Trust
Subprocessors
Every third-party service that processes Mise customer data, what they do, and where they're hosted. We notify active customers in advance when we add or change a subprocessor.
Mise relies on a small set of vendors to operate. Each one receives only the data needed for its specific job. The table below is the complete list as of the date above.
When we add or change a subprocessor that affects how customer data is handled, we’ll email active customers at least 30 days in advance and update this page on the same day. Cosmetic edits (purpose-text tweaks, link updates) get the date bump without an email.
Supabase
Purpose: Postgres database, authentication, edge functions. The system of record for all customer data.
Data accessed: All customer data: account info, businesses, transactions, categorizations, loans, subscriptions, suggestions.
Region: US-east (Northern Virginia)
Vercel
Purpose: Hosting for the marketing site and the product app.
Data accessed: Server logs (IP, user agent, request path). No customer business data is persisted on Vercel.
Region: US-east (Northern Virginia, edge globally)
Plaid
Purpose: Bank connection and transaction sync. Plaid handles authentication with your bank and provides Mise read-only transaction data.
Data accessed: Bank account identifiers, transactions, balances. Plaid never shares your banking password with us.
Region: United States
Anthropic
Purpose: AI categorization (the Claude API). For each transaction Mise can't rule-match, we send the merchant + amount + your chart of accounts and Anthropic proposes a category.
Data accessed: Per-transaction: date, amount, merchant name, description. Per request: your chart of accounts. Not used to train Claude's general models.
Region: United States
Intuit (QuickBooks Online)
Purpose: Two-way QuickBooks Online integration. We read your QBO chart of accounts and push journal entries you confirm.
Data accessed: QBO accounts list. We write journal entries (which contain the categorized transaction data). We don't read invoices, bills, customers, or vendors.
Region: United States
Stripe
Purpose: Subscription billing and the Customer Portal.
Data accessed: Email, last-4 of card, subscription state. We never see full card numbers or CVV.
Region: United States
Resend
Purpose: Transactional email delivery (signup confirmations, password resets, billing notifications).
Data accessed: Email address + the contents of the email being sent.
Region: United States
GitHub
Purpose: Source code repository. Code review and deployment pipeline.
Data accessed: No customer business data. Source code only; deployment metadata.
Region: United States
What we don’t use
For clarity:
- No analytics or advertising platforms.We don’t use Google Analytics, Segment, Mixpanel, Facebook Pixel, or anything similar. No third-party tracking on the marketing site or in the product.
- No data brokers.We don’t sell, share, or enrich your data with any third party not listed above.
- No offshore data processing. Every subprocessor stores Mise data in US data centers.
Questions
If a subprocessor matters to your evaluation (or your customers won’t let you use a tool that touches a specific one), email hello@miseencomptes.com — we’ll talk through what each one does in your specific case and whether there’s a workaround.