Subprocessors

These are the third-party providers NuvoWork relies on to operate the product. For each one we list what it is used for, exactly what data is shared, and why that data is needed. None of these providers receive data for advertising, profiling, or resale.

Last updated: August 4, 2026

Cloud hosting, database & authentication (Lovable Cloud)
Purpose
Runs the NuvoWork application and stores all company and employee records.
Data shared
All application data: account email, password hash, company and employee profiles, time entries, breaks, work categories, pay rates, PTO, payroll runs, messages, calendar events, GPS clock-event records, and audit logs.
Why it is needed
The product cannot operate without hosting and a database. Data is stored in the United States and access is restricted by row-level security rules enforced per company.
Transactional email delivery (Resend)
Purpose
Sends employee invitations, password resets, and account notices.
Data shared
Recipient email address, recipient and company display names, and the contents of the message being sent.
Why it is needed
Invitations and password resets must be delivered by email. No marketing lists are maintained and email addresses are not shared for any other purpose.
Payments (Stripe)
Purpose
Processes Pro subscription payments and manages billing.
Data shared
Billing email, company identifier, subscription and payment status. Card details are entered directly with Stripe.
Why it is needed
Card data must be handled by a PCI-compliant processor. NuvoWork never sees or stores card numbers.
Address lookup (OpenStreetMap / Nominatim)
Purpose
Converts clock-in and clock-out coordinates into a readable street address for the time record.
Data shared
The latitude and longitude of a single clock event. No account, employee, or company identifiers are sent.
Why it is needed
Coordinates alone are not useful to an admin reviewing a timesheet. This request is only made when a company has GPS verification enabled.
Browser & mobile push delivery (device push services)
Purpose
Delivers push notifications to employees who opted in on their own device (for example Apple or Google push services, depending on the browser).
Data shared
An anonymous push endpoint created by the browser and the encrypted notification payload.
Why it is needed
Push delivery on phones must pass through the browser vendor's push service. Notifications are encrypted before they leave NuvoWork.

What is not on this list

NuvoWork uses no advertising networks, no data brokers, and no third-party analytics or tracking SDKs. There is no Google Analytics, no ad pixels, and no cross-site tracking. If we ever add a provider that receives personal information, it will be added here before it goes live.

Privacy Policy·Security & Privacy·Terms