Skip to main content

Legal

Subprocessors

Last updated: September 2026

Everyone outside PipeLineHub who can see any part of your data, and exactly what each of them gets. If a company is not on this page, it does not receive anything from us.

1. Always in use

These run for every account. Each one is here because the service cannot work without it, not because it is convenient.

  • Supabase

    Supabase, Inc. (United States)

    What it does:
    Accounts, sign-in and the database behind the Lead Vault, the Site Monitor and billing state.
    What it receives:
    Email address, hashed password, subscription status, saved favourites, pipeline stages, monitor settings and alerts.
    Processed in:
    AWS, region chosen at project creation
    Their privacy policy (opens in a new tab)
  • Vercel

    Vercel Inc. (United States)

    What it does:
    Hosting and delivery of this website, plus optional page-view analytics.
    What it receives:
    Standard web-server request data (IP address, user agent, URL) held briefly in logs. Analytics counts page views and is only loaded if you allow it.
    Processed in:
    Global edge network
    Their privacy policy (opens in a new tab)
  • PayPal

    PayPal Holdings, Inc. (United States)

    What it does:
    Taking subscription payments and managing renewals and cancellations.
    What it receives:
    Whatever you give PayPal at checkout. We receive back only a subscription ID, plan, status and payer ID. We never see your card or bank details.
    Processed in:
    Global
    Their privacy policy (opens in a new tab)
  • Resend

    Resend, Inc. (United States)

    What it does:
    Sending Site Monitor verification codes, the alert emails you asked for, and the free weekly leads email to addresses that confirmed it.
    What it receives:
    The recipient email address and the content of that email.
    Processed in:
    United States
    Their privacy policy (opens in a new tab)
  • Google (Sign-in)

    Google LLC (United States)

    What it does:
    Signing in with Google, if you choose that instead of a password.
    What it receives:
    Your Google account email address and name, only when you use that button.
    Processed in:
    Global
    Their privacy policy (opens in a new tab)
  • GitHub Actions

    GitHub, Inc. (United States)

    What it does:
    Running the Site Monitor worker on a schedule.
    What it receives:
    The website addresses being monitored. The worker authenticates back to this site with a short-lived OIDC token and holds no database or email keys.
    Processed in:
    United States
    Their privacy policy (opens in a new tab)

2. Only when a feature is switched on

These are reached only when the named setting is configured on this deployment, and only for the feature described. If the setting is empty, the service is never called.

  • Google (Gemini API)

    Google LLC (United States)

    What it does:
    Drafting the first version of an outreach email in the dashboard.
    What it receives:
    The lead record you asked about and the pitch profile you wrote (your service, tone and sign-off). Your email address is not sent.
    Processed in:
    Global
    Only when enabled:
    GEMINI_API_KEY
    Their privacy policy (opens in a new tab)
  • Anthropic

    Anthropic PBC (United States)

    What it does:
    Summarising what changed on a monitored competitor page, in plain language, for the alert email.
    What it receives:
    Extracted text from the public competitor page being compared. No customer personal data is sent.
    Processed in:
    United States
    Only when enabled:
    ANTHROPIC_API_KEY
    Their privacy policy (opens in a new tab)
  • Serper

    Serper (United States)

    What it does:
    Checking where a monitored site ranks for the keywords its owner chose.
    What it receives:
    The keyword and country chosen by the site owner, and the site address.
    Processed in:
    United States
    Only when enabled:
    SERPER_API_KEY
    Their privacy policy (opens in a new tab)

3. What we do not use

To be explicit about the categories a page like this usually hides:

  • no advertising or retargeting networks, and no advertising pixels;
  • no session-recording or heatmap tools;
  • no data brokers, enrichment vendors or audience-sharing arrangements;
  • no chat, CRM or marketing-automation SDK embedded in these pages. The support chat is our own code and answers from a fixed script.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

4. International transfers

Most of the providers above are based in the United States, so running PipeLineHub involves transferring data there. Where the law that applies to you requires a transfer mechanism, we rely on the providers’ standard contractual clauses, which each of them publishes as part of the data-processing terms linked above.

5. Changes and questions

We update this page when a provider is added or removed. If you have a contract with us that requires notice of a change, email amoriasim2010@gmail.com and we will add you to the list we notify. The Privacy Policy explains what we do with data ourselves.

Questions? Email amoriasim2010@gmail.com.

Cookies

One cookie keeps you signed in. With your OK we'd also count page views, to see which pages need work. It stays off unless you say yes. · Cookie Policy