Sub-processors
Effective 14 August 2026
These are the companies that can hold or handle data on our behalf, and exactly what reaches each one. We give 30 days notice by email before adding or replacing any of them, as described in the Data Processing Addendum.
| Provider | What it does for us | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | All workspace data, account emails, uploaded logos | United States (AWS us-east-1) |
| Vercel | Application hosting and content delivery | Requests in transit, IP addresses in server logs | United States and global edge network |
| Stripe | Subscription billing | Billing email, payment details entered on Stripe's own pages | United States |
| Resend | Transactional email (invitations, account email) | Recipient email address, workspace name, inviter email | United States |
| Anthropic | Optional AI setup suggestions | Only the business description an admin types into the setup box. No contact, work, or note records are ever sent. | United States |
| Optional two-way calendar sync, only if a user connects it | Titles, times, locations and notes of that user's own appointments and dated tasks | United States and global |
Services you turn on yourself
These are not our sub-processors. They receive data only because you connected them, and you can disconnect them at any time from Settings.
- Slack
- Discord
- Telegram
- Zapier, Make, n8n or any other endpoint reached through the Webhooks card
What each one receives depends on the events you subscribe it to. A channel notification typically contains the record title and the name of the event, for example that a new customer was added.
Getting notified of changes
Notice goes to the email address on your account. If you would like it sent somewhere else, such as a compliance mailbox, tell us at legal@crmniche.com.