Subprocessors and Service Providers
Last updated: August 4, 2026
The providers below may process information on our behalf or receive information when you or an Account Owner uses the relevant feature. The categories describe the information the application sends or makes available to each provider based on the current source code. Optional providers receive information only when the relevant feature is enabled or used. This list may change as providers or features change, subject to any notice required by law or contract.
Convex
Function: Database and backend hosting for CRM records, authentication-linked application data, and server functions.
Data categories: Account, team, customer, contact, scheduling, billing, message, voice, file, location, integration, and operational records stored in the application.
Clerk
Function: Authentication and account identity management.
Data categories: Names, email addresses, profile and authentication identifiers, session information, and sign-in provider data.
Stripe
Function: Platform subscriptions, customer payments, billing, and payment-device services.
Data categories: Payment and billing details, customer identifiers, transaction and invoice data, and Stripe account or payment-method identifiers; full card numbers are handled by Stripe rather than stored by the application.
Railway
Function: Application hosting where configured for a deployment.
Data categories: Application runtime, request, and operational data processed by the hosted application. Production use of Railway depends on deployment configuration.
Cloudflare
Function: R2 file and object storage plus application-edge, CDN, Bot Fight Mode, and WAF services.
Data categories: Uploaded photos, documents, attachments, signatures, PDFs, voice recordings, and other stored files; request IP addresses, headers, URLs, and security or traffic metadata processed at the application edge.
Twilio
Function: SMS/MMS delivery and inbound messaging.
Data categories: Sender and recipient mobile numbers, SMS/MMS message content and media metadata, delivery status, message identifiers, and account or webhook metadata. The registered application routes do not currently send voice calls or call recordings to Twilio.
Resend
Function: Email delivery, including transactional messages and Account Owner-created campaign and drip messages.
Data categories: Recipient email addresses, subjects, message bodies, rendered template output, attachments when used, and delivery or engagement metadata.
Axiom
Function: Application log and event storage.
Data categories: Redacted request and event metadata, account and organization identifiers, counts and timing or performance data, and redacted error context emitted by the application. Sensitive phone, email, token, address, transcript, and payment fields are replaced with a redaction marker before ingestion.
Sentry
Function: Error, performance, replay, and reliability diagnostics.
Data categories: Redacted application error and performance data, stack traces, request/device/browser metadata, wide-event breadcrumbs, mobile user or account context, and replay data when Sentry is configured. Sensitive event fields and user email addresses are replaced with a redaction marker while operational identifiers and counts are retained.
Inngest
Function: Background job and workflow execution.
Data categories: Workflow event payloads, record identifiers, and data needed for notifications, billing, voice, booking, and synchronization jobs.
Upstash Redis
Function: Rate limiting and request-protection services.
Data categories: Raw portal access tokens used as Redis keys, user and organization identifiers used as keys, IP addresses, rate-limit counters, and request-protection metadata.
OpenAI
Function: AI features, including live voice conversations, onboarding assistance, transcription, intent parsing, generation of CRM tool requests, message generation, and document/image upload and extraction.
Data categories: Live or stored microphone audio and voice conversations; transcripts; prompts and conversation content; CRM tool requests and results; contact names and other identifiers; account and profile information; job notes and descriptions; uploaded document images and PDFs; bulk customer and business records extracted from those documents, including names, contact details, addresses, account information, invoices, job information, and other records contained in the documents; and text submitted for or generated by AI features.
Google Maps Platform
Function: Address autocomplete, maps, routing, and route optimization.
Data categories: Addresses, customer or job coordinates, route stops, and mapping or routing request data.
Google Calendar
Function: Optional calendar connection and synchronization.
Data categories: Google account and calendar identifiers, OAuth tokens, event details, and appointment-related data.
Google identity sign-in
Function: Optional Google identity sign-in on mobile.
Data categories: Identity and profile information, authentication responses, and account identifiers returned through Google sign-in.
GoHighLevel/LeadConnector
Function: Optional CRM contact synchronization.
Data categories: Integration credentials or tokens and synchronized contact data: contact names, email addresses, phone numbers, company names, tags/source values, and GoHighLevel/Humboldt contact mapping identifiers.
QuickBooks/Intuit
Function: Optional accounting integration for contacts, invoices, estimates, expenses, and time entries.
Data categories: Integration credentials or tokens; contact and billing-address data; invoices and estimates with customer references, amounts, currencies, and line items; expenses/purchases with vendor, account, category, notes, and amounts; and time-entry data with employee references, hours, dates, and notes.
Expo
Function: Optional mobile push-notification delivery.
Data categories: Device push tokens, app/device metadata, and notification payloads.
OpenStreetMap
Function: Map embeds on public tracking pages.
Data categories: Tracking-page coordinates and browser/request metadata needed to load the map embed.
Apple
Function: Sign in with Apple and optional Apple Maps navigation.
Data categories: Identity and profile information used for Apple sign-in, and customer or job destination coordinates when Apple Maps is selected.
Apple Speech framework / Google Speech Recognition (device-dependent)
Function: Mobile speech recognition through the operating system speech service selected by the device.
Data categories: Microphone audio and interim or final transcripts; on-device mode may process audio locally, while network mode sends audio to Apple Speech, Google Speech Recognition, or another speech service selected by the device.
unpkg
Function: Public API documentation asset delivery.
Data categories: Browser and network request metadata associated with loading Swagger UI assets; the application code does not send CRM records to unpkg.