Subprocessor List
Last updated: August 5, 2026
This page lists the third-party subprocessors ProFront uses to deliver its services. Each subprocessor receives only the data necessary for their specific function. This list is updated as the platform evolves.
Supabase
Database & Authentication
Account data storage, authentication, and row-level access control
Data: All account, communication, contact, and usage data
United States
Vercel
Application Hosting
Platform hosting and serverless compute
Data: Request and response data processed in transit
United States
Voice AI Platform
Voice Orchestration
Inbound call handling, voice AI routing, and call lifecycle management
Data: Call audio, transcripts, caller phone numbers, call metadata
United States
Twilio
Messaging & Telephony
Phone number provisioning, SMS delivery, and inbound message handling
Data: Phone numbers, SMS message content
United States
Stripe
Payment Processing
Subscription billing, payment processing, and invoice management
Data: Subscription status, invoice history. Payment card details are stored exclusively by our payment processor and never by ProFront
United States
AI Language Model Provider
AI Inference
Conversation intelligence, knowledge search, and agent responses
Data: Conversation context. Not used to train provider models; provider-side retention is limited to transient operational purposes such as response caching and abuse prevention
United States
Voice Synthesis Provider
Text-to-Speech
AI-generated voice responses for English and multilingual receptionist interactions
Data: Text content of AI-generated responses
United States
Resend
Transactional Email
Delivery of account notifications including missed call alerts and voicemail summaries
Data: Email addresses, notification content
United States
Sentry
Error Monitoring
Application error and performance monitoring, used to detect and diagnose service faults
Data: Error messages, stack traces, and technical diagnostic context. Configured to exclude IP addresses, request headers, cookies, request bodies, and URL query strings; personal data is filtered from diagnostic context before transmission. Error messages may incidentally contain personal data where it appears in the underlying fault
United States
Web Enrichment Provider
Web Scraping
Website content scraping for knowledge base enrichment, performed only at customer request
Data: Publicly accessible URLs and their content
United States
Google Places
Business Data Enrichment
Business profile enrichment during onboarding and agent setup
Data: Business name, address, and publicly listed business details
United States
Google Calendar
Appointment Scheduling
Calendar availability and appointment booking, only when customer connects their Google account via OAuth
Data: Calendar events and availability, only when explicitly connected
United States
Notes
AI language model providers receive conversation context to generate responses in real time. ProFront uses commercially reasonable measures to minimize the personal data included in these requests. Under our service agreements, these providers do not use conversation content to train their models, and any provider-side retention is limited to transient operational purposes such as response caching and abuse prevention.
ProFront may route AI inference requests through multiple model providers depending on availability, performance, and configuration. All such providers operate under equivalent data handling commitments.
Our error monitoring provider receives diagnostic data about application faults. Reports are configured to omit IP addresses, request headers, cookies, request bodies, and URL query strings, and a filtering step removes recognized personal data from the diagnostic context attached to each report. Performance tracing is disabled. Because an error message, and the stack trace around it, can quote the data that caused the fault, we cannot guarantee that no personal data ever appears in a fault report. This data is retained only for the provider's standard diagnostic retention period.
ProFront reviews subprocessors periodically and updates this page when providers are added, replaced, or removed. Material changes are communicated to customers via email or in-app notice.
For questions about this list or our data practices, contact us at privacy@profront.ai.