HiringCoach.ai

Sub-processors

Last reviewed 2026-08-10

This list identifies third parties involved in delivering HiringCoachAI. The core tables identify providers that process data on our behalf, for which we remain accountable. The user-connected calendar and meeting section separately identifies external services a coach directs HiringCoachAI to connect; inclusion in that section does not by itself mean the provider is a HiringCoachAI processor or sub-processor.

Advance notice of new sub-processors is available by request at [email protected].

This page identifies vendor names, purposes, data categories, locations, and high-level assurance posture. API keys, account IDs, DPA acceptance timestamps, dashboard screenshots, security runbooks, and credential locations remain internal.

Core infrastructure

Sub-processorPurposeData processedLocationCertifications
Google Cloud Platform / FirebaseAuthentication, Firestore database, Cloud Storage for coach/client materials, chat attachments, profile images, account/resume files, backup/export buckets and Cloud Functions source, Cloud Tasks, Cloud Text-to-SpeechAll user profile, content, session, audit, and user-uploaded material data; backup/export objects inherit source classificationUS: Firestore live database in US multi-region; user-content and backup/export buckets in the configured US location; Cloud Functions source buckets in a US regionSOC 1/2/3, ISO 27001/17/18/701, Payment Card Industry Data Security Standard (PCI DSS), HIPAA, FedRAMP High
VercelApplication hosting, Edge Middleware, Serverless Functions, AI Gateway, logs, and Vercel Analytics when analytics consent is grantedRequest headers, execution logs, routed AI traffic, and consented site-level analytics telemetry after pageview query strings and fragments are removedGlobal edge; primary USSOC 2 Type II, ISO 27001
CloudflarePublic DNS, reverse proxy, CDN/security edge for hiringcoach.aiDNS records, request metadata, IP addresses, HTTP headers for proxied trafficGlobal edgeSOC 2 Type II, ISO 27001

Payments

Sub-processorPurposeData processedLocationCertifications
StripeSubscription billing, payment card processing (hosted Checkout and Elements / Payment Element)Customer ID, email, payment token, subscription and billing-status metadata. No payment-card primary account number (PAN), card verification value (CVV), or card-track data touches HiringCoachAI.US + EUPayment Card Industry Data Security Standard (PCI DSS) Level 1, SOC 1/2, ISO 27001

Communications

Sub-processorPurposeData processedLocationCertifications
SendGrid (Twilio)Transactional email, notifications, verification messages, user-message delivery, and Twilio Programmable Messaging for consented non-promotional coaching SMS to U.S./Canadian recipientsEmail sender/recipient addresses, subject and message body (including user communication content or a profile-review snapshot included in an email), and delivery events; for SMS, destination number, coach identity, message body, opt-out keyword, provider message ID and delivery status. The application requests Twilio body discard and destination-number obfuscation on each outbound text.USSOC 2 Type II, ISO 27001
Mailchimp (Intuit)Account/customer communications, communication-list management, and opt-in marketing email where applicableEmail, name, communication preferencesUSSOC 2 Type II
Google Workspace / GmailTransactional and support email routing, administrative profile-review notifications, hiring, and accommodation mailboxesSender/recipient addresses, subject, message body, replies, attachments where used, and delivery/routing metadataUSSOC 2/3, ISO 27001

AI providers

We do not have separate Zero Data Retention (ZDR) agreements with any AI provider. Where a provider exposes per-request storage or transcript-exposure controls, our code sends them, and an automated check runs in local compliance checks and the scheduled/manual security workflow to verify covered OpenAI Chat Completions or Responses requests include store: false and Deepgram transcription requests include redact=true. These flags reduce provider-side storage or transcript exposure where supported, but they are not the same as a signed ZDR agreement. Each provider's then-current standard API retention windows otherwise apply. The no-training posture relies on each provider's then-current standard API terms; we have not signed separate enterprise no-training amendments.

Sub-processorPurposeData processedLocationRetention
OpenAI (called both directly and via Vercel AI Gateway)LLM generation and coach-profile content moderationUser prompts and completions; coach profile text, link fields, and photos submitted for moderationUSPer-request store: false on OpenAI Chat Completions and Responses requests. No Zero Data Retention (ZDR) amendment: OpenAI's then-current standard API retention windows apply.
Perplexity AIResearch-backed company intelligence (optional)Query textUSStandard API terms; provider default retention applies.
ElevenLabsText-to-speechText to be spokenUSStandard API terms; provider default retention applies.
DeepgramSpeech-to-textAudio clips (user voice)USPer-request redact=true to redact sensitive number-like entities from transcripts, such as payment cards and Social Security numbers; provider default audio retention otherwise applies.
Google Cloud Text-to-SpeechAlternate TTSTextUSStandard API terms; provider default retention applies.

