Subprocessors
Last updated: 2026-10-01
Revenue Recovery Engine uses the following third-party subprocessors to operate the Service. Each subprocessor is bound by a written agreement that limits their use of customer data to providing services to us, with confidentiality, security, and (where applicable) data-processing requirements equivalent to those in our agreement with you.
We notify customers at least 14 days before adding or replacing a subprocessor, per the Changes section of our Terms of Service.
| Subprocessor | Purpose | Data processed | HQ | Policy |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage (call recordings, lead CSVs) | All customer + lead data at rest | United States | Link |
| Vercel Inc. | Application hosting, serverless functions, CDN | All in-transit traffic; function logs | United States | Link |
| Stripe, Inc. | Subscription billing, payment processing, customer portal | Business name, contact email, payment method (Stripe holds card data; we do not) | United States | Link |
| Twilio Inc. | Phone numbers, SMS, voice routing | Inbound/outbound phone numbers, SMS message bodies, call metadata | United States | Link |
| Synthflow AI | AI voice agent, call transcription, call recording | Caller phone number, caller name, transcript, recording, call metadata | Germany | Link |
| Anthropic, PBC | Large language model for SMS drafting and conversation handling | Prompt content (business name, lead name/service/notes); responses | United States | Link |
| Resend, Inc. | Transactional email delivery (welcome, payment, auth, digests) | Recipient email, message subject and body | United States | Link |
| Functional Software, Inc. (Sentry) | Error tracking, performance monitoring | Error stack traces, request metadata, user id (no message bodies) | United States | Link |
| Google LLC | Google Calendar OAuth + event sync (optional, per-customer) | OAuth access + refresh tokens (encrypted at rest); calendar events created on customer's behalf | United States | Link |
| HubSpot, Inc. | CRM sync (optional, per-customer; only if customer connects) | API tokens (encrypted at rest); lead + appointment data synced to customer's HubSpot | United States | Link |
| Pipedrive OÜ | CRM sync (optional, per-customer; only if customer connects) | API tokens (encrypted at rest); lead + appointment data synced to customer's Pipedrive | Estonia | Link |
| Jobber (Octopusapp Inc.) | Client-list import (optional, per-customer; only if customer connects) | OAuth tokens (encrypted at rest); client names and contact details read from the customer's Jobber account | Canada | Link |
| n8n GmbH (self-hosted instance) | Workflow orchestration (reactivation, follow-up, post-call, daily digest) | Lead + appointment + call metadata passed between workflow steps | Germany | Link |
Website and marketing vendors
These companies receive information about visitors to our website and app. Meta and Google advertising tools load only if you click OK on the cookie banner, and those companies use the data under their own privacy terms. See our Cookie Policy.
| Vendor | Purpose | Data received | HQ | Policy |
|---|---|---|---|---|
| Meta Platforms, Inc. | Advertising measurement (Meta Pixel and Conversions API) — only if you click OK on the cookie banner | Pages viewed, ad-click identifiers, and at signup a hashed (scrambled) email, name and phone so Meta can count the signup | United States | Link |
| Google LLC (Ads and Analytics) | Advertising measurement and website analytics — only if you click OK on the cookie banner | Pages viewed, ad-click identifiers, approximate location from the browser | United States | Link |
| HeyCatch | Website and dashboard usage analytics | Pages viewed and interactions on our website and in the customer dashboard, with a browser identifier | See vendor | Link |
Customer-directed integrations
If you connect an outbound webhook (for example a Zapier, Make, or custom endpoint) under Settings → CRM sync, RRE sends your new lead and appointment data to the destination you choose and control. That destination is not an RRE subprocessor — it is an onward transfer you direct, and you are responsible for its handling of the data. RRE only delivers to the URL you configure, and you can remove it at any time.
For questions about subprocessors or to request our standard Data Processing Agreement (DPA), email privacy@smartflow.tools.