1. Current service register
| Service | Current position |
|---|---|
| Production application and database hosting | Not selected. Provider legal entity, region, support access and contract must be recorded before launch. |
| Map tiles | The current dashboard requests tiles from tile.openstreetmap.org when there are current driver coordinates. This discloses network information and map area. Assess its role, policy and suitability; do not assume an Article 28 subprocessor contract exists. |
| Fonts | Geist is downloaded at build time and self-hosted by Next.js. The frontend does not direct visitor font requests to Google Fonts. |
| Email, SMS and customer support | Account messages currently use private mock previews with no external delivery. SMTP email and Twilio SMS adapters are available but no production sender or provider contract has been confirmed. No support-ticket provider is configured. Provider identity, processing terms and transfer arrangements must be published before activation. |
| Payments and subscription invoicing | A Stripe-hosted Checkout and customer-portal integration is implemented but live billing is not configured. Before enabling it, confirm the contracted Stripe entity, roles, processing terms, international transfers, retention and applicable disclosures. Stripe may act in different roles for different payment activities; do not assume all processing is solely on our instructions. |
| OCR and route optimisation | Not implemented. No OCR/model/routing provider has been appointed for customer receipts. |
| Analytics and advertising | No analytics or advertising integration is present in this application. |
2. Development is not production hosting
The local PostgreSQL container, GitHub source repository and generated marketing artwork do not establish where customer data will be hosted in production. Secrets and local database files are excluded from source control. The generated artwork is an illustration, not a customer testimonial.
3. Before appointing a provider
Record the provider’s legal identity, purpose, information processed, country/region, remote-access locations, contract and applicable transfer safeguards. Assess whether the provider is a processor, subprocessor or independent controller. Complete customer notice/authorisation procedures before any change that requires them.
Official guidance & references
The sources below inform the review. They do not certify this product or replace the company’s operational responsibilities.
EDPB: controller and processor responsibilitiesOpenStreetMap Foundation privacy policyOpenStreetMap tile usage policy