Sub-processors

Last reviewed 2026-04-24

We engage the third parties listed below ("sub-processors") to help us operate HiringCoach.ai. Each is bound by a Data Processing Agreement. To subscribe to advance notice of changes, email [email protected].

Core infrastructure

Sub-processorPurposeData processedRegion
Google Cloud / FirebaseAuthentication, database, file storage, background tasks, text-to-speechAll user profile, content, session, and audit dataUS (default)
VercelApplication hosting, edge middleware, serverless functions, AI Gateway, logsRequest headers, execution logs, routed AI trafficGlobal edge; primary US

Payments

Sub-processorPurposeData processedRegion
StripeSubscription billing, card processing (hosted)Customer ID, email, subscription metadata. No card PAN touches HiringCoach.US + EU

Communications

Sub-processorPurposeData processedRegion
SendGrid (Twilio)Transactional emailRecipient email, send metadata, bounce / complaint recordsUS
Mailchimp (Intuit)Opt-in marketing emailEmail, marketing consent, preferencesUS

AI providers

Sub-processorPurposeData processedRegion
OpenAILLM generation (called directly and via Vercel AI Gateway)User prompts and completions; per-request store: false. Standard OpenAI API retention applies (no ZDR amendment).US
PerplexityResearch-backed intelligenceQuery text. Provider default retention applies.US
ElevenLabsText-to-speechText to be spoken. Provider default retention applies.US
DeepgramSpeech-to-textAudio clips (user voice); per-request redact=true. Provider default retention applies.US
Google Cloud TTSAlternate text-to-speechText. Provider default retention applies.US

Error monitoring and analytics

Sub-processorPurposeData processedRegion
SentryError and performance monitoringStack traces, hashed user IDs (PII scrubbed)US
AmplitudeProduct analyticsEvent data, session IDsUS
MixpanelProduct analyticsEvent dataUS
HotjarHeatmaps and session insightsSession recordings with input maskingEU
Google Analytics / GTMWeb analyticsPage views, eventsUS / EU
Meta Pixel (Facebook)Conversion measurementHashed identifiers, conversion eventsUS

Integrations and platform

Sub-processorPurposeData processedRegion
MapboxGeocoding and mapsLocation strings you enterUS
LinkedInOAuth sign-in; profile import with your consentLinkedIn profile fieldsUS
Google OAuthOAuth sign-in; Google Drive export (opt-in)Profile and email; Drive scope only when you grant itUS
Facebook OAuthOAuth sign-inProfile and emailUS
Canva (optional)Design asset importFile metadataUS
GitHubSource-code hosting and CINo customer production dataUS
Domain registrar + DNSDomain and DNS managementNo customer dataUS

How to object

Per our Privacy Policy, you may object to specific processing. Contact [email protected]. Some sub-processors (payments, identity, infrastructure) are essential to the service; we cannot provide the service without them. For analytics and marketing, you can opt out via the cookie banner or your account settings.

showUpgradeModal: false, modalType: migration, planName: