Third-Party Vendors
Effective Last updated
At Cleft, we carefully select third-party vendors who share our commitment to data protection and user privacy. This page provides complete transparency about every vendor we work with.
All vendors meet our data protection standards and comply with GDPR, CCPA, and other applicable privacy regulations.
Vendor overview
- 37 vendors in total.
- 20 vendors process personal identifiable information (PII), such as notes, account info, or payment details. All have signed Data Processing Agreements.
- 17 vendors handle no personal customer data; they support our business operations, marketing, and development.
Vendors processing personal data
These 20 vendors handle personal identifiable information and are subject to our strictest data protection requirements.
Cloud infrastructure and data processing
Amazon Web Services (AWS)Processes personal data
Services: Hosting and managing cloud infrastructure, and transactional email delivery (Amazon SES)
Personal data: Hosts encrypted user data; sends account, billing, and security email
Data centers: EU, Global (multiple locations)
HQ: Seattle, Washington, USA
Secure hosting infrastructure only. AWS provides encrypted storage but cannot access your actual notes or content. Transactional email (account, billing, security notices) is sent via Amazon SES.
AppleProcesses personal data
Services: Developing and distributing applications through the Apple ecosystem
Personal data: App Store account data and on-device processing
Data centers: Global (multiple locations)
HQ: Cupertino, California, USA
The Whisper transcription model runs locally on your device. Apple handles App Store transactions but doesn't access your Cleft content.
CloudflareProcesses personal data
Services: CDN, DNS, and DDoS protection services
Personal data: Website traffic and DNS queries
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Website traffic patterns and DNS queries only. No access to Cleft content or user data.
AI processing partners
OpenAIProcesses personal data
Services: Primary LLM provider for note enhancement
Personal data: Processes transcript text only
HQ: San Francisco, California, USA
Transcript text only (never audio) for AI processing. Your data is never used for model training.
GroqProcesses personal data
Services: Backup LLM provider to ensure service reliability
Personal data: Processes transcript text only
Data centers: Global (multiple locations)
HQ: Mountain View, California, USA
Alternative AI processor for text enhancement. Same privacy protections as OpenAI.
Payment and billing
StripeProcesses personal data
Services: Handling online transactions securely
Personal data: Payment processing (PCI compliant)
HQ: San Francisco, California, USA
Payment processing only. We never see your actual payment details.
RevenueCatProcesses personal data
Services: Managing in-app subscriptions and purchases
Personal data: Subscription data and analytics
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Subscription management and analytics. No access to your notes or content.
Customer management and communications
HubSpotProcesses personal data
Services: Managing marketing activities and customer interactions
Personal data: Contact info and support interactions
Data centers: EU
HQ: Cambridge, Massachusetts, USA
Contact information and customer support interactions only.
MailerliteProcesses personal data
Services: Marketing email campaigns only (newsletters and opt-in updates)
Personal data: Email addresses for marketing (opt-in)
Data centers: Global (multiple locations)
HQ: Vilnius, Lithuania
Marketing only: email addresses for newsletter delivery (opt-in). Not used for transactional or account email, and no access to personal content.
Business intelligence and monitoring
Google WorkspaceProcesses personal data
Services: Communication, document creation, and collaboration
Personal data: Internal business communications
Data centers: EU
HQ: Mountain View, California, USA
Internal team communications only. No user data processing.
MetabaseProcesses personal data
Services: Analysing business data and generating reports
Personal data: Aggregated business analytics
Data centers: EU (self-hosted)
HQ: N/A (open-source project)
Aggregated business metrics only. No individual user data.
1PasswordProcesses personal data
Services: Team password management and secure credential storage
Personal data: Internal team credentials and access management
Data centers: EU
HQ: Toronto, Ontario, Canada
Internal team passwords and credentials only. No customer data or personal information.
Website and design services
WebflowRetiredProcesses personal data
Retired: Being retired in 2026. Our public website now runs on Cloudflare (listed under Cloud infrastructure above); Webflow no longer hosts the site or receives form submissions.
Services: Previously designed and hosted our public-facing website and forms
Personal data: Website form submissions (historical)
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Formerly handled website contact forms and landing page interactions. No new data is sent to Webflow.
SoFriendlyProcesses personal data
Services: Enhancing user experience through design consulting
Personal data: Design consultation materials
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Design assets and user experience materials only.
Scheduling, integrations, and automation
NangoProcesses personal data
Services: OAuth integration management (e.g. the Notion connection)
Personal data: Integration authorization tokens
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Manages the OAuth tokens for integrations you connect (such as Notion). Handles authorization only, not your note content. DPA on file.
FilloutProcesses personal data
Services: Form building and data collection (replaces SavvyCal)
Personal data: Form submissions and contact information
Data centers: Global (multiple locations)
HQ: San Francisco, California, USA
Form submissions and scheduling data only.
Business operations vendors
These 17 vendors support our business operations, marketing, and development but never access your personal information or content.
Social media and marketing
Facebook / MetaNo personal data
Services: Social media marketing and brand engagement
LinkedInNo personal data
Services: Social media marketing, talent and brand engagement
Development and collaboration
SlackNo personal data
Services: Facilitating internal communication and collaboration
Anthropic (Claude)No personal data
Services: Internal development and business operations (coding, drafting, support triage)
Used internally for development and running the business. It does not process your notes or content. Any review of inbound feedback or email is done on text we manually scrub of personal data first, human-directed and never automated.
Documentation and content
MintlifyNo personal data
Services: Documentation platform hosting (replaced GitBook)
Public documentation content only.
Screen StudioNo personal data
Services: Product video creation
Media and podcast
Analytics (anonymous only)
Fathom AnalyticsNo personal data
Services: Collecting website analytics with a focus on privacy
Anonymous page views and bounded website interaction events only. No personal data collected.
Vendor data practices
Data retention. Our vendors are contractually required to retain data only as long as necessary for service delivery, delete data upon our request, and follow the same data retention policies we maintain.
Data security. All vendors must encrypt data in transit and at rest, maintain SOC 2 Type II compliance or equivalent, undergo regular security audits, and report any security incidents within 24 hours.
Data access.Vendor access to your data is limited to what’s necessary for service delivery, logged and monitored, subject to strict confidentiality agreements, and never used for the vendor’s own purposes.
Vendor selection process
We maintain strict criteria when selecting third-party vendors to ensure the highest level of data protection:
- Privacy standards: GDPR, CCPA, and international privacy law compliance.
- Security certifications: we prefer and prioritize vendors aligned with SOC 2 Type II, ISO 27001, and other recognized industry security standards.
- Data Processing Agreements: clear contractual obligations about data handling.
- Incident response: a proven track record of security and transparency.
- Business continuity: financial stability and reliable service delivery.
Your rights regarding vendor data
You have the right to:
- Know which vendors process your data.
- Request deletion of your data from all vendors.
- Receive copies of vendor DPAs upon request.
- Be notified of any vendor data breaches.
- Opt out of specific vendor services where possible.
Contact
For questions about our vendors or data processing, including vendor DPA requests, contact our Data Protection Officer at dpo@cleftnotes.com or our general privacy inbox at privacy@cleftnotes.com. If you have concerns about any of our vendors or their data practices, the DPO is the right contact.
