Sub-processors
Last updated: 1 October 2026
Vanround is operated by Glebefish Limited. Running it means relying on a small number of third-party services. Where we handle personal data on behalf of a courier firm using Vanround, those services are our sub-processors, and this page lists all of them.
It is kept current. If you want to be told when it changes, email hello@vanround.com.
Who does what
| Service | What it does for Vanround | What data it handles | Where |
|---|---|---|---|
| Google Firebase & Google Cloud |
Sign-in, database, photo and file storage, push notifications, crash reporting, usage analytics, and running our server code | Everything the app stores: drops, customer details, photographs, signatures, messages, and user accounts | London (europe‑west2) for the database, file storage and server code. Crash reporting and analytics may be processed outside the UK |
| Google Maps Google Maps APIs |
Turning a typed drop address into map coordinates, on the office dashboard and on Android phones, and drawing the map in the app on Android. Google does this as an independent controller, under its own controller terms, rather than on our instructions: that is how Google offers its Maps APIs to every business that uses them. On an iPhone the app uses Apple instead; see below. Corrected 30 September 2026: this line did not say either | The drop address only. When the app draws a map on Android, Google also sees the phone's IP address and the part of the map on screen | Google's own infrastructure, worldwide, under its controller terms |
| Resend | Sending invitation emails when a courier firm invites someone to join it on Vanround, and — only where a courier firm has turned them on — drop update emails to that courier firm's own customers | The invited person's email address, and the name of the person inviting them. Where drop updates are on: the customer's name and email address, and what the message says about their drop — title, reference, address, and who signed for it. Updated 6 September 2026, before the feature could be used | European Economic Area (Ireland) |
| Expo | Building the app, and delivering app updates to phones without a full reinstall | A device's IP address and app version when it checks for an update. No customer or drop data. Expo's terms let it use aggregated, anonymised data to improve its own products | Global content delivery network |
| Mistral AI Paris, France |
Two things. First, when you import your customer list from a spreadsheet, working out which column is which: which one holds the name, which the phone number. Second, when you upload a PDF booking confirmation, reading it to pull out the customer and the addresses for you to check, off for your firm until one of your admins turns it on in Settings. In use from 1 October 2026, replacing Anthropic, which was never sent any customer data. This list is updated before a change is made, not after | A sample of the file you upload: its column headings and up to twenty rows, with long entries shortened. Not the rest of the file. It is asked to describe the layout, not to produce any customer record: every record is built from your file by our own code. For the PDF reading, the whole document you upload: the customer's name, phone number and address as they appear on it. Nothing is created from it until you have checked what was found. Not kept: Mistral has agreed not to store or log what we send for longer than it takes to produce the answer. Not used for training | EU and EFTA countries. We use Mistral's EU service, which keeps the processing there |
| Hetzner Online GmbH our map server |
Working out the real driving distance of a drop — road miles rather than a straight line — so a price can be based on the drive that will actually be made. Added 17 September 2026, before the feature reaches anyone | Map coordinates only: the stops on a drop or a round, and the firm's own address as the start and end of each van's day, for a firm that keeps its vans in the app. No name, no address in words, no phone number, no email address. The map itself is open data held on that machine, so nothing is looked up anywhere else | Germany (Falkenstein). It never leaves the EU, and it is a machine we rent and run ourselves rather than somebody else's service |
| HERE Europe B.V. drive times in traffic |
Working out how long a drop will take to drive in the usual traffic for the day and time it leaves, on the office's new drop form. Added 28 September 2026 | Map coordinates only: the stops on the drop, and the day and time it leaves. No name, no address in words, no phone number, no email address. The drive time that comes back is deleted from the drop after 30 days, which is as long as HERE's terms allow it to be kept. HERE may use anonymised, aggregated learnings from these requests to improve its own products, which its terms allow. We have asked HERE to switch that off for our account, and this line will say when it has | The Netherlands (HERE Europe B.V., Eindhoven). HERE's terms do not say which country a request is processed in. We have asked, and this line will say when they answer |
| Ideal Postcodes | Turning a postcode into the list of addresses at it, so an address can be picked from a list instead of typed out | The postcode, and nothing else — not the customer's name, not the house number, not who was asking or what the drop is | United Kingdom |
| Stripe Stripe Payments UK Limited |
Taking the payment when a courier firm's customer pays an invoice by card. The money goes into the courier firm's own Stripe account, not through us. The courier firm has its own agreement with Stripe, which it accepts when it connects its account, and Stripe takes the payment under that agreement. Stripe is also an independent controller for its own purposes: fraud checks, identity and money-laundering checks, choosing the banks and card networks a payment goes through, and improving its own products. Added 29 September 2026, before card payments are switched on: nobody can pay by card yet. Corrected 30 September 2026: this line called Stripe an independent controller for the card details, which is only true for those purposes | The invoice amount and reference, the courier firm's name, and the customer's email address, filled in on the payment page so the receipt reaches them. The customer types their card details into Stripe's own page, so they never pass through us. When a courier firm connects its Stripe account, Stripe is given its email address and trading name, and asks everything else it needs directly | United Kingdom, the EU and the United States, under Stripe's data processing agreement, which includes the EU Standard Contractual Clauses and the UK Addendum |
| Cloudflare | Hosting this website and the dashboard, forwarding email sent to our contact address, and carrying requests to our map server | Website visitor data, anything you send us by email, and the map coordinates on their way to our map server | Global |
What this means in practice
Everything a courier firm records in Vanround โ drops, customer names and addresses, photographs and signatures โ is stored by Google in London. It does not go to any of the other services on this page, except in seven narrow ways: a drop address is sent to Google, or on an iPhone to Apple, so it can be placed on a map; a postcode is sent to Ideal Postcodes so the addresses at it can be listed; the coordinates of a drop's stops are sent to our own map server so the drive between them can be measured; the same coordinates and the time it leaves are sent to HERE so the drive can be timed in traffic; a customer paying an invoice by card is sent to Stripe with the amount, the reference and their email address; a customer file or PDF booking that an admin uploads is sent to Mistral to be read; and a courier firm that has turned on drop update emails sends that customer's name, email address and drop details through Resend.
