TarmacSync uses the following third-party subprocessors to provide the Service. Airport user data — procurement sessions, configuration, and conversation content — may be processed by these services as part of normal operation. This list is referenced from our Privacy Policy.
Current subprocessors
Entries marked When configured are switched on by a deployment setting and are absent from deployments that do not set it.
Neon (Database)
Purpose:
Persistent storage for airport configurations, procurement sessions, project cases, lifecycle records, audit events, and evidence packets.
Data processed:
All structured data stored by TarmacSync — see our Privacy Policy for retention details.
⚠️ Confirm the storage provider and its region before enabling upload-based workflows. Uploaded documents are not covered by the database provider's agreements.
Google (Gemini AI Inference)
When configured
Purpose:
AI inference for procurement guidance when Gemini is the configured provider, and extraction of uploaded PDFs during onboarding import.
Data processed:
Conversation content, airport context included in the system prompt, and the text of PDFs submitted through the onboarding wizard.
AI inference for procurement guidance. DeepSeek is the default provider when AI_PROVIDER is unset, and is an automatic fallback when another selected provider's key is absent.
Data processed:
Conversation content (user messages and AI responses) and airport context included in the system prompt.
⚠️ There is no code-level block on DeepSeek in any environment. A deployment that must not send content to a PRC-based provider has to set AI_PROVIDER to another provider AND leave DEEPSEEK_API_KEY unset — setting AI_PROVIDER alone is not sufficient, because DeepSeek remains a fallback.
OpenRouter (AI Inference)
When configured
Purpose:
AI inference for procurement guidance when OpenRouter is configured as the primary or fallback provider.
Data processed:
Conversation content (user messages and AI responses) and airport context included in the system prompt.
⚠️ Review OpenRouter's current routing, retention, and provider data-use terms before deploying with sensitive procurement data.
Sentry (Error Monitoring)
When configured
Purpose:
Capture of unhandled application errors, and of document-ingestion failures, for diagnosis.
Data processed:
Error messages, stack traces, and request context. Application payloads may incidentally contain user-supplied text present in the failing operation. The document-ingestion worker reports under a stricter posture and excludes uploaded document text, file names and stack-frame local variables before send; the organization identifier is hashed rather than sent.
⚠️ Enabling this routes complete conversation content to a new party. Retention is configurable from three days, and self-hosting keeps trace data within your own infrastructure. Not enabled for document ingestion, which makes no generative call — see ADR-025.
Upstash Redis
When configured
Purpose:
Distributed rate limiting and short-lived operational cache.
Data processed:
Rate-limit keys, counters, and short-lived operational metadata.
These services are not subprocessors — they store no airport data and act on nobody’s behalf. They are listed because search terms derived from what you type leave our infrastructure when they are queried.
Tavily (Web Search)
When configured
Purpose:
Vendor and market research during proactive enrichment of a path review.
Data processed:
Search query strings derived from the purchase description. No stored customer records are sent.
This list is generated from the vendor manifest the application itself is built against, so it cannot drift from the code. Material changes — new AI providers, database providers, or storage providers — will be communicated to airport pilot customers before taking effect.
Data processing agreements
DPAs are available from Neon, Resend, Langfuse, Vercel for enterprise and government customers. Contact [email protected] to request DPAs for your organization’s records. For vendors without a DPA on file, request the current terms before enabling the feature that uses them.