Legal
Subprocessors
Last updated August 29, 2026 · TryGTM
Providers used by the product, their purpose and the data they may process. Availability depends on the features and connections used. Contact us for the current contractual list, processing locations and retention terms.
01Providers and processing
Core infrastructure uses Vercel for the web application, Supabase for database and authentication, and Fly.io for separately hosted services. Stripe processes payments. Resend handles domain email and transactional email; Unipile provides connected account transport. OpenRouter routes model requests to the selected model provider. Firecrawl reads websites, Apify retrieves public activity, ZeroBounce verifies email addresses, and Upstash provides shared rate limiting. Optional SMS uses Twilio. Prospect searches use a licensed data provider; contact us for the current named provider and contractual terms.
Model requests can contain personal data and conversation content. We do not claim that prompts are anonymous. Model provider selection, retention and training settings require account-level controls; contact support@trygtm.com for the current model and upstream data providers and their contractual terms before sending data subject to specific requirements.
02The list
| Category | What reaches it | Region |
|---|---|---|
Application hosting Runs the product and the scheduled jobs behind it. | Everything in your workspace, in transit and at rest during processing. | Confirm current processing locations |
Database and authentication Stores workspace data and authenticates people into it. | Accounts, contacts, conversations, campaigns, ledgers. | Confirm current processing locations |
Prospect data and enrichment Answers who matches your ICP, and reveals contact details for a named person. | Search filters, and the identifiers of the people revealed. | Confirm current processing locations |
Email delivery and inbound Sends outbound mail from your attached sending domains and receives replies. | Message content, recipient addresses, delivery events. | Confirm current processing locations |
LinkedIn connectivity Connects your own LinkedIn account so it can search, invite and message. | Your account credential in transit only, and the messages sent through it. | Confirm current processing locations |
Public activity observation Watches what a known contact recently engaged with publicly, for intent scoring. | Public profile URLs of contacts already in your workspace. | Confirm current processing locations |
Web reading Reads a company's public website to build an ICP and a company profile. | Requested public URLs and retrieved page content, which may contain personal data. | Confirm current processing locations |
Model inference Qualification, copywriting, reply classification and the agent screen. | Relevant contact names, professional profiles and research, company facts, and message content needed for qualification, drafting, reply handling and quality review. | Confirm current processing locations |
Payments Subscriptions, credit purchases and invoices. | Billing contact and payment method. We never see the card. | Confirm current processing locations |
Support and product email Transactional mail to you, and support conversations. | Your name, your email address, the contents of your ticket. | Confirm current processing locations |
03Data handling boundaries
- Credentials. A LinkedIn password is forwarded within a single request and is never persisted, never logged and never returned.
- Model inputs and diagnostics. Relevant personal data can be processed by model providers. Operational error and CSP reporting use event codes and identifiers rather than message bodies, prompts, credentials or full request URLs.
- Payment card details. Handled entirely by the payment provider. We store customer and subscription identifiers, invoices and billing state, not full card details.
04Changes
We notify before adding a subprocessor that touches customer data, and enterprise agreements carry a right to object. Removals happen without notice, because a vendor leaving the stack is not a change you need protecting from.