Trust Center
We use the following third-party vendors to deliver MyBookie. Each one processes only the data needed for their specific function. Subscribe to our changelog at /security to be notified when this list changes.
Last updated: May 17, 2026
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| MongoDB Atlas | Primary database for all customer data (transactions, accounts, businesses) | Email, hashed password, business data, transactions, encrypted Plaid tokens | United States (us-east) |
| Plaid | Bank account connection and transaction sync | Bank account metadata, transaction history (read-only) | United States |
| Stripe | Payment processing for subscription billing | Email, billing address, masked card number (PCI handled by Stripe) | United States · global |
| Resend | Transactional email delivery (security alerts, weekly briefs, invoices) | Email address, email content | United States |
| OpenAI | AI insights, KPI commentary, weekly Finance Brief generation | Aggregated financial summaries (no raw transaction data with PII) | United States |
| Anthropic | AI smart-categorization and chatbot responses | Transaction descriptions, user questions | United States |
| Vonage | SMS delivery for 2FA codes (when SMS 2FA is enabled) | Phone number, 6-digit one-time code | United States · global |
| Emergent (hosting) | Application hosting and Kubernetes infrastructure | All data in transit and at rest | United States |