How to read this register
This register names third-party services that may receive customer or public-site visitor data through Nebula. It includes Nebula-appointed, browser-direct and customer-directed paths without deciding their legal classification. A location is stated only where Nebula's repository evidence establishes it. Provider regions, legal entities, roles and contractual safeguards must be confirmed for the intended customer deployment and recorded in the applicable agreement before this draft is treated as the operative public register.
Provider paths in the reviewed evidence
| Provider | Evidence status | Purpose | Data categories | Location position |
|---|---|---|---|---|
| Vercel | Live hosting verified on 26/07/2026. The application compute region remains a source configuration claim. | Application hosting, configured Sydney compute and scheduled functions. | Requests and responses, account and session context, server-processed application payloads, source documents and extracted text handled by workers, generated files, service metadata and platform logs. | Application compute is configured for syd1, Sydney. Current runtime region, edge, control-plane, support, telemetry and log-processing locations are not established. |
| Neon | Last evidenced configured in the repository-held production review dated 16/05/2026. Current activation not verified. | Managed PostgreSQL for structured operational records. | Account, organisation, engagement, audit, integration, billing and operational records. | The application uses managed PostgreSQL. The production project region is not established by repository-held configuration or signed provider terms. |
| Cloudflare | Last evidenced configured in the repository-held production review dated 16/05/2026. Current activation not verified. | R2 object storage for documents and files. | Source documents, evidence files, generated files and application-managed object metadata. | The application uses the R2 automatic region setting. The production bucket location is not established by code. |
| Resend | One fresh production signup verification message was recorded as sent and delivered by Resend and reached Gmail Inbox on 26/07/2026. The sending domain, DKIM and SPF were verified and no suppressions were shown. The link was not clicked. Continuing delivery health and post-verification account state remain unverified. | Transactional email, support and contact-message delivery. | Recipient and sender details, internal user identifier, complete message content, account links, support and contact content, engagement details, operational notices, payment summaries and delivery metadata. | The applicable processing locations are not established by code or signed provider terms in the repository. |
| Google Analytics 4 and linked Google Ads | Google Analytics operates on the public surface after consent, with one live page view verified on 26/07/2026. Current source keeps only the five disclosed UTM campaign fields on static marketing page locations and maps record-specific values in the manual call's page-path, page-location and same-origin page-referrer fields. A local browser test proves the real contact call site queues one lead event after a grant and none after a refusal. No retained post-fix production request, deployment check or Analytics account export establishes provider ingestion or the complete provider-generated event boundary. The Google Ads product link is completed. Dated console evidence records lead_submitted as the primary Submit lead form conversion with status Awaiting conversions, property-level ads personalisation allowed in 0 of 307 regions, and Google signals off. | Public website usage and consent-gated conversion measurement, with a configured Google Ads relationship for advertising conversion measurement. Analytics data is disallowed for personalised advertising at the property level. Signup event calls exist outside the tagged public surface and their delivery is not established. The owner published the Search campaign and immediately paused it. A fresh read showed it Paused with its A$50.00 average daily budget unchanged, and the immediate overview showed zero impressions, clicks, conversions and cost before the pause. Future campaign delivery and spend remain unverified. | The manual page-view call sends a static route or route class in the page-path field, the origin and that same path in the page-location field, and a reduced same-origin referrer or unchanged external referrer in the page-referrer field. On static marketing pages only, page-location can also carry utm_source, utm_medium, utm_campaign, utm_term and utm_content; other query values are removed. Google also receives ordinary browser request metadata and can add fields. Implemented event values include lead form type, enquiry category, signup context and requested plan, and a founding workspace-presence flag, remaining-place count and programme duration. The current source mapping excludes record-specific tokens, organisation identifiers, anchor identifiers, ABNs and block heights from the page-path and page-location fields, and from the page-referrer field when the referrer is within Nebula. The primary conversion is the lead_submitted GA event, whose implemented parameters are form type and enquiry category. A local browser test proves browser dispatch after consent, but real provider ingestion is unverified. Separate funnel-event parameters do not explicitly include names, email addresses, free-text messages, passwords, documents, organisation names, account identifiers or engagement content. Complete fields added by Google, provider-generated page views and the exact data made available through the link or conversion are not established. Source leaves advertising storage, advertising user data and advertising personalisation denied when analytics storage is granted. Property-level ads personalisation is allowed in 0 of 307 regions and Google signals is off, but the complete linked-service data boundary is not established. | The Analytics property reports Australia as its country and Australia/Sydney as its timezone. The linked Ads account records Australia, Australian dollars and Brisbane time. These are not processing-region evidence. The legal entity, role, processing and support locations, retention, transfer position and applicable signed terms remain unverified. |