Of the remaining services, Resend is the only one that ever sees a customer by name, and only where a courier firm has turned drop update emails on. With those emails off — which is how every courier firm starts, and how both of ours are today — Resend only ever handles an invitation. Expo only ever sees a phone checking whether a newer version of the app exists. Cloudflare only handles this website and our inbox.
One route does not involve Resend at all. A courier firm can connect its own Microsoft 365 or Google account, and its drop update emails then go out through that account rather than through us — so the message reaches the customer via the courier firm’s own mail provider, under the arrangement it already has with them, and Resend never sees it. We hold the permission that account gave us so the emails can be sent, and nothing else; disconnecting it in Vanround removes that permission at our end, and the account’s own settings remove it at theirs. Added 6 September 2026.
Some services are not sub-processors at all, and it is worth saying which. When a worker taps “Open in Maps”, the drop address is handed to the navigation app they chose — Google Maps, Waze or Apple Maps. That app is working for the worker at that point rather than for us, so it is not somebody processing data on our instructions and it is not listed above. Nothing else about the drop goes with the address. Added 17 September 2026, because the policy described the map the app draws and never the one a worker opens.
Load exchanges work like the connected mailbox. A courier firm can connect its own Courier Exchange or SDCN membership in Settings. The exchange then works for the courier firm, under the membership and terms it already has, not for us, so it is not listed above. We hold the login it gives us, encrypted, and use it only when one of its admins asks to see its own loads and the quotes on them. What comes back is shown to that admin and not kept. Nothing is sent to an exchange except that login and the dates asked for. Disconnecting it in Settings deletes the login at our end. Added 30 September 2026: this page did not mention the exchanges before.
The phone's own map on an iPhone. On an iPhone the app turns a typed address into coordinates, and draws its map, with Apple's map service rather than Google's. Apple is sent the address typed, and sees the phone's IP address and the part of the map on screen. That is the phone's own service, which Apple runs as an independent controller under its own terms. Added 30 September 2026: this page said the address always went to Google.
The dashboard's maps. The maps on the dashboard are drawn from the OpenStreetMap Foundation's tile servers. The browser asks them for the squares of map on screen, so they see the office computer's IP address and which area it is looking at. Nothing about a drop, a customer or a member of staff is sent. The Foundation handles that under its own privacy policy. Added 30 September 2026.
What we do not do
- We do not sell personal data. We do not share it for anyone else's own purposes, except where a service keeps that right and this page says so: Google and Apple for maps, Stripe for its own checks, and HERE and Expo for anonymised learnings.
- We do not use it for advertising.
- We do not use your data to train AI or machine learning models, and we do not let anyone else do so. The only features that send customer data to an AI service are the two Mistral ones listed above, each only when an admin uploads a file for it to read, and neither lets Mistral train on it. Any new one will be listed here, and you told by email, before it is switched on.
Each of the services above uses suppliers of its own, published in its own sub-processor list and bound by our agreement with it. We can tell you what we send and to whom โ that is this page โ but we cannot make promises on a supplier's behalf about its own supply chain. Where a provider publishes a list, our agreement with them requires notice before it changes.
One setting worth naming
Google Analytics offers a setting that lets Google use the data it collects to improve its own products. Turning it on would make Google an independent user of that data rather than a service acting on our instructions.
We have turned it off, along with the options that contribute data to industry benchmarks and that give Google's sales and marketing staff access to our analytics. The one option we have left on lets Google's technical support staff look at the data when they need to diagnose a fault โ that is them helping us run the service, which is the whole point of them having it.
We mention it because it is on by default, and because it is the setting that decides whether the first line above is actually true.
Changes
Where we choose to add or replace a sub-processor, we update this page and tell affected firms by email before the change takes effect — so it is never something you find out about afterwards. Adding Anthropic was the first change done this way, and replacing it with Mistral the second.
Where one of the services above changes its own suppliers, we pass their notice on as soon as we get it. We cannot give more notice than we are given, and the periods differ: Google gives us 30 days, Resend 14, and Mistral commits only to “reasonable notice”. Where what we receive is too short to be useful, we will switch the affected feature off rather than pass on notice you cannot act on.
Questions
If you are a courier firm using Vanround and you need this in contractual form, or you want to know more about how one of these services is used, contact hello@vanround.com.
If you are a customer of a courier firm that uses Vanround, that firm controls your data โ contact them directly. See section 2 of our privacy policy.