Subprocessors and data flow
Last updated: August 13, 2026
This page lists the vendors TaskGeniusAI uses to run the product, optional tools that only receive data when configured or consented, and third parties a customer chooses to connect. It is the public map referenced by the Privacy Policy and the Data Processing Addendum.
How data moves
- Sign-in. Operators authenticate with Supabase Auth (magic link, password, OAuth, or recovery). Sessions stay on the TaskGenius web app.
- Connect sources. The customer grants Google, Meta, CallRail, JustCall, Housecall Pro, CMS, or notification destinations. Credentials are stored encrypted; we use them only for that workspace.
- Ingest and normalize. Webhooks and pull-sync land in raw ingest, then workers normalize into leads, calls, jobs, and spend facts. Hosting is Vercel (web) plus the workers host (queues).
- Analyze. Dashboards and recommendations read normalized facts. When AI features are enabled, summarized workspace facts may be sent to OpenAI or Anthropic.
- Bill and notify. Stripe handles checkout and subscription state. Resend sends invites, dunning, and support mail. Optional Telegram or Slack destinations receive operator alerts the customer enables.
- Operate and retain. Axiom receives application logs. Sentry receives exceptions only if SENTRY_DSN is set. Raw ingest payloads and call transcripts are redacted on a 180-day schedule. Account deletion cancels Stripe and removes the operator identity.
Platform subprocessors
Vendors we engage to host, authenticate, bill, email, orchestrate, log, and run AI features.
| Provider | Role | Data | Region |
|---|---|---|---|
| Vercel | Web application hosting, CDN, and serverless functions | Account session traffic, workspace UI requests, logs | United States / Vercel regions |
| Supabase | Authentication and primary Postgres database | Account identity, workspace and business records, encrypted secrets | United States / Supabase project region |
| Stripe | Subscription checkout, invoices, and customer portal | Billing email, customer and subscription ids — not full card numbers | United States / Stripe regions |
| Resend | Transactional email (invites, billing notices, support) | Recipient email and message content we send | United States |
| Expo | Mobile push delivery — relays alerts to Apple Push Notification service for the iOS app | Device push token and the notification title/body we send | United States |
| Upstash | Redis rate limiting for public auth and webhooks | Request IP and route keys — not message bodies | United States / Upstash regions |
| Amazon Web Services (S3) | Signed image uploads (avatars and similar objects) | Uploaded image files and object keys | United States / configured AWS region |
| Inngest | Scheduled and event-driven workflow orchestration | Job metadata and account identifiers needed to run crons | United States |
| Axiom | Application and worker logs | Operational logs; error messages may include paths or ids | United States / EU (Axiom region) |
| OpenAI | Model inference for recommendations and operator Ask | Workspace facts and prompts we send to the model | United States |
| Anthropic | Alternate model inference when that provider is configured | Workspace facts and prompts we send to the model | United States |
Optional processors
These receive data only when the matching environment variable is set or the visitor accepts analytics on /cookies.
| Provider | Role | Data | Region |
|---|---|---|---|
| Sentry | Exception monitoring when SENTRY_DSN is set | Error message, stack, route — sendDefaultPii is off | United States / Sentry region |
| Vercel Analytics | Consent-gated product analytics | Page views and coarse device signals | United States / Vercel regions |
| Datah | Consent-gated product analytics | Page views on the marketing and app host | Provider regions |
| Seline | Consent-gated product analytics | Page views on the marketing and app host | Provider regions |
Customer-directed processors
Connected only when a workspace operator installs them. We process their data on that customer's instruction.
| Provider | Role | Data | Region |
|---|---|---|---|
| Ads, Analytics, Search Console, Business Profile, Local Services Ads | Campaign, lead, listing, and analytics records the customer grants | Google regions | |
| Meta | Meta Ads connection | Ad account performance the customer grants | Meta regions |
| CallRail | Call tracking and transcripts the customer connects | Call metadata, recordings/transcripts, attribution | United States |
| JustCall | Outbound / sales-dialer connection | Call metadata, recordings/transcripts, agent notes | United States / JustCall regions |
| Housecall Pro | CRM / job sync (typically via Zapier webhook) | Customers, jobs, and booking facts the customer sends | United States |
| Zapier | Customer-built webhook recipes (for example Housecall Pro) | Payloads the customer's Zap forwards to TaskGenius | United States |
| Telegram | Optional operator notification bot | Chat ids and notification copy the operator enables | Telegram regions |
| Slack | Optional workspace notification destination | Channel destination and notification copy | Slack regions |
| Framer | Optional Website CMS pull | Published site pages the customer grants | Framer regions |
| Wix | Optional Website CMS pull | Published site pages the customer grants | Wix regions |
Questions: taskgeniusai@gmail.com.