| Google Calendar appointment scheduling | The owner observed a live public schedule on 27/07/2026, and current source links the Business and Enterprise pricing actions to it. No completed attendee booking or deployed pricing-path walk was retained for this review. | Owner-operated, Google-hosted public appointment scheduling linked from Nebula for Business and Enterprise introduction requests. This is separate from customer-selected Google identity and Google Workspace integrations. | A visitor's browser supplies the client IP address and ordinary request metadata when the external page is opened. The Google-hosted appointment page collects attendee name, email address and selected appointment time. The observed schedule was configured for calendar invitations and updates by email and Google Meet generation, but no completed booking, resulting email, calendar event or Meet link was observed end to end. | The schedule uses Australia/Sydney for appointment display and availability. That setting does not establish a processing region. The Google account type, contracting legal entity, legal role, processing, support and backup locations, retention, deletion, transfer position and applicable signed terms are not established. Booking-specific procurement approval and privacy effective-date treatment remain open. |
| Anthropic | Last evidenced configured in the repository-held production review dated 16/05/2026. Current activation not verified. | Document intelligence through Nebula's sanctioned AI boundary. | System instructions, extracted document text, file names, engagement context, model output and complete PDFs for native document calls. | No processing region is pinned in code. Provider terms and transfer safeguards must be confirmed for the customer scope. |
| ipapi.co | Implemented browser-direct code path. Current deployment use not verified. | Browser-direct approximate network location for the authenticated dashboard weather display. | Client IP address and ordinary request metadata. The response can include approximate latitude, longitude and city. | No region is pinned in code. Provider entity, terms, retention, processing locations and legal classification require confirmation. |
| Open-Meteo | Implemented browser-direct code path. Current deployment use not verified. | Browser-direct city geocoding and current weather for approximate coordinates. | Client IP address, ordinary request metadata, approximate coordinates and a saved, entered or timezone-derived city name. | No region is pinned in code. Provider entity, terms, retention, processing locations and legal classification require confirmation. |
| Stripe | Test-mode hosted Checkout and server-side reconciliation operated against the production deployment on 26/07/2026. The active production webhook endpoint and 11 event subscriptions were recorded. A signing-secret mismatch was corrected in Vercel Production and the redeploy reached Ready. Stripe showed no event deliveries, so live-money mode and end-to-end webhook delivery remain unverified. | Hosted subscription checkout, founding payments, Orbits top-ups, billing portal, payment reconciliation, invoices and refunds when configured. | Organisation, product, price and checkout-intent identifiers; mode, amount and currency; Orbits, founding and discount metadata; provider-issued customer, checkout, subscription, payment, invoice, charge and refund identifiers; and billing status. The retained hosted test collected a payer name and payment-card details directly on Stripe's surface. An email address may also be collected there. Current non-test callers do not pass a customer email from Nebula code. | The applicable processing locations, contracting entity, signed terms and transfer position are not established by repository evidence. |
Configuration-dependent providers
| Provider | Activation condition | Data categories | Evidence position |
|---|---|---|---|
| Fly.io | Used for the Nebula-operated proof gateway in the last repository-held production review, dated 16/05/2026. | Signed canonical proof events, internal identifiers, event details, evidence hashes and signatures. Source document files are not included. | The current production gateway, hosting region and contractual boundary require confirmation. |
| Sentry | Used only when a Sentry DSN is configured. | Application error, request and diagnostic context selected by the configured telemetry path. | The last repository-held production review, dated 16/05/2026, recorded Sentry DSNs as unset. |
| Upstash | Used only when shared Redis-backed rate limiting is configured. | Rate-limit keys and counters. A key can include the caller identifier supplied by the protected route, including an IP address, user identifier or organisation identifier. | The application otherwise uses an in-process rate-limit store. |
| Alchemy or another selected Polygon JSON-RPC provider | Used only when public Polygon proof submission is configured. | Proof commitments and transaction metadata. Source documents are not submitted. | The code defaults to an Alchemy Polygon Amoy demo endpoint when no Polygon RPC URL is supplied. The selected production provider is not identified by repository-held configuration. |
AI provider boundary
Nebula's model registry is provider-neutral and multi-model. This draft lists Anthropic because it is the last AI provider evidenced as configured to process customer data. A customer-specific deployment must confirm the provider and model available before use.