Error monitoring and analytics

Sub-processorPurposeData processedConsent
SentryApplication error & performance monitoring, plus Vercel log drain destinationStack traces, user IDs only where needed for debugging, request metadata after recursive event/log/trace URL scrubbing; Session Replay and automatic DOM screenshots disabled; no prompts/completions intentionally loggedEssential
Google Analytics 4Basic site traffic measurement and, after Analytics consent, fuller analytics measurementBy default: query-free page location and referrer, denied consent state, random per-page value, and standard network metadata such as timestamp, IP address, and browser user agent. No analytics cookies, persistent identifiers, Google signals, ad personalization, or behavioral events before Analytics consent.Legitimate interest for limited cookieless page counts. Analytics consent for analytics storage and detailed measurement. Direct app-owned gtag.js; GTM and container-loaded marketing tags remain disabled.
AmplitudeProduct analyticsEvent data and session IDs; Session Replay and URL-bearing autocapture disabledAnalytics consent
MixpanelProduct analyticsEvent data; session recording disabledAnalytics consent
PostHog (PostHog Inc.)Product analytics: event capture, funnels, and behavioral insightsEvent names and properties (e.g. login_attempted, subscription_purchased, plan tier); stable user identifier (Firebase UID) and email attached only after analytics consent is granted; standard request metadata (IP, user-agent)Analytics consent. Client-side SDK starts opted-out by default; capture begins only after analytics consent and is revoked live on consent withdrawal. Server-side transactional events from Stripe webhook and account-deletion confirmation fire under the corresponding lawful basis documented per-event in the data map. PostHog Inc., US-hosted; standard PostHog DPA applies.
Meta (Facebook) Conversions APIServer-side gift-flow conversion measurement; the client Meta Pixel is disabledGift conversion events and hashed identifiersMarketing consent

Developer productivity / integrations

Sub-processorPurposeData processedLocationCertifications
MapboxGeocoding and location displayApproximate location strings entered by userUSSOC 2 Type II
LinkedInOAuth sign-in; profile import (with user consent)LinkedIn profile fields, limited scopeUSSOC 2 Type II, ISO 27001
Google OAuth / DriveOAuth sign-in; folder-bounded Google Drive Materials mirror and export (opt-in)Profile, email, and files or metadata inside the user-authorized HiringCoachAI folder; per-file user scope plus a dedicated principal shared only on that folderUSSOC 1/2/3, ISO 27001 (Google Cloud parent)
Facebook OAuthOAuth sign-inProfile, emailUSSOC 2 Type II, ISO 27001
CanvaDesign asset importFile metadataAustralia + USSOC 2 Type II, ISO 27001

User-connected calendar and meeting providers

Microsoft Graph / Outlook Calendar and Zoom require HiringCoachAI provider credentials plus coach authorization; Apple iCloud CalDAV requires a coach-supplied app-specific password. Each integration processes data only after the coach takes that connection step. Granola MCP uses per-user browser OAuth and its active workspace, while the separate REST API and REST webhook path remains an optional advanced Business or Enterprise path. OAuth does not grant REST API or webhook access, and MCP does not send or receive webhook notifications. Standard Dynamic Client Registration browser OAuth does not require a client secret or a traditional app-registration portal. Microsoft is classified as a user-authorized connected provider under its API and identity-platform developer terms, not as a HiringCoachAI processor or sub-processor. Zoom, Apple, and Granola remain pending legal and Privacy Officer classification. This list does not claim that HiringCoachAI has executed or accepted a DPA with a connected provider unless its row expressly says so.

