This list identifies third parties involved in delivering HiringCoachAI. The core tables identify providers that process data on our behalf, for which we remain accountable. The user-connected calendar and meeting section separately identifies external services a coach directs HiringCoachAI to connect; inclusion in that section does not by itself mean the provider is a HiringCoachAI processor or sub-processor.
Advance notice of new sub-processors is available by request at [email protected].
This page identifies vendor names, purposes, data categories, locations, and high-level assurance posture. API keys, account IDs, DPA acceptance timestamps, dashboard screenshots, security runbooks, and credential locations remain internal.
Core infrastructure
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Google Cloud Platform / Firebase | Authentication, Firestore database, Cloud Storage for coach/client materials, chat attachments, profile images, account/resume files, backup/export buckets and Cloud Functions source, Cloud Tasks, Cloud Text-to-Speech | All user profile, content, session, audit, and user-uploaded material data; backup/export objects inherit source classification | US: Firestore live database in US multi-region; user-content and backup/export buckets in the configured US location; Cloud Functions source buckets in a US region | SOC 1/2/3, ISO 27001/17/18/701, Payment Card Industry Data Security Standard (PCI DSS), HIPAA, FedRAMP High |
| Vercel | Application hosting, Edge Middleware, Serverless Functions, AI Gateway, logs, and Vercel Analytics when analytics consent is granted | Request headers, execution logs, routed AI traffic, and consented site-level analytics telemetry after pageview query strings and fragments are removed | Global edge; primary US | SOC 2 Type II, ISO 27001 |
| Cloudflare | Public DNS, reverse proxy, CDN/security edge for hiringcoach.ai | DNS records, request metadata, IP addresses, HTTP headers for proxied traffic | Global edge | SOC 2 Type II, ISO 27001 |
Payments
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Stripe | Subscription billing, payment card processing (hosted Checkout and Elements / Payment Element) | Customer ID, email, payment token, subscription and billing-status metadata. No payment-card primary account number (PAN), card verification value (CVV), or card-track data touches HiringCoachAI. | US + EU | Payment Card Industry Data Security Standard (PCI DSS) Level 1, SOC 1/2, ISO 27001 |
Communications
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| SendGrid (Twilio) | Transactional email, notifications, verification messages, user-message delivery, and Twilio Programmable Messaging for consented non-promotional coaching SMS to U.S./Canadian recipients | Email sender/recipient addresses, subject and message body (including user communication content or a profile-review snapshot included in an email), and delivery events; for SMS, destination number, coach identity, message body, opt-out keyword, provider message ID and delivery status. The application requests Twilio body discard and destination-number obfuscation on each outbound text. | US | SOC 2 Type II, ISO 27001 |
| Mailchimp (Intuit) | Account/customer communications, communication-list management, and opt-in marketing email where applicable | Email, name, communication preferences | US | SOC 2 Type II |
| Google Workspace / Gmail | Transactional and support email routing, administrative profile-review notifications, hiring, and accommodation mailboxes | Sender/recipient addresses, subject, message body, replies, attachments where used, and delivery/routing metadata | US | SOC 2/3, ISO 27001 |
AI providers
We do not have separate Zero Data Retention (ZDR) agreements with any AI provider. Where a provider exposes per-request storage or transcript-exposure controls, our code sends them, and an automated check runs in local compliance checks and the scheduled/manual security workflow to verify covered OpenAI Chat Completions or Responses requests include store: false and Deepgram transcription requests include redact=true. These flags reduce provider-side storage or transcript exposure where supported, but they are not the same as a signed ZDR agreement. Each provider's then-current standard API retention windows otherwise apply. The no-training posture relies on each provider's then-current standard API terms; we have not signed separate enterprise no-training amendments.
| Sub-processor | Purpose | Data processed | Location | Retention |
|---|
| OpenAI (called both directly and via Vercel AI Gateway) | LLM generation and coach-profile content moderation | User prompts and completions; coach profile text, link fields, and photos submitted for moderation | US | Per-request store: false on OpenAI Chat Completions and Responses requests. No Zero Data Retention (ZDR) amendment: OpenAI's then-current standard API retention windows apply. |
| Perplexity AI | Research-backed company intelligence (optional) | Query text | US | Standard API terms; provider default retention applies. |
| ElevenLabs | Text-to-speech | Text to be spoken | US | Standard API terms; provider default retention applies. |
| Deepgram | Speech-to-text | Audio clips (user voice) | US | Per-request redact=true to redact sensitive number-like entities from transcripts, such as payment cards and Social Security numbers; provider default audio retention otherwise applies. |
| Google Cloud Text-to-Speech | Alternate TTS | Text | US | Standard API terms; provider default retention applies. |
Error monitoring and analytics
| Sub-processor | Purpose | Data processed | Consent |
|---|
| Sentry | Application error & performance monitoring, plus Vercel log drain destination | Stack traces, user IDs only where needed for debugging, request metadata after recursive event/log/trace URL scrubbing; Session Replay and automatic DOM screenshots disabled; no prompts/completions intentionally logged | Essential |
| Amplitude | Product analytics | Event data and session IDs; Session Replay and URL-bearing autocapture disabled | Analytics consent |
| Mixpanel | Product analytics | Event data; session recording disabled | Analytics consent |
| PostHog (PostHog Inc.) | Product analytics: event capture, funnels, and behavioral insights | Event names and properties (e.g. login_attempted, subscription_purchased, plan tier); stable user identifier (Firebase UID) and email attached only after analytics consent is granted; standard request metadata (IP, user-agent) | Analytics consent. Client-side SDK starts opted-out by default; capture begins only after analytics consent and is revoked live on consent withdrawal. Server-side transactional events from Stripe webhook and account-deletion confirmation fire under the corresponding lawful basis documented per-event in the data map. PostHog Inc., US-hosted; standard PostHog DPA applies. |
| Meta (Facebook) Conversions API | Server-side gift-flow conversion measurement; the client Meta Pixel is disabled | Gift conversion events and hashed identifiers | Marketing consent |
Developer productivity / integrations
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Mapbox | Geocoding and location display | Approximate location strings entered by user | US | SOC 2 Type II |
| LinkedIn | OAuth sign-in; profile import (with user consent) | LinkedIn profile fields, limited scope | US | SOC 2 Type II, ISO 27001 |
| Google OAuth / Drive | OAuth sign-in; folder-bounded Google Drive Materials mirror and export (opt-in) | Profile, email, and files or metadata inside the user-authorized HiringCoachAI folder; per-file user scope plus a dedicated principal shared only on that folder | US | SOC 1/2/3, ISO 27001 (Google Cloud parent) |
| Facebook OAuth | OAuth sign-in | Profile, email | US | SOC 2 Type II, ISO 27001 |
| Canva | Design asset import | File metadata | Australia + US | SOC 2 Type II, ISO 27001 |
User-connected calendar and meeting providers
Microsoft Graph / Outlook Calendar and Zoom require HiringCoachAI provider credentials plus coach authorization; Apple iCloud CalDAV requires a coach-supplied app-specific password. Each integration processes data only after the coach takes that connection step. Microsoft is classified as a user-authorized connected provider under its API and identity-platform developer terms, not as a HiringCoachAI processor or sub-processor. Zoom and Apple remain pending legal and Privacy Officer classification. This list does not claim that HiringCoachAI has executed or accepted a DPA with a connected provider unless its row expressly says so.
| Connected provider | Purpose | Data processed | Location | Contract / assurance status |
|---|
| Microsoft Graph / Outlook Calendar | Coach-authorized calendar discovery, conflict checks, and booking-event creation or deletion | OAuth authorization context; calendar IDs, names, and editability; event start/end and availability status for conflict checks; booking title, start/end, optional location, and attendee email only when invitations are enabled; OAuth request metadata and encrypted credentials | Provider-operated regions selected by Microsoft and the connected account | N/A user-authorized connected provider under the Microsoft APIs Terms and identity-platform developer Terms, which do not create a HiringCoachAI-Microsoft processor/sub-processor relationship. No Microsoft processor DPA or SCC coverage is claimed. Privacy Officer classification and publisher verification recorded 2026-08-10; publisher verification is an identity signal, not compliance certification. |
| Zoom | Coach-authorized creation and cancellation of per-booking meeting links | Connected coach Zoom account identity; meeting topic, start time, duration, meeting ID, attendee join URL, and OAuth request metadata | Provider-operated regions selected by Zoom and the connected account | Zoom Marketplace/developer terms apply; controller/processor role, DPA coverage, production app review, and account-specific terms evidence are pending production legal/vendor review |
| Apple iCloud CalDAV | Coach-authorized calendar discovery, conflict checks, and booking-event creation or deletion | Coach Apple Account email, app-specific password, CalDAV server and calendar paths, free/busy event intervals, and event start/end, title, and description | Provider-operated regions selected by Apple and the connected account | The coach's iCloud terms govern their account; controller/processor role, DPA availability, and HiringCoachAI's permitted production access posture are pending legal/vendor review |
Platform
| Sub-processor | Purpose | Location |
|---|
| GitHub | Source-code hosting and CI | US |
| Domain registrar + DNS | Domain and DNS management | US |
Historical / removed
| Date | Integration | Reason |
|---|
| 2026-07-29 | Hotjar (Contentsquare) client SDK | Runtime initialization and session capture removed because URL metadata could not be safely suppressed. The installed package is dormant and sends no production data. |
| 2026-07-29 | Google Analytics / Google Tag Manager (GTM), including container-loaded LinkedIn Insight tags | Client container loading removed because vendor-managed tags could read query-backed product URLs. |
| 2026-07-29 | Meta Pixel client SDK | Browser PageView collection removed because the vendor SDK derives the full current URL. The server-side gift-flow Conversions API remains listed above. |
How to object
Per our Privacy Policy, you may object to specific processing. Contact [email protected]. Some sub-processors (payments, identity, infrastructure) are essential to the service; we cannot provide the service without them. For others (analytics, marketing), you can opt out via the cookie banner or your account settings.
Change log
| Date | Change |
|---|
| 2026-08-10 | Classified Microsoft Graph / Outlook Calendar as a user-authorized connected provider, corrected its exact read/write data scope, recorded no Microsoft processor DPA/SCC claim, and separated connected providers from HiringCoachAI sub-processors. |
| 2026-07-29 | Disabled Hotjar, GTM/GA/LinkedIn Insight browser tags, the client Meta Pixel, Sentry automatic DOM screenshots, and URL-bearing replay; added recursive URL scrubbing for remaining browser telemetry. |
| 2026-07-27 | Added conservative coverage for coach-connected Microsoft Graph / Outlook Calendar, Zoom, and Apple iCloud CalDAV integrations; no executed DPA or final controller/processor classification is claimed pending legal and vendor review. |
| 2026-07-24 | Added Twilio Programmable Messaging scope, SMS data categories, geographic limitation, and provider-redaction requests. |
| 2026-07-16 | Documented full transactional-email content, Google Workspace / Gmail communication routing, and OpenAI coach-profile moderation. |
| 2026-04-24 | Initial publication |
| 2026-05-11 | Confirmed /sub-processors renders from this canonical markdown source and added public-safety note. |
| 2026-05-17 | Added PostHog (PostHog Inc., US) as a product-analytics sub-processor. Client-side SDK is opted-out by default and gated through the analytics consent category. |