Customer-directed and user-initiated services
Customer-selected identity and connected services, including Microsoft Entra ID, Microsoft 365, Google identity, Google Workspace, authorised business-system integrations and external webhooks, are assessed for the customer deployment. Polygonscan is opened only when a user follows a public transaction link. A service may be the customer's own provider, an independent controller, an external destination or a Nebula subprocessor depending on the contractual arrangement.
| Service | Purpose | Data categories |
|---|---|---|
| Microsoft Entra ID and Microsoft 365 | Customer-selected sign-in, directory, SCIM, SharePoint, Outlook and Teams connections. | Identity claims, directory records and customer-authorised service metadata or content within granted scopes. |
| Google identity and Google Workspace | Customer-selected sign-in, directory, SCIM, Drive, Gmail, Calendar and Chat connections. | Identity claims, directory records and customer-authorised service metadata or content within granted scopes. |
| Xero | Customer-authorised finance and time-entry integration. | Tenant, invoice, payment, project and time-entry data within granted scopes. |
| QuickBooks Online | Customer-authorised finance and time-activity integration. | Realm, invoice, payment and time-activity data within granted scopes. |
| MYOB | Customer-authorised company-file, invoice and timesheet integration. | Company, invoice, timesheet and authorised identity data within granted scopes. |
| Procore | Customer-authorised project and construction-system integration. | Project, company, document, field, labour, time and cost data within granted access. |
| Oracle Aconex | Customer-authorised project, document and correspondence integration. | Project, organisation, document revision and correspondence data within granted access. |
| Customer-configured webhook endpoint | Organisation-selected delivery of subscribed project events to an external HTTPS endpoint. | Event type and time, project and record identifiers, status and action details, and event-specific file, payment, dispute, notification or user data. |
| Polygonscan | User-initiated inspection of a public Polygon transaction in a third-party block explorer. | Client IP address, ordinary request metadata and the public transaction hash in the URL. Source documents are not sent by Nebula. |
Public proof networks
Polygon submission is configuration-dependent and was not substantiated as active by the last repository-held production review. When enabled, Nebula publishes a SHA-256 commitment and transaction metadata rather than the source document. A confirmed public-network record cannot be removed by Nebula.
Changes and questions
Any applicable data processing agreement must set advance notice and objection rights for a new subprocessor. No notice period is established by this draft. The version history for this register is retained in Nebula's source control. Privacy and procurement questions can be sent to privacy@nebulaplatform.com.au.
Review Nebula's security and data handling statement for the related control posture.
Version history
- Version 0.7
- 27/07/2026
- Added the owner-operated Google Calendar appointment path linked from Nebula after the owner observed the live schedule and current source linked Business and Enterprise pricing actions to it. A completed attendee booking, signed provider terms, legal classification, processing location, retention position, transfer position and procurement approval remain unverified. The direct path preceded its register entry and booking-specific provider review.
- Version 0.6
- 26/07/2026
- Reconciled the observed ads privacy controls and paused campaign state, plus the later Stripe price-mapping and Team Checkout evidence. Production Analytics payload evidence, provider-generated page-view behaviour, Business Checkout, mapping audit rows, live mode, real webhook delivery, real conversion ingestion and provider checks remain open.
- Version 0.5
- 26/07/2026
- Reconciled current source and retained evidence dated 26/07/2026 for Analytics, Google Ads, Resend and Stripe, including the saved-draft owner handoff. Production payload evidence, provider-generated page-view behaviour, continuing email health, real Stripe delivery, real conversion ingestion and provider checks remain open.
- Version 0.4
- 26/07/2026
- Recorded the deployed route-class mapping for the explicit page-path field and the residual automatically collected page-location and referrer boundary. Complete route control, linked-service evidence and provider checks remain open.
- Version 0.3
- 26/07/2026
- Reconciled Google Analytics 4, linked Google Ads, Vercel, Resend and Stripe against current source and dated production evidence. The analytics route control, linked-service data boundary and provider terms, region, retention and legal-classification checks remain open.
- Version 0.2
- 25/07/2026
- Code-derived provider register, including browser-direct weather services and customer webhooks.