Skip to main content
MavenPay
Sub-Processors

Sub-Processors

Effective 2026-06-08

  • Last updated ·
  • Effective from ·
The Short Version

This page describes the categories of Sub-processors that Maven Pay Inc. engages to process Personal Data on behalf of customers in connection with the MavenPay service. It supplements our Privacy Policy and our Data Processing Addendum.

1. Introduction

This page describes the categories of Sub-processors that Maven Pay Inc. engages to process Personal Data on behalf of customers in connection with the MavenPay service. It supplements our Privacy Policy and our Data Processing Addendum.

We make this categorical list public so that any visitor can understand the shape of the engagements we operate under. We make the corresponding named list available to customers on request under a Data Processing Addendum. Write to compliance@mavenpay.com for the current named list.

2. What We Mean By Sub-Processor

A Sub-processor is a third party that Maven Pay Inc. engages to process Personal Data on behalf of a customer in the course of providing the MavenPay service. A Sub-processor processes Personal Data on documented instructions from Maven Pay Inc. only. A Sub-processor is not a third party that decides on its own how to process the data.

Where a customer uses a feature operated by a regulated infrastructure provider, and that provider is the regulated party for the in-scope service, that provider is not a Sub-processor under this page. The provider is an independent regulated counterparty and is governed by its own terms of service and privacy policy. The identity of that provider is disclosed at the point where you activate the feature.

3. Categories Of Sub-Processor We Engage

Cloud-infrastructure providers. We engage cloud-infrastructure providers to host the MavenPay service, including compute, storage, databases, object storage, content-delivery networks, and managed networking. Personal Data may be processed in any of the regions where we operate the service.

Identity-verification providers. We engage identity-verification providers to verify the identity documents and the live likeness of customers and authorised representatives at onboarding and on triggered re-verification.

Sanctions and adverse-media screening providers. We engage sanctions-screening, politically-exposed-persons-screening, and adverse-media providers to screen customers and counterparties at onboarding and on an ongoing basis.

Transaction-monitoring providers. We engage transaction-monitoring providers to detect patterns indicative of fraud, money laundering, terrorist financing, or other illicit activity in the transactions we process.

Email, SMS, push, and voice-notification providers. We engage providers of transactional email, SMS, push notifications, and voice notifications to send service-related communications to customers.

Customer-support providers. We engage customer-support tooling providers to operate inbound and outbound customer-support channels, including help-desk, ticketing, knowledge-base, and chat surfaces.

Analytics and product-telemetry providers. We engage analytics and product-telemetry providers to understand how customers use the MavenPay product and the MavenPay marketing site, where the customer has given consent on the consent banner where required.

Customer-relationship-management providers. We engage customer-relationship-management providers to manage commercial relationships with prospect and existing customers.

Card-issuing and card-network providers. We engage card-issuing partners and the relevant card networks to issue and operate payment cards, where the customer uses card features.

Bank-connection and open-banking providers. We engage bank-connection and open-banking providers to connect customer bank accounts to MavenPay, where the customer chooses to connect a bank account.

Crypto-asset infrastructure providers. We engage crypto-asset infrastructure providers to operate the on-ramp, off-ramp, custody, and settlement of crypto-asset features.

Travel-distribution providers. We engage travel-distribution providers to source hotel inventory, flight inventory, ground-transfer inventory, and related travel inventory, where the customer uses concierge travel features.

Mobile-connectivity providers and mobile-network operators. We engage mobile-connectivity providers and mobile-network operators to deliver eSIM data and mobile top-up products, where the customer uses those features.

Document-management and signature providers. We engage document-management and electronic-signature providers to manage Personal Data captured during onboarding, contract management, and customer attestations.

Logging, monitoring, and observability providers. We engage logging, monitoring, and observability providers to keep the MavenPay service reliable, secure, and auditable.

Security-monitoring and threat-intelligence providers. We engage security-monitoring and threat-intelligence providers to detect, contain, and investigate security events that affect the MavenPay service.

Legal, compliance, audit, and advisory firms. We engage external counsel, auditors, accountants, tax advisers, and other professional advisers in connection with the regulated operation of the MavenPay service.

4. Where Personal Data May Be Processed

Personal Data processed by Sub-processors may be transferred to and processed in Canada, the United States of America, the United Kingdom, the European Union and the European Economic Area, Singapore, Hong Kong, and the United Arab Emirates. Transfers outside the European Economic Area, the United Kingdom, and Switzerland that are not the subject of an adequacy decision are subject to Standard Contractual Clauses, to the United Kingdom International Data Transfer Addendum, and to equivalent transfer mechanisms in other jurisdictions, as described in our Privacy Policy and our Data Processing Addendum.

5. Due Diligence We Apply To A Sub-Processor

Before we engage a Sub-processor, we perform due diligence appropriate to the category of Personal Data the Sub-processor will process and to the risk profile of the engagement. We require the Sub-processor to commit to data-protection obligations no less protective than those set out in our Data Processing Addendum and to the technical and organisational measures published on the Maven Pay Trust Center at https://app.vanta.com/mavenpay.com/trust/lyjdri3s8ydg4qnc4uuq1.

We re-review every Sub-processor on a periodic schedule and on every trigger event, including a change in the Sub-processor's services, a change in the relevant law, a security event, or a change in our own risk profile.

6. How We Communicate A Change

When we add or replace a Sub-processor, we give at least thirty days notice to customers under a Data Processing Addendum. A customer that reasonably objects on data-protection grounds within fifteen days of notification may invoke the resolution and termination rights set out in our Data Processing Addendum.

For customers that are not under a Data Processing Addendum, we update this page to reflect any change in category and we update the named list available on request. The thirty-day notice period and the objection right are reserved to Data Processing Addendum customers.

7. Contact

For the current named list, for a copy of the Standard Contractual Clauses applicable to a specific transfer, or for any question about this page, write to compliance@mavenpay.com.

8. Changes To This Page

We may update this page from time to time. When we make a material change, we will tell you in the MavenPay product or by email at least thirty days before the change takes effect. The current version of this page and its effective date are shown at the top of this page.

Behind The Rail

Built On A Regulated Canadian Rail

Money Service Business🇨🇦C1000000640FINTRAC-registered
Payment Service Provider🇨🇦Supervised By Bank Of CanadaVerify on Bank of Canada
Reach

Questions about this document? Reach compliance@mavenpay.com.

Document version effective 2026-06-08. Last updated 2026-06-08. Prior versions available on request.