Subprocessors

Who else touches your data.

AGCONN relies on a small set of infrastructure providers to operate the platform. Each one has signed a written data processing agreement, sees only the data needed for its role, and is named here so you can audit the chain end to end. This page is the single source of truth — when it changes, the privacy policy is updated to match.

Last reviewed · 2026-05-09

  • ProviderSupabase
    Purpose

    Postgres database and object storage — the system of record for every account, job posting, application, certificate, and uploaded file.

    Data category

    All application data, including resumes, certificates, and identity records

    Location

    United States

    View DPA
  • ProviderGoogle Cloud Platform
    Purpose

    Application hosting — runs the AGCONN web app, API, and background workers on Google Kubernetes Engine, with container images stored in Artifact Registry.

    Data category

    App runtime traffic and logs (transient); IP and request metadata

    Location

    us-west1 · Oregon, USA

    View DPA
  • ProviderCloudflare
    Purpose

    Content delivery network, DNS, TLS termination, bot management, and DDoS protection — every visitor's request flows through Cloudflare before reaching the origin.

    Data category

    IP address, TLS metadata, request URL and headers, bot/threat signals

    Location

    Global edge network

    View DPA
  • ProviderClerk
    Purpose

    Authentication service — phone OTP, magic-link email, password and Google OAuth sign-in flows; session and token management.

    Data category

    Phone number, email, password hash, OAuth tokens, session metadata

    Location

    United States

    View DPA
  • ProviderGoogle (OAuth sign-in)
    Purpose

    Google sign-in (OAuth 2.0) — used only when an employer or admin chooses to sign in with Google instead of email or phone.

    Data category

    Email address, name, and Google account ID. We do not request access to contacts, calendar, or drive.

    Location

    Global

    View DPA
  • ProviderTwilio
    Purpose

    SMS delivery — sends one-time codes, application status updates, and the SMS alerts workers have opted into.

    Data category

    Phone number, message body, delivery status

    Location

    United States

    View DPA
  • ProviderResend
    Purpose

    Transactional email delivery — sign-in codes, account notifications, certificate-issuance receipts, billing receipts.

    Data category

    Email address, message body, delivery status

    Location

    United States

    View DPA
  • ProviderStripe
    Purpose

    Employer billing — Pro and Enterprise plan subscriptions, invoicing, and payment processing. Workers never enter payment information.

    Data category

    Employer billing details (name, business address, tax ID, payment method) and payment metadata

    Location

    United States

    View DPA
  • ProviderPostHog
    Purpose

    Product analytics — measures which features are used and which are broken so we can improve the platform. Only loads after analytics consent and respects the GPC signal automatically.

    Data category

    IP address, device and browser data, page-view events, custom feature events (opt-in only)

    Location

    United States · us.i.posthog.com

    View DPA
  • ProviderSentry
    Purpose

    Application error diagnostics — captures unhandled exceptions and performance traces so engineers can fix bugs.

    Data category

    IP address, user agent, error stack trace, request URL and breadcrumbs (sensitive fields scrubbed)

    Location

    United States

    View DPA
Our commitments to you.

These rules apply to every subprocessor on this list, present and future.

Written DPA before any data flows

Every provider on this list has executed a data processing agreement that obligates them to process AGCONN data only on our instructions, apply industry-standard security, support data-subject requests, and notify us of any incident.

Minimum necessary access

Each subprocessor sees only the data category needed for its role. We do not pool data across providers, and we do not enable provider-side cross-context tracking, profiling, or advertising features.

30 days notice for material changes

When we add a subprocessor that handles personal information, replace one, or change a category of data shared, we update this page and notify active account holders by email and SMS at least 30 days before the change takes effect.

No sale, no advertising sharing

We do not sell personal information to any subprocessor or anyone else. We do not share personal information for cross-context behavioral advertising. The Global Privacy Control (GPC) signal is honored automatically.

Who's not on this list, and why.

Some providers people expect to see — Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, advertising or retargeting platforms, data brokers, identity-verification vendors that scan government IDs — are deliberately absent. We don't use them. If a subprocessor not on this page ever processes your data, that's a violation of our own policy and we want to hear about it at [email protected].