Vendors & Subprocessors

Third-party services that support JourneyLoop

Our Transparency Commitment

We believe in complete transparency about which third-party vendors have access to data on our platform. This page lists all vendors that may process or store data as part of providing JourneyLoop services.

For HIPAA compliance purposes, vendors that may handle PHI require Business Associate Agreements (BAAs). See our BAA Status page for details on which vendors have signed BAAs.

All Vendors

Vendor Category Purpose Data Processed BAA
Heroku (Salesforce)
Compliance ↗
Infrastructure Application hosting All application data. HIPAA-compliant options available. SOC 2, ISO 27001, PCI DSS certified. Available
Supabase
HIPAA Info ↗
Infrastructure Primary database All structured data (encrypted at rest). HIPAA compliance available. Upgrade Required
Redis Cloud
Security ↗
Infrastructure Caching & task queue Temporary session data for background processing - no PHI stored Not Required
Google Cloud Storage
HIPAA Compliance ↗
Infrastructure File storage Uploaded files, transcripts Available
OpenAI
Privacy ↗
AI Processing AI content analysis & generation Session transcripts, coaching insights Available
Google AI (Gemini)
Compliance ↗
AI Processing Text-to-speech generation Content for voice synthesis Available
AI Processing Session recording & storage Audio, video, and transcripts stored with encryption Available
Make.com
Security ↗
Email Email routing & automation Notification content (no PHI) Not Required
Stripe
Privacy ↗
Payments Payment processing Billing info only (no PHI) Not Required
Sentry
Security ↗
Monitoring Error tracking & performance Error logs, stack traces (no PHI) Not Required
Firecrawl
Website ↗
Research Web content extraction Public web content only (no PHI) Not Required
Serper
Website ↗
Research Search API Search queries only (no PHI) Not Required
Google Calendar API
HIPAA Compliance ↗
Integration Calendar integration Session scheduling data Available

Data Processing Notes

  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • PHI Handling: Currently, no vendor receives identifiable PHI. When PHI is enabled, only BAA-signed vendors will have access
  • Data Minimization: Vendors only receive data necessary for their specific function
  • Regular Audits: We regularly review vendor access and update this list