Subprocessors

Last updated: 18 August 2026

These are the service providers Swimo.fit uses to run the platform — the companies that process some of your club’s information on our behalf. This page is the complete, current list: what actually reaches each provider, and why. It is the list our Data Processing Addendum authorises, and the same table appears in our Privacy Policy.

The current list

ProviderWhat reaches themWhy
Google Cloud PlatformEverything. The application runs on Cloud Run and the database is Cloud SQL for PostgreSQL, so all of the data described in the Privacy Policy lives on Google's infrastructure. Server logs go to Cloud Logging; credentials and signing keys are held in Secret Manager; container images in Artifact Registry.Hosting, database, logging, and secret storage.
Firebase AuthenticationYour email address, your sign-in identity, and a session token. Also the identity provider you chose.Signing you in and verifying every request. We never store your password ourselves.
Firebase StoragePhotos and videos you upload, video thumbnails, and profile pictures.Storing media for technique submissions and feedback, posts, and profiles.
Cloud FirestoreOnly tiny 'something changed' markers: a club identifier, a topic name such as 'calendar' or 'posts', a timestamp, and sometimes an opaque identifier (which session an attendance update belongs to). No message text, no names, no email addresses, no swimmer records, no media. Clients can read only their own club's markers and can never write.Telling apps that are open to refresh. PostgreSQL remains the only store of actual content.
Google Sign-InIf you choose it: the fact you signed in, and the email address and name on your Google account.An optional sign-in method.
Apple Sign-InIf you choose it: the fact you signed in, and the email address (or Apple's private relay address) and name you release to us.An optional sign-in method on iOS.
ResendThe recipient's email address and the full contents of each notification email, which includes the sender's name, the swimmer's name, and an excerpt of a technique submission's note, a coach's written feedback, or a post. Sent from noreply@invitation.swimo.fit.Delivering invitation and notification email.
Apple Push Notification serviceYour device's push token, and the notification's title and body, which contains an excerpt of a technique submission's note, a coach's written feedback, or a post that triggered it.Delivering push notifications to iPhones and iPads.
Firebase Cloud Messaging (Google)The same push token, title, and body, for Android devices.Delivering push notifications on Android.
Google Maps PlatformVenue and event addresses you type, and the coordinates they resolve to. Address autocomplete runs in your browser and talks to Google directly.Turning an address you type into a suggestion and a set of coordinates.
Google Weather APIVenue coordinates and the times of upcoming sessions. No personal details.Pool conditions on the dashboard and storm watch/warning alerts.
Google FontsYour browser's IP address and user agent, because the web app loads its typeface from Google's font servers.Web typography.
Apple (App Store)Whatever Apple collects when you download or update the mobile app, under Apple's own privacy policy. We do not receive it.Distributing the iOS app.

How this list changes

This is a living list. When we intend to swap or add a provider that will process club personal information, we update this page and tell clubs by email before the change takes effect where we reasonably can. Clubs have a right to object, as set out in section 5 of the Data Processing Addendum.

We remain responsible for the providers we use: each one is bound by a contract imposing data-protection obligations materially equivalent to our own. We do not sell personal information and we do not share it for advertising.

Questions

Questions about this list, from clubs or their advisers: info@swimo.fit.