both private organization media and public organization media.
Private files and media are stored privately and accessed through signed URLs or other controlled access methods.
Media intentionally published publicly may be stored or served separately from private organization media, including through a special bucket, public storage path, or other separation method.
Organizations control what they publish publicly.
Youth photos, videos, names, identifying details, event participation, or sensitive information should be published publicly only with appropriate permission and in accordance with organization policy and applicable law.
Patravo cannot control screenshots, downloads, search-engine caches, social-media sharing, third-party archives, or copies made after content is intentionally published publicly or downloaded by an authorized user.
14. Email Tracking
Patravo does not use email open tracking or click tracking.
Patravo may still process delivery-related information needed to operate email features, such as:
- Delivery status
- Bounce information
- Failure information
- Opt-out status
- Security or abuse-prevention information
This delivery information is used to provide, troubleshoot, secure, and improve the service. It is not used for advertising.
15. International Processing
Patravo is operated from the United States.
Patravo’s subprocessors may process data in the United States and other countries where they or their infrastructure operate.
Where required, Patravo uses appropriate contractual, technical, organizational, and legal safeguards for international processing.
Additional international data-transfer terms may be included in a Data Processing Addendum or other written agreement where applicable.
Patravo does not promise that data will remain in a specific country or region unless Patravo has made that commitment in a signed written agreement.
16. Vendor Security Review
Patravo reviews service providers based on the role they perform, the data they process, available security documentation, privacy documentation, and service need.
Vendor review may consider:
- Service purpose
- Data categories processed
- Whether youth data may be processed
- Whether customer content may be processed
- Whether message contents may be processed
- Whether photos, videos, or files may be processed
- Whether authentication data may be processed
- Security documentation
- Privacy documentation
- Data-processing terms
- Confidentiality obligations
- Incident-notification practices
- Availability and reliability
- Ability to support deletion, access, export, and retention obligations where applicable
- Consistency with Patravo’s no-advertising and no-data-sale commitments
Patravo may rely on provider agreements, data-processing terms, privacy documentation, security documentation, and other available materials when reviewing subprocessors.
Some Patravo providers may maintain their own security certifications, audit reports, or compliance materials. Those provider materials support Patravo’s vendor review, but they do not mean Patravo itself has the same certification unless Patravo separately states that it has completed that certification.
17. Contractual and Use Restrictions
Patravo uses subprocessors to provide services to Patravo.
Subprocessors may process personal information only as needed to provide their services to Patravo.
Patravo does not allow subprocessors to use Patravo data for their own:
- Advertising
- Marketing
- Data brokerage
- Cross-site behavioral tracking
- Sale of personal information
- Unrelated commercial purposes
Patravo may use provider data-processing terms, vendor agreements, standard service terms, enterprise agreements, security documentation, and privacy documentation where appropriate.
18. Changes to Subprocessors
Patravo may add, replace, or remove subprocessors as the service evolves.
When Patravo makes a material change to this Subprocessor List, Patravo will update this page and the Subprocessor Changelog.
Material changes may include:
- Adding a new subprocessor
- Removing a subprocessor
- Changing the purpose of a subprocessor
- Changing the data categories processed by a subprocessor
- Adding a provider that processes youth information, messages, media, authentication information, or sensitive organization data
- Adding a payment, analytics, crash reporting, support, or communication provider
Where required by law, contract, or Patravo’s Data Processing Addendum, Patravo will provide notice and an opportunity to object.
19. Customer Objection Process
Where required by law, contract, or Patravo’s Data Processing Addendum, customers may object to a new subprocessor.
Objections should be sent to:
An objection should include:
- The customer or organization name
- The subprocessor at issue
- The reasonable data-protection basis for the objection
- Any specific concern about youth data, organization data, media, messages, security, or international processing
- Contact information for follow-up
Patravo will review the objection and respond as appropriate.
Depending on the circumstances, Patravo may:
- Provide additional information
- Explain why the provider is needed
- Limit use where practical
- Offer an alternative where available
- Allow the customer to disable a feature-specific provider where applicable
- Allow termination of the affected service where required by contract or law
An objection does not automatically require Patravo to stop using a core provider for all customers. Some subprocessors are necessary to provide Patravo.
20. App Store and Google Play Alignment
Patravo’s Subprocessor List should be consistent with Patravo’s App Store privacy details and Google Play Data Safety disclosures.
If Patravo adds or removes mobile SDKs, analytics tools, crash reporting tools, payment SDKs, push notification providers, communication providers, or other third-party services, Patravo will review whether this Subprocessor List, Privacy Policy, Security Policy, App Store disclosures, and Google Play disclosures need to be updated.
Patravo does not use advertising SDKs, ad networks, marketing pixels, or cross-site behavioral tracking.
21. Providers Not Currently Listed
As of this version, the current Subprocessor List includes the providers listed in Section 6.
If Patravo later uses additional providers, they should be reviewed and added where appropriate.
Potential future provider categories may include:
- Payment processors
- Push notification providers
- Customer support tools
- Error monitoring tools
- Crash reporting tools
- Product analytics tools limited to reliability
- Calendar integrations
- File import/export providers
- Security monitoring providers
- Status page providers
- Documentation or help-center providers
- Consent management providers
- Identity verification providers
Patravo will update this page if a provider becomes a Patravo subprocessor.
22. No Advertising or Data Brokerage
Patravo does not use subprocessors to sell personal information, serve advertisements, build advertising profiles, or track users across unrelated websites.
Patravo does not use:
- Advertising cookies
- Marketing pixels
- Meta Pixel
- TikTok Pixel
- Google Ads remarketing tags
- Third-party ad networks
- Cross-site behavioral tracking
- Browser fingerprinting for advertising
Patravo does not allow subprocessors to turn Patravo data into advertising inventory or data-broker inventory.
23. Relationship to Other Patravo Policies
This Subprocessor List should be read together with:
- Patravo Privacy Policy
- Patravo Security Policy
- Patravo Terms of Service
- Patravo Youth Safety & Safeguarding Policy
- Patravo Acceptable Use Policy
- Patravo Cookie Notice
- Patravo Data Processing Addendum, where applicable
The Privacy Policy explains how Patravo collects, uses, shares, retains, protects, and deletes personal information.
The Security Policy explains Patravo’s security practices.
The Terms of Service explain the rules for using Patravo.
The Data Processing Addendum, where applicable, may include additional customer-specific data-processing terms.
24. Versioning and Changelog
Patravo is committed to transparent updates.
Every update to this Subprocessor List receives a version number.
Current and previous versions are available at:
https://patravo.com/trust/subprocessors/versions
Material changes are summarized in the changelog at:
https://patravo.com/trust/subprocessors/changelog
Patravo may avoid publishing sensitive operational details if doing so would create security risk.
25. Contact
Questions about Patravo subprocessors may be sent to:
Venlorin LLC
522 W Riverside Ave Ste N
Spokane, WA 99201
United States
Website: https://patravo.com
Privacy: privacy@patravo.com
Security: security@patravo.com
Support: support@patravo.com