SpendCaddie Logo
SpendCaddie

Service Providers & Subprocessors Notice

Version: 2.0Effective Date: May 21, 2026Last Updated: May 21, 2026

This Service Providers & Subprocessors Notice explains the third-party providers that Bobby Built Ventures, LLC d/b/a SpendCaddie uses to operate, secure, support, and improve the SpendCaddie service.

This page is not a consumer Data Processing Addendum. Individual consumer users are not controllers of SpendCaddie's consumer app processing. Any business or enterprise data processing agreement applies only if separately accepted or executed by an authorized business customer.

1. How SpendCaddie uses providers

SpendCaddie uses service providers for:

  • authentication;
  • database and storage;
  • hosting;
  • read-only financial account connections;
  • web billing;
  • iOS billing;
  • subscription entitlement management;
  • email delivery;
  • AI explanation generation;
  • analytics and performance measurement;
  • rate limiting;
  • infrastructure jobs;
  • push notifications;
  • security; and
  • support.

Providers may process personal information only as needed to provide their services, comply with law, protect their systems, enforce their terms, and support SpendCaddie.

2. Current providers

ProviderPurposeCategories of data that may be processed
PlaidRead-only financial account connection, account refresh, balances, transactions, liabilities, institution metadataaccount metadata, balances, transactions, liability/credit card fields, institution data, Plaid item/account IDs, connection status
StripeWeb billing, checkout, subscription management, customer portal, payment failure eventsbilling email, customer ID, subscription ID, invoice and payment metadata, limited payment method metadata
AppleiOS In-App Purchase billing, subscription cancellation, renewal, refund handlingApple-controlled purchase and subscription data
RevenueCatSubscription entitlement/status management and purchase event processingapp user ID, entitlement status, product IDs, platform/store metadata, purchase/renewal/cancellation/billing events
SupabaseAuthentication, database, storage, row-level security, backend infrastructureaccount, auth, profile, financial, consent, subscription, audit, support, and app data
VercelHosting, deployment, performance, and consented analyticsrequest logs, hosting metadata, performance data, analytics data where consented
ResendEmail deliveryemail address, email content, transactional and support message metadata
AnthropicAI explanation generationstructured debt-plan context, account/debt names or masks, balances, APRs, minimums, payoff summaries, alert context, user questions, AI usage metadata
UpstashRate limiting, infrastructure jobs, queue/scheduled job supportrate-limit keys, job metadata, limited operational data
ExpoMobile push notification delivery and mobile platform servicespush tokens, device/app metadata, notification payload metadata where enabled
Browser push providersWeb push notification deliverybrowser push endpoints, encrypted notification payloads, device/browser metadata
Financial institutionsSource of linked-account data through Plaidaccount data authorized through Plaid
App stores and device platformsApp distribution, device permissions, app updates, platform servicesdevice/app metadata, purchase or platform data controlled by the provider

3. Provider changes

Our providers may change over time. We may add, remove, replace, or change providers as needed for security, reliability, functionality, cost, legal compliance, product development, or user support.

If a provider change materially affects privacy practices, we will update our Privacy Policy or this notice as appropriate.

4. Third-party terms

Your use of certain features may be subject to third-party terms and privacy policies, including Plaid, Stripe, Apple, RevenueCat, and your financial institution.

SpendCaddie is not responsible for third-party services, provider outages, provider decisions, provider retention practices, or provider privacy practices except to the extent required by applicable law.

5. Security and provider review

SpendCaddie uses reasonable security and vendor-management practices appropriate to our stage, the sensitivity of data, and the services involved. Providers that process sensitive personal or financial information are expected to maintain reasonable security measures appropriate to the information they process.

6. Business/enterprise agreements

If SpendCaddie later offers business or enterprise services, those customers may be subject to separate written terms, including a data processing agreement if appropriate. Such agreements do not apply to individual consumer users unless expressly stated in a separately executed agreement.

7. Contact

Privacy Inquiries: privacy@spendcaddie.com
General Support: support@spendcaddie.com