A business using the Platform is the data controller for the personal information of their own clients, vendors, and guests — they decide what's collected and why. VisualsBySaad acts as a data processor: we process that information on the business's behalf, to provide the Platform's functionality, not for our own independent purposes.
The Platform is built on infrastructure provided by named third parties, each acting as a sub-processor. Personal information may pass through:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting, authentication, file storage |
| Stripe | Payment processing for subscriptions and client invoices |
| Twilio | SMS and WhatsApp message delivery |
| Anthropic | AI-assisted features, where a business chooses to enable them for their own client communications |
| Hostinger | Web hosting for the Platform's pages, and outbound SMTP delivery for transactional emails (booking confirmations, contracts, invoices, notifications) sent through the Platform |
These providers have their own data handling practices and security certifications, which we have not independently audited beyond reviewing their published terms — a business with specific data residency or compliance requirements should review each provider's own documentation directly.
Some of these providers may process or store data outside Canada, including in the United States. Under PIPEDA, this is permitted, but a business must be transparent with their own clients about it if asked — this document is intended to make that transparency straightforward rather than something a business has to dig for.
If a core sub-processor changes (for example, switching SMS providers), this document will be updated to reflect it.
Data is protected through account-level authentication and row-level database security, meaning one business's data is not accessible to another business, and a vendor or venue can only see data for events they're actually involved in. Payment card details are handled entirely by Stripe and never stored directly by the Platform.
On request, and subject to reasonable legal and accounting retention requirements, a business's data can be deleted from the Platform. Deletion requests should be directed to us through the Platform's contact channels.
If a business is asked by their own client how that client's data is handled, this document and the Privacy Policy provide a specific, concrete answer.
We do not use personal information processed on a business's behalf for our own marketing, do not sell it, and do not share it with any party not listed above except as required by law.