ProPal Subprocessor and Infrastructure List
Last Updated: August 3, 2026 Version: 1.0
This list identifies principal third-party service providers that may process personal information to support ProPal. The exact services, regions, and configurations may change as ProPal develops. A vendor’s inclusion does not mean every customer record is sent to every vendor.
1. Twilio
Purpose: Telephone-number provisioning, SMS and MMS transmission, inbound webhooks, delivery events, sender registration, opt-out and help handling, messaging logs, and related communications infrastructure.
Typical data: Customer and provider phone numbers, message content, media, timestamps, source and destination numbers, delivery status, carrier information, opt-out events, and technical logs.
2. SendGrid (a Twilio service)
Purpose: Transactional and operational email delivery, including provider dispatch, account, support, billing, and system notices.
Typical data: Email addresses, message content, delivery status, bounce and complaint data, timestamps, and link or open events where enabled.
3. Supabase
Purpose: Hosted PostgreSQL database, provider authentication, object storage, server-side and Edge Function execution, access control, and application infrastructure.
Typical data: Customer and provider profiles, phone numbers, email addresses, message records, service requests, locations, routing and dispatch state, provider configuration, ratings, billing state, support information, files, and audit records.
4. OpenAI
Purpose: AI-assisted message interpretation, intake, classification, summarization, structured extraction, response generation, evaluation, and related custom AI operations when OpenAI models are selected.
Typical data: Relevant message content, service-request details, addresses or location context where necessary, provider context, prompts, model output, and technical metadata.
5. Anthropic
Purpose: AI-assisted message interpretation, intake, classification, summarization, structured extraction, response generation, evaluation, and related custom AI operations when Anthropic models are selected.
Typical data: Relevant message content, service-request details, addresses or location context where necessary, provider context, prompts, model output, and technical metadata.
6. Google Maps Platform
Purpose: Address entry assistance, normalization, geocoding, mapping, distance calculations, and evaluation of provider coverage.
Typical data: Service addresses, latitude and longitude, search queries, place identifiers, map interactions, and technical request information.
7. Stripe
Purpose: Provider subscription checkout, payment methods, recurring billing, invoices, receipts, payment-failure events, customer portal, taxes or related billing functions where enabled.
Typical data: Provider business and contact information, Stripe customer and subscription identifiers, plan and location data, billing addresses, payment status, invoice information, and payment credentials submitted directly to Stripe.
ProPal generally does not store full payment-card numbers.
8. Hosting and Deployment Providers
Purpose: Public website and application hosting, content delivery, deployment previews, domain and TLS operation, server logs, performance, and availability.
Typical data: IP addresses, device and browser data, page requests, cookies, server logs, and content transmitted to hosted services.
The current deployment provider should be inserted or confirmed in this list before publication if it processes personal information beyond ordinary public web traffic.
9. Monitoring, Error, and Security Vendors
Purpose: Error detection, performance monitoring, logging, abuse prevention, alerting, backup, vulnerability management, and incident response.
Typical data: Technical logs, request metadata, error traces, identifiers, partial message or record context where configured, IP address, and device information.
Any monitoring vendor that receives production personal information should be named here before launch.
10. Professional Advisers
Purpose: Legal, accounting, insurance, security, compliance, and professional services.
Typical data: Information reasonably necessary for advice, audits, disputes, claims, tax reporting, security, and compliance.
11. Independent Service Providers Are Recipients, Not General Subprocessors
Home-service providers receive customer service-request information to evaluate, accept, schedule, quote, perform, or support the customer-requested service. They are independent businesses and generally act under their own legal obligations for the direct customer relationship after handoff.
They do not receive the customer’s mobile opt-in or consent as permission for unrelated marketing. They may use the information only for the requested service and legally authorized follow-up.
12. Changes and Notice
ProPal may add, remove, or replace vendors as technology and operations change. Material updates should be reflected in this list and the Privacy Policy. Enterprise customers with a negotiated notification right will receive notice according to their agreement.
13. Contact
Questions may be sent to hello@textpropal.com.