Effective Date: August 8, 2026
This Vendor and Subprocessor Management Policy defines how RepLogix selects, evaluates, and manages third-party service providers that process, store, or transmit customer data. It ensures that vendors meet appropriate security and privacy standards.
This policy applies to all third-party vendors and subprocessors used by RepLogix to deliver the Service, including hosting, database, authentication, payment processing, email, SMS, analytics, and support tools.
RepLogix uses the following categories of subprocessors:
| Provider | Function | Data Accessed |
|---|---|---|
| Base44 | Application hosting, database, auth, file storage | All application data (encrypted at rest) |
| Stripe | Payment processing, subscription billing | Payment metadata (no card numbers stored by RepLogix) |
| Google (OAuth) | Authentication provider | Email, name (for account creation) |
| Resend | Email delivery | Email addresses, message content |
| Twilio | SMS notifications | Phone numbers, message content |
All subprocessors are located in or process data within the United States. An up-to-date subprocessor list is maintained and available upon request.
Before engaging a new vendor or subprocessor, RepLogix evaluates:
Vendor due diligence includes:
Vendor contracts must include:
Vendors are monitored on an ongoing basis:
When a vendor relationship ends:
This Vendor Management Policy is reviewed at least annually and when significant vendor changes occur.
For questions about this policy or to request the current subprocessor list, contact:
RepLogix Security
Email: RepLogixapp@gmail.com