Sub-processors
The vendors below process personal data in connection with the Services, as described in our Privacy Policy. Business customers receive 30 days’ notice of additions or replacements via our Data Processing Addendum.
| Vendor | Role — and what they receive | Location |
|---|---|---|
| Stripe | Payment processing for purchases: card details entered directly in Stripe checkout, billing name/email, transaction amount. We see only masked card data and payment status. | US |
| OpenRouter (OpenRouter, Inc.) | AI model routing for generation and analytics features: product inputs, generation requests and, for AI analytics features, the end-user analytics data we process for customers - routed to third-party model providers under policies that prohibit training on inputs; providers may retain prompts for a limited period for abuse prevention. | US (routing); model providers process in various locations |
| Vercel | Frontend and application hosting: request data incl. IP addresses. | US |
| DigitalOcean | Backend APIs, workers, managed PostgreSQL: account data, workspace content, encrypted connected-account tokens. | US |
| Cloudflare | DNS for heycatch.ai. Our own DNS records are not proxied, so for our website and app Cloudflare sees lookups rather than page content. Our backend API and webhook hostnames resolve to DigitalOcean App Platform, whose ingress runs behind Cloudflare: for those requests Cloudflare terminates TLS and handles the request content. | US/global |
| Clerk | Authentication: name, email, credentials/OAuth identifiers, session and device data. | US |
| bundle.social (Bundle sp. z o.o.) | Social publishing and post analytics for connected accounts: OAuth tokens and content you publish. | EU (Poland; some providers may process outside the EEA) |
| twitterapi.io (Prism Digital, LLC) | Retrieval of public X/Twitter data: search queries derived from your product settings. | US (AWS; vendor states max 48h retention) |
| FastLane (Possibility Studios Pty Ltd) | AI short-form video generation: your product/project info. | Australia (may process outside AU via providers) |
| Apify (Apify Technologies s.r.o.) | Reddit account audit scraping: the Reddit username you submit. | EU/US |
| Exa | Web search for product/competitor research: queries derived from your product info. | US |
| Customer.io | Transactional and lifecycle email: contact attributes from signup/waitlist. | US |
| Sentry | Application error tracking: request metadata, plus the pseudonymous identifiers we attach — internal user/project IDs in the app, and a pseudonymous browser/device ID on our landing pages. We do not attach email addresses, names or IP addresses. | US |
| Axiom (Axiom, Inc.) | Log ingestion and querying: application logs, which may include identifiers and IPs. | US/EU (AWS + Cloudflare) |
| Amplitude | Marketing analytics for our landing-page funnel: page events, session recordings of marketing pages with typed input masked, device/browser and screen data. Funnel answers you type in are sent as event data - including your email address (also used as the Amplitude user ID), name, product link and chosen plan. Events also carry campaign attribution (UTM parameters), a pseudonymous visitor ID and the A/B test variants you were assigned. On a purchase, our backend also sends a purchase-confirmation event with those same fields plus the payment method; card details and payment amounts are not sent. | US |
| Google Analytics | Website analytics on marketing pages: page events, device/browser data and IP. | US |
| PostHog (PostHog, Inc.) | Product analytics infrastructure (US Cloud): app usage events and, where the HeyCatch SDK is enabled, the end-user events we process for that customer. No advertising use; session replay disabled. | US |
| Crisp (Crisp IM SAS) | Support chat on our website: chat messages, email if provided, device/usage metadata. | EU (France) |
| Meta Platforms | Advertising measurement on our marketing pages, where enabled, as an independent controller: browser pixel page events and device/browser data, plus server-side conversion events carrying a hashed email address and first name. Global Privacy Control is honored. | US |
| Upstash (Upstash, Inc.) | Queues and scheduled jobs: job payloads referencing user/workspace identifiers. | US/EU (AWS, region selectable) |
| Google Workspace | Corporate email/support and our internal customer sheet: the content of your emails to support@heycatch.ai, and one row per paid invoice (name, email, plan and transaction details) written to a Google Sheet we read. | US/EU |
| Resend | Transactional email delivery: the recipient address and the content of the message we send you. | US |
| Slack (Slack Technologies, LLC) | Internal engineering alerting: the body of each alert, which can include stack traces and log lines carrying user, workspace and request identifiers. | US |
| Trigger.dev | Background job orchestration: task payloads and run logs, including user and workspace identifiers and the workspace content those jobs process. | US |