This list identifies third parties involved in delivering HiringCoachAI. The core tables identify providers that process data on our behalf, for which we remain accountable. The user-connected calendar and meeting section separately identifies external services a coach directs HiringCoachAI to connect; inclusion in that section does not by itself mean the provider is a HiringCoachAI processor or sub-processor.
Advance notice of new sub-processors is available by request at [email protected].
This page identifies vendor names, purposes, data categories, locations, and high-level assurance posture. API keys, account IDs, DPA acceptance timestamps, dashboard screenshots, security runbooks, and credential locations remain internal.
Core infrastructure
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Google Cloud Platform / Firebase | Authentication, Firestore database, Cloud Storage for coach/client materials, chat attachments, profile images, account/resume files, backup/export buckets and Cloud Functions source, Cloud Tasks, Cloud Text-to-Speech | All user profile, content, session, audit, and user-uploaded material data; backup/export objects inherit source classification | US: Firestore live database in US multi-region; user-content and backup/export buckets in the configured US location; Cloud Functions source buckets in a US region | SOC 1/2/3, ISO 27001/17/18/701, Payment Card Industry Data Security Standard (PCI DSS), HIPAA, FedRAMP High |
| Vercel | Application hosting, Edge Middleware, Serverless Functions, AI Gateway, logs, and Vercel Analytics when analytics consent is granted | Request headers, execution logs, routed AI traffic, and consented site-level analytics telemetry after pageview query strings and fragments are removed | Global edge; primary US | SOC 2 Type II, ISO 27001 |
| Cloudflare | Public DNS, reverse proxy, CDN/security edge for hiringcoach.ai | DNS records, request metadata, IP addresses, HTTP headers for proxied traffic | Global edge | SOC 2 Type II, ISO 27001 |
Payments
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Stripe | Subscription billing, payment card processing (hosted Checkout and Elements / Payment Element) | Customer ID, email, payment token, subscription and billing-status metadata. No payment-card primary account number (PAN), card verification value (CVV), or card-track data touches HiringCoachAI. | US + EU | Payment Card Industry Data Security Standard (PCI DSS) Level 1, SOC 1/2, ISO 27001 |
Communications
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| SendGrid (Twilio) | Transactional email, notifications, verification messages, user-message delivery, and Twilio Programmable Messaging for consented non-promotional coaching SMS to U.S./Canadian recipients | Email sender/recipient addresses, subject and message body (including user communication content or a profile-review snapshot included in an email), and delivery events; for SMS, destination number, coach identity, message body, opt-out keyword, provider message ID and delivery status. The application requests Twilio body discard and destination-number obfuscation on each outbound text. | US | SOC 2 Type II, ISO 27001 |
| Mailchimp (Intuit) | Account/customer communications, communication-list management, and opt-in marketing email where applicable | Email, name, communication preferences | US | SOC 2 Type II |
| Google Workspace / Gmail | Transactional and support email routing, administrative profile-review notifications, hiring, and accommodation mailboxes | Sender/recipient addresses, subject, message body, replies, attachments where used, and delivery/routing metadata | US | SOC 2/3, ISO 27001 |
AI providers
We do not have separate Zero Data Retention (ZDR) agreements with any AI provider. Where a provider exposes per-request storage or transcript-exposure controls, our code sends them, and an automated check runs in local compliance checks and the scheduled/manual security workflow to verify covered OpenAI Chat Completions or Responses requests include store: false and Deepgram transcription requests include redact=true. These flags reduce provider-side storage or transcript exposure where supported, but they are not the same as a signed ZDR agreement. Each provider's then-current standard API retention windows otherwise apply. The no-training posture relies on each provider's then-current standard API terms; we have not signed separate enterprise no-training amendments.
