Subprocessors

DealHatch uses the following third-party subprocessors to deliver the service. The first group is engaged for every customer. The second is engaged only if you connect that integration — those services receive nothing until you enable the feature and consent to the disclosure.

Last updated: August 20, 2026 · DealHatch processes and stores customer data in the United States only.

This list is maintained by our team and is pending formal legal review. Questions? Contact contact@dealhatch.ai.

Engaged for all customers

SubprocessorPurposeData processed
SupabaseDatabase, authentication, and file storageAccount data and all application content at rest
Fly.ioBackend application hosting (United States)All application content in transit through the API
VercelFrontend application hosting and deliveryRequests to the web application, including IP address
Google (Gemini API)AI text generation and embeddings for strategies, summaries, search, and email-to-deal matchingDeal content, approved email text, and document text you submit for AI features
LlamaIndex (LlamaParse)Document parsing (PDF, Office files) for the knowledge pipelineDocuments and approved email attachments you upload for processing
Upstash (Redis)Background job queue for ingestion, AI generation, and scheduled workJob payloads, which may reference deal and document identifiers
SentryApplication error monitoring and diagnostics, in both the backend and your browserError reports and diagnostic metadata, including the page and account an error occurred on; not deal content
Resend (or a configured SMTP provider)Transactional email — invitations, notifications, and data-request confirmationsRecipient email address and the contents of messages we send you
StripePayments and subscription billingBilling contact details and payment information
Web3FormsDelivers submissions from the public website forms — contact, waitlist, and notify-meOnly what you type into those forms: name, email address, and company where given. No application or deal data.

Engaged only when you connect the integration

SubprocessorPurposeData processed
Google (Gmail API)Optional mailbox integration — reading mail you choose to connect (read-only)Mailbox content of connected Gmail accounts, per your consent
Microsoft (Graph API)Optional mailbox integration — reading mail you choose to connect (read-only)Mailbox content of connected Microsoft accounts, per your consent
IMAP host you specifyOptional mailbox integration with a mail server of your choosing (read-only)Mailbox content of the connected account, per your consent
HubSpotOptional CRM sync — reading deals, activities, and attachmentsCRM records you authorise us to read, and the credentials you connect
SalesforceOptional CRM sync — reading deals, activities, and attachmentsCRM records you authorise us to read, and the credentials you connect
Zoho CRMOptional CRM sync — reading deals, activities, and attachmentsCRM records you authorise us to read, and the credentials you connect
PipedriveOptional CRM sync — reading deals, activities, and attachmentsCRM records you authorise us to read, and the credentials you connect
SlackOptional notifications to a Slack workspace you configureNotification contents, which may include deal titles and invited email addresses

Your content is never used to train AI models — not by us, and not by our AI providers, whose paid service tiers exclude customer content from model training. An AI provider may retain what we send it for a limited period for abuse monitoring before deleting it; that retention is not model training. Emails you do not approve for a deal are deleted automatically within 30 days.