How this list works
This list names providers evidenced by the application. A configured integration is not proof that every deployment uses it. The operator must keep deployment-specific hosting and email providers current before production launch. Customers may ask privacy@plainspoken.co.za for current details or raise a reasonable objection to a new subprocessor.
Identified providers
The table separates a named payment integration from deployment-specific services whose vendor names are not in source control.
| Provider | Purpose | Data category | Processing location |
|---|---|---|---|
| PayFast | Bloom subscription checkout | Payer details and transaction references | Verify against current provider terms |
| Deployment SMTP provider | Transactional email | Recipient address and message | Deployment-specific; not yet verified |
| Deployment hosting provider | Application and database hosting | Service and customer data | Deployment-specific; not yet verified |