Connected providerPurposeData processedLocationContract / assurance status
Microsoft Graph / Outlook CalendarCoach-authorized calendar discovery, conflict checks, and booking-event creation or deletionOAuth authorization context; calendar IDs, names, and editability; event start/end and availability status for conflict checks; booking title, start/end, optional location, and attendee email only when invitations are enabled; OAuth request metadata and encrypted credentialsProvider-operated regions selected by Microsoft and the connected accountN/A user-authorized connected provider under the Microsoft APIs Terms and identity-platform developer Terms, which do not create a HiringCoachAI-Microsoft processor/sub-processor relationship. No Microsoft processor DPA or SCC coverage is claimed. Privacy Officer classification and publisher verification recorded 2026-08-10; publisher verification is an identity signal, not compliance certification.
ZoomCoach-authorized creation and cancellation of per-booking meeting linksConnected coach Zoom account identity; meeting topic, start time, duration, meeting ID, attendee join URL, and OAuth request metadataProvider-operated regions selected by Zoom and the connected accountZoom Marketplace/developer terms apply; controller/processor role, DPA coverage, production app review, and account-specific terms evidence are pending production legal/vendor review
Apple iCloud CalDAVCoach-authorized calendar discovery, conflict checks, and booking-event creation or deletionCoach Apple Account email, app-specific password, CalDAV server and calendar paths, free/busy event intervals, and event start/end, title, and descriptionProvider-operated regions selected by Apple and the connected accountThe coach's iCloud terms govern their account; controller/processor role, DPA availability, and HiringCoachAI's permitted production access posture are pending legal/vendor review
GranolaCoach-authorized review and import of selected meeting notes into relationship-scoped coaching records; MCP note retrieval only after explicit connection and consent; optional REST webhook event intake onlyMCP OAuth connection metadata, active workspace, granted scope indicators, plan capability indicators, and encrypted local credentials; selected note IDs, titles, URLs, timestamps, and reviewed content; REST webhook event IDs and processing metadataProvider-operated regions selected by Granola and the connected accountCoach-authorized connected provider only after explicit connection and consent. MCP uses per-user browser OAuth at https://mcp.granola.ai/mcp over Streamable HTTP. Basic provides personal notes from the last 30 days, Business provides personal and public notes, and Enterprise is admin-configured, subject to the active workspace and granted scope. Official documentation describes a supported MCP integration, but HiringCoachAI remains test-only and production fail-closed until live verification and approval. REST API keys and webhooks remain optional advanced Business or Enterprise features and are not granted by OAuth. REST/API/webhook mode requires COACH_GRANOLA_ENABLED=true; MCP additionally requires COACH_GRANOLA_MCP_ENABLED=true; both flags default to false in production. MCP does not send or receive webhook notifications. The published Granola DPA is identified and linked, but applicability, incorporation into our Agreement, account-specific acceptance, and Privacy Officer or counsel approval are PENDING. No bespoke DPA, automatic sends, or AI calls are claimed for the connection.

Platform

Sub-processorPurposeLocation
GitHubSource-code hosting and CIUS
Domain registrar + DNSDomain and DNS managementUS

Historical / removed

DateIntegrationReason
2026-07-29Hotjar (Contentsquare) client SDKRuntime initialization and session capture removed because URL metadata could not be safely suppressed. The installed package is dormant and sends no production data.
2026-07-29Google Tag Manager (GTM), including container-loaded Google Analytics and LinkedIn Insight tagsClient container loading removed because vendor-managed tags could read query-backed product URLs. Direct app-owned GA4 returned on 2026-08-25 with query-free page views and default-denied storage and ad signals. GTM and LinkedIn remain disabled.
2026-07-29Meta Pixel client SDKBrowser PageView collection removed because the vendor SDK derives the full current URL. The server-side gift-flow Conversions API remains listed above.

How to object

Per our Privacy Policy, you may object to specific processing. Contact [email protected]. Some sub-processors (payments, identity, infrastructure) are essential to the service; we cannot provide the service without them. Analytics cookies, detailed product analytics, and marketing can be disabled through the cookie banner or account settings. Limited cookieless GA4 page counts continue under legitimate interest without persistent identifiers.

Change log

DateChange
2026-08-25Restored direct GA4 in advanced Consent Mode with query-free cookieless page counts, default-denied storage and ad signals, and the existing Analytics preference controlling analytics cookies and detailed measurement. GTM and its LinkedIn tag remain disabled.
2026-08-24Added Granola MCP OAuth and optional REST API/webhook modes as conditional coach-authorized connected-provider paths. Documented active-workspace and plan-dependent scope variability, explicit consent, no automatic sends or AI, safe metadata-only export, local credential deletion, no advertised OAuth revocation endpoint, provider-source boundary, dual production flags, the published DPA identified and linked with applicability and incorporation pending, and pending controller/processor, terms, live verification, and Privacy Officer or counsel review. No bespoke DPA is claimed.
2026-08-10Classified Microsoft Graph / Outlook Calendar as a user-authorized connected provider, corrected its exact read/write data scope, recorded no Microsoft processor DPA/SCC claim, and separated connected providers from HiringCoachAI sub-processors.
2026-07-29Disabled Hotjar, GTM/GA/LinkedIn Insight browser tags, the client Meta Pixel, Sentry automatic DOM screenshots, and URL-bearing replay; added recursive URL scrubbing for remaining browser telemetry.
2026-07-27Added conservative coverage for coach-connected Microsoft Graph / Outlook Calendar, Zoom, and Apple iCloud CalDAV integrations; no executed DPA or final controller/processor classification is claimed pending legal and vendor review.
2026-07-24Added Twilio Programmable Messaging scope, SMS data categories, geographic limitation, and provider-redaction requests.
2026-07-16Documented full transactional-email content, Google Workspace / Gmail communication routing, and OpenAI coach-profile moderation.
2026-04-24Initial publication
2026-05-11Confirmed /sub-processors renders from this canonical markdown source and added public-safety note.
2026-05-17Added PostHog (PostHog Inc., US) as a product-analytics sub-processor. Client-side SDK is opted-out by default and gated through the analytics consent category.

← Back to the trust center

showUpgradeModal: false, modalType: migration, planName: