Policies

Third-Party Vendors

Version 3.0 Last updated 2026-08-15

Overview

Xive — the platform owned and operated by Velaris Management Group LLC, a Kentucky limited liability company — relies on a small number of service providers, often called “vendors” or “subprocessors”, to run the Services. They host our infrastructure, deliver video, move money, send messages, and help us keep the platform safe.

This page names the providers that materially process personal information today. What data we share with them, and on what legal bases, is governed by our Privacy Policy. Technical safeguards are summarised in our Data Storage & Security Overview.

Providers we use

  • Google Cloud (Google LLC) — compute and managed PostgreSQL hosting for the platform and its primary database, in the United States. Processes: everything stored by the Service.
  • Cloudflare, Inc. — DNS, content delivery, TLS termination, web application firewall and bot mitigation; Cloudflare Stream for live ingest, recording, and video delivery; Cloudflare R2 for stored media; Cloudflare Workers AI for automated media screening. Processes: IP addresses and request metadata, uploaded media, live video and recordings.
  • Stripe, Inc. — card payments on the web, and Stripe Connect for creator identity verification, tax collection, and payouts. Processes: payment credentials (which we never see), transaction data, and creator identity and bank details.
  • Apple Inc. — in-app purchases through the App Store and push notification delivery to iOS devices. Processes: purchase receipts and device push tokens.
  • Google LLC — in-app purchases through Google Play and push notification delivery to Android devices. Processes: purchase receipts and device push tokens.
  • Expo (650 Industries, Inc.) — the push notification service that routes our notifications to Apple’s and Google’s push gateways, and delivery of app updates. Processes: device push tokens and notification payloads.
  • Postmark (ActiveCampaign, LLC) — transactional and administrative email. Processes: email addresses and message content.
  • OpenStreetMap Foundation — the Nominatim service, used to turn coordinates supplied at sign-in into a city and region. Processes: coordinates only, with no account identifier attached.
  • Microsoft Corporation (Azure) — storage of a legacy set of media files predating our move to Cloudflare R2. Processes: stored media.
  • Google LLC (Google Analytics) — website usage analytics. Processes: pages viewed, approximate location derived from IP address, and device and browser information.
  • Google LLC (Google AdSense) — non-personalised advertising on the website. Processes: the content of the page being viewed, IP address, and approximate location. It does not receive your account identity.

We run our identity provider, our realtime messaging service, and our voice and video calling service on infrastructure we operate ourselves, so no third-party SaaS provider processes your credentials, your realtime activity, or your calls.

We use Google Analytics for website usage analytics and Google AdSense for non-personalised advertising on the website. We do not use marketing platforms or crash-reporting services, and our mobile apps contain no analytics or advertising software development kits and show no advertising.

How we govern vendors

Before a material vendor touches user data in production, we review its documentation, certifications where relevant, and incident history. Riskier relationships receive deeper review or are rejected.

  • Confidentiality and use limitations: vendors may use our data only to provide the contracted service, not for unrelated model training or resale unless expressly allowed.
  • Data processing terms: where GDPR, UK GDPR, or similar laws apply, we rely on Article 28-style processor obligations covering instructions, subprocessors, deletion or return, and cooperation with audits.
  • Security and incidents: vendors commit to notify us of breaches or unauthorised access affecting our data within contractually defined windows and to assist with investigation.
  • Sub-subprocessors: where vendors appoint their own subprocessors, we rely on their published change notice processes.

International processing

Our hosting is in the United States. Content delivery is global by design, so published media may be cached near the person watching it. Where cross-border transfers require safeguards — Standard Contractual Clauses, the UK Addendum, or another approved mechanism — we rely on the mechanisms described in our Privacy Policy and in each provider’s data processing terms.

Changes

We add, replace, or retire vendors as the product, security posture, or economics change. Material changes are reflected on this page, and announced in-product or by email where our agreements or the law require it. This page is maintained by hand and reflects our production stack as of the “Last updated” date; short-lived trials and non-production tooling are not listed.

Contact

Questions about vendors, subprocessors, or data processing agreements: [email protected].

More policies