DealHatch uses the following third-party subprocessors to deliver the service. The first group is engaged for every customer. The second is engaged only if you connect that integration — those services receive nothing until you enable the feature and consent to the disclosure.
Last updated: August 20, 2026 · DealHatch processes and stores customer data in the United States only.
This list is maintained by our team and is pending formal legal review. Questions? Contact contact@dealhatch.ai.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Supabase | Database, authentication, and file storage | Account data and all application content at rest |
| Fly.io | Backend application hosting (United States) | All application content in transit through the API |
| Vercel | Frontend application hosting and delivery | Requests to the web application, including IP address |
| Google (Gemini API) | AI text generation and embeddings for strategies, summaries, search, and email-to-deal matching | Deal content, approved email text, and document text you submit for AI features |
| LlamaIndex (LlamaParse) | Document parsing (PDF, Office files) for the knowledge pipeline | Documents and approved email attachments you upload for processing |
| Upstash (Redis) | Background job queue for ingestion, AI generation, and scheduled work | Job payloads, which may reference deal and document identifiers |
| Sentry | Application error monitoring and diagnostics, in both the backend and your browser | Error reports and diagnostic metadata, including the page and account an error occurred on; not deal content |
| Resend (or a configured SMTP provider) | Transactional email — invitations, notifications, and data-request confirmations | Recipient email address and the contents of messages we send you |
| Stripe | Payments and subscription billing | Billing contact details and payment information |
| Web3Forms | Delivers submissions from the public website forms — contact, waitlist, and notify-me | Only what you type into those forms: name, email address, and company where given. No application or deal data. |
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Google (Gmail API) | Optional mailbox integration — reading mail you choose to connect (read-only) | Mailbox content of connected Gmail accounts, per your consent |
| Microsoft (Graph API) | Optional mailbox integration — reading mail you choose to connect (read-only) | Mailbox content of connected Microsoft accounts, per your consent |
| IMAP host you specify | Optional mailbox integration with a mail server of your choosing (read-only) | Mailbox content of the connected account, per your consent |
| HubSpot | Optional CRM sync — reading deals, activities, and attachments | CRM records you authorise us to read, and the credentials you connect |
| Salesforce | Optional CRM sync — reading deals, activities, and attachments | CRM records you authorise us to read, and the credentials you connect |
| Zoho CRM | Optional CRM sync — reading deals, activities, and attachments | CRM records you authorise us to read, and the credentials you connect |
| Pipedrive | Optional CRM sync — reading deals, activities, and attachments | CRM records you authorise us to read, and the credentials you connect |
| Slack | Optional notifications to a Slack workspace you configure | Notification contents, which may include deal titles and invited email addresses |
Your content is never used to train AI models — not by us, and not by our AI providers, whose paid service tiers exclude customer content from model training. An AI provider may retain what we send it for a limited period for abuse monitoring before deleting it; that retention is not model training. Emails you do not approve for a deal are deleted automatically within 30 days.