| Sub-processor | Purpose | Data processed | Location | Retention |
|---|
| OpenAI (called both directly and via Vercel AI Gateway) | LLM generation and coach-profile content moderation | User prompts and completions; coach profile text, link fields, and photos submitted for moderation | US | Per-request store: false on OpenAI Chat Completions and Responses requests. No Zero Data Retention (ZDR) amendment: OpenAI's then-current standard API retention windows apply. |
| Perplexity AI | Research-backed company intelligence (optional) | Query text | US | Standard API terms; provider default retention applies. |
| ElevenLabs | Text-to-speech | Text to be spoken | US | Standard API terms; provider default retention applies. |
| Deepgram | Speech-to-text | Audio clips (user voice) | US | Per-request redact=true to redact sensitive number-like entities from transcripts, such as payment cards and Social Security numbers; provider default audio retention otherwise applies. |
| Google Cloud Text-to-Speech | Alternate TTS | Text | US | Standard API terms; provider default retention applies. |
Error monitoring and analytics
| Sub-processor | Purpose | Data processed | Consent |
|---|
| Sentry | Application error & performance monitoring, plus Vercel log drain destination | Stack traces, user IDs only where needed for debugging, request metadata after recursive event/log/trace URL scrubbing; Session Replay and automatic DOM screenshots disabled; no prompts/completions intentionally logged | Essential |
| Google Analytics 4 | Basic site traffic measurement and, after Analytics consent, fuller analytics measurement | By default: query-free page location and referrer, denied consent state, random per-page value, and standard network metadata such as timestamp, IP address, and browser user agent. No analytics cookies, persistent identifiers, Google signals, ad personalization, or behavioral events before Analytics consent. | Legitimate interest for limited cookieless page counts. Analytics consent for analytics storage and detailed measurement. Direct app-owned gtag.js; GTM and container-loaded marketing tags remain disabled. |
| Amplitude | Product analytics | Event data and session IDs; Session Replay and URL-bearing autocapture disabled | Analytics consent |
| Mixpanel | Product analytics | Event data; session recording disabled | Analytics consent |
| PostHog (PostHog Inc.) | Product analytics: event capture, funnels, and behavioral insights | Event names and properties (e.g. login_attempted, subscription_purchased, plan tier); stable user identifier (Firebase UID) and email attached only after analytics consent is granted; standard request metadata (IP, user-agent) | Analytics consent. Client-side SDK starts opted-out by default; capture begins only after analytics consent and is revoked live on consent withdrawal. Server-side transactional events from Stripe webhook and account-deletion confirmation fire under the corresponding lawful basis documented per-event in the data map. PostHog Inc., US-hosted; standard PostHog DPA applies. |
| Meta (Facebook) Conversions API | Server-side gift-flow conversion measurement; the client Meta Pixel is disabled | Gift conversion events and hashed identifiers | Marketing consent |
Developer productivity / integrations
| Sub-processor | Purpose | Data processed | Location | Certifications |
|---|
| Mapbox | Geocoding and location display | Approximate location strings entered by user | US | SOC 2 Type II |
| LinkedIn | OAuth sign-in; profile import (with user consent) | LinkedIn profile fields, limited scope | US | SOC 2 Type II, ISO 27001 |
| Google OAuth / Drive | OAuth sign-in; folder-bounded Google Drive Materials mirror and export (opt-in) | Profile, email, and files or metadata inside the user-authorized HiringCoachAI folder; per-file user scope plus a dedicated principal shared only on that folder | US | SOC 1/2/3, ISO 27001 (Google Cloud parent) |
| Facebook OAuth | OAuth sign-in | Profile, email | US | SOC 2 Type II, ISO 27001 |
| Canva | Design asset import | File metadata | Australia + US | SOC 2 Type II, ISO 27001 |
User-connected calendar and meeting providers
Microsoft Graph / Outlook Calendar and Zoom require HiringCoachAI provider credentials plus coach authorization; Apple iCloud CalDAV requires a coach-supplied app-specific password. Each integration processes data only after the coach takes that connection step. Granola MCP uses per-user browser OAuth and its active workspace, while the separate REST API and REST webhook path remains an optional advanced Business or Enterprise path. OAuth does not grant REST API or webhook access, and MCP does not send or receive webhook notifications. Standard Dynamic Client Registration browser OAuth does not require a client secret or a traditional app-registration portal. Microsoft is classified as a user-authorized connected provider under its API and identity-platform developer terms, not as a HiringCoachAI processor or sub-processor. Zoom, Apple, and Granola remain pending legal and Privacy Officer classification. This list does not claim that HiringCoachAI has executed or accepted a DPA with a connected provider unless its row expressly says so.
| Connected provider | Purpose | Data processed | Location | Contract / assurance status |
|---|
| Microsoft Graph / Outlook Calendar | Coach-authorized calendar discovery, conflict checks, and booking-event creation or deletion | OAuth authorization context; calendar IDs, names, and editability; event start/end and availability status for conflict checks; booking title, start/end, optional location, and attendee email only when invitations are enabled; OAuth request metadata and encrypted credentials | Provider-operated regions selected by Microsoft and the connected account | N/A user-authorized connected provider under the Microsoft APIs Terms and identity-platform developer Terms, which do not create a HiringCoachAI-Microsoft processor/sub-processor relationship. No Microsoft processor DPA or SCC coverage is claimed. Privacy Officer classification and publisher verification recorded 2026-08-10; publisher verification is an identity signal, not compliance certification. |
| Zoom | Coach-authorized creation and cancellation of per-booking meeting links | Connected coach Zoom account identity; meeting topic, start time, duration, meeting ID, attendee join URL, and OAuth request metadata | Provider-operated regions selected by Zoom and the connected account | Zoom Marketplace/developer terms apply; controller/processor role, DPA coverage, production app review, and account-specific terms evidence are pending production legal/vendor review |
| Apple iCloud CalDAV | Coach-authorized calendar discovery, conflict checks, and booking-event creation or deletion | Coach Apple Account email, app-specific password, CalDAV server and calendar paths, free/busy event intervals, and event start/end, title, and description | Provider-operated regions selected by Apple and the connected account | The coach's iCloud terms govern their account; controller/processor role, DPA availability, and HiringCoachAI's permitted production access posture are pending legal/vendor review |
| Granola | Coach-authorized review and import of selected meeting notes into relationship-scoped coaching records; MCP note retrieval only after explicit connection and consent; optional REST webhook event intake only | MCP OAuth connection metadata, active workspace, granted scope indicators, plan capability indicators, and encrypted local credentials; selected note IDs, titles, URLs, timestamps, and reviewed content; REST webhook event IDs and processing metadata | Provider-operated regions selected by Granola and the connected account | Coach-authorized connected provider only after explicit connection and consent. MCP uses per-user browser OAuth at https://mcp.granola.ai/mcp over Streamable HTTP. Basic provides personal notes from the last 30 days, Business provides personal and public notes, and Enterprise is admin-configured, subject to the active workspace and granted scope. Official documentation describes a supported MCP integration, but HiringCoachAI remains test-only and production fail-closed until live verification and approval. REST API keys and webhooks remain optional advanced Business or Enterprise features and are not granted by OAuth. REST/API/webhook mode requires COACH_GRANOLA_ENABLED=true; MCP additionally requires COACH_GRANOLA_MCP_ENABLED=true; both flags default to false in production. MCP does not send or receive webhook notifications. The published Granola DPA is identified and linked, but applicability, incorporation into our Agreement, account-specific acceptance, and Privacy Officer or counsel approval are PENDING. No bespoke DPA, automatic sends, or AI calls are claimed for the connection. |
Platform
| Sub-processor | Purpose | Location |
|---|
| GitHub | Source-code hosting and CI | US |
| Domain registrar + DNS | Domain and DNS management | US |
Historical / removed
| Date | Integration | Reason |
|---|
| 2026-07-29 | Hotjar (Contentsquare) client SDK | Runtime initialization and session capture removed because URL metadata could not be safely suppressed. The installed package is dormant and sends no production data. |
| 2026-07-29 | Google Tag Manager (GTM), including container-loaded Google Analytics and LinkedIn Insight tags | Client container loading removed because vendor-managed tags could read query-backed product URLs. Direct app-owned GA4 returned on 2026-08-25 with query-free page views and default-denied storage and ad signals. GTM and LinkedIn remain disabled. |
| 2026-07-29 | Meta Pixel client SDK | Browser PageView collection removed because the vendor SDK derives the full current URL. The server-side gift-flow Conversions API remains listed above. |
How to object
Per our Privacy Policy, you may object to specific processing. Contact [email protected]. Some sub-processors (payments, identity, infrastructure) are essential to the service; we cannot provide the service without them. Analytics cookies, detailed product analytics, and marketing can be disabled through the cookie banner or account settings. Limited cookieless GA4 page counts continue under legitimate interest without persistent identifiers.
Change log
| Date | Change |
|---|
| 2026-08-25 | Restored direct GA4 in advanced Consent Mode with query-free cookieless page counts, default-denied storage and ad signals, and the existing Analytics preference controlling analytics cookies and detailed measurement. GTM and its LinkedIn tag remain disabled. |
| 2026-08-24 | Added Granola MCP OAuth and optional REST API/webhook modes as conditional coach-authorized connected-provider paths. Documented active-workspace and plan-dependent scope variability, explicit consent, no automatic sends or AI, safe metadata-only export, local credential deletion, no advertised OAuth revocation endpoint, provider-source boundary, dual production flags, the published DPA identified and linked with applicability and incorporation pending, and pending controller/processor, terms, live verification, and Privacy Officer or counsel review. No bespoke DPA is claimed. |
| 2026-08-10 | Classified Microsoft Graph / Outlook Calendar as a user-authorized connected provider, corrected its exact read/write data scope, recorded no Microsoft processor DPA/SCC claim, and separated connected providers from HiringCoachAI sub-processors. |
| 2026-07-29 | Disabled Hotjar, GTM/GA/LinkedIn Insight browser tags, the client Meta Pixel, Sentry automatic DOM screenshots, and URL-bearing replay; added recursive URL scrubbing for remaining browser telemetry. |
| 2026-07-27 | Added conservative coverage for coach-connected Microsoft Graph / Outlook Calendar, Zoom, and Apple iCloud CalDAV integrations; no executed DPA or final controller/processor classification is claimed pending legal and vendor review. |
| 2026-07-24 | Added Twilio Programmable Messaging scope, SMS data categories, geographic limitation, and provider-redaction requests. |
| 2026-07-16 | Documented full transactional-email content, Google Workspace / Gmail communication routing, and OpenAI coach-profile moderation. |
| 2026-04-24 | Initial publication |
| 2026-05-11 | Confirmed /sub-processors renders from this canonical markdown source and added public-safety note. |
| 2026-05-17 | Added PostHog (PostHog Inc., US) as a product-analytics sub-processor. Client-side SDK is opted-out by default and gated through the analytics consent category. |