Legal · Kontracks
Sub-processors
Last updated June 19, 2026 · The current list of third parties Kontracks engages to process Personal Data on behalf of Customers.
Kontracks ("we", "us") engages the third-party service providers listed below ("Sub-processors") to deliver the Service. Each Sub-processor is bound by a written data-protection contract with Kontracks that imposes substantially similar obligations to those in the Kontracks Data Processing Addendum.
Subscribe to updates. To receive email notification whenever this list changes, email
privacy@kontracks.com with the subject "Subscribe to Sub-processor Updates" from the administrator address on your account. Notifications are sent at least fifteen (15) days before a new Sub-processor begins processing Personal Data.
Infrastructure & hosting
| Vendor | Purpose | Data processed | Region |
| Vercel, Inc. | Hosting of the web application, API edge network, CDN, image optimization, cron execution. | All Customer Data in transit; ephemeral compute caches. | United States |
| Neon, Inc. | Managed PostgreSQL database hosting and automated backups. | All structured Customer Data at rest. | United States |
| Google LLC (Google Cloud Platform / Cloud Storage) | Object storage for photos, attachments, generated PDFs, customer document uploads, brand assets. | Files Customer or End Customers upload; generated PDFs. | United States |
Communications
| Vendor | Purpose | Data processed | Region |
| Telnyx LLC | SMS / MMS delivery, dedicated phone-number provisioning, 10DLC brand and campaign registration on behalf of the Customer with The Campaign Registry (TCR). | Recipient phone numbers, message body, sender identity, delivery receipts, consent metadata. | United States |
| The Campaign Registry (TCR) | Carrier-mandated brand and campaign registration for 10DLC SMS originating from U.S. long codes. | Customer's brand identity (legal name, EIN, address, contact, vertical); campaign description and sample messages. | United States |
| Resend, Inc. | Outbound transactional and marketing email delivery on Customer-verified domains. | Recipient email, sender identity, subject and body of email, delivery receipts, open and click events. | United States |
| Google LLC (Gmail API) | Inbound and outbound email sync when Customer connects a Gmail account. | Email metadata and content for the connected Gmail account, scoped to identified customer threads. | United States |
| Microsoft Corporation (Microsoft Graph) | Inbound and outbound email sync when Customer connects a Microsoft 365 / Outlook account. | Email metadata and content for the connected Microsoft account, scoped to identified customer threads. | United States |
Calendar, contacts & files
| Vendor | Purpose | Data processed | Region |
| Google LLC (Google Calendar API) | Two-way sync of jobs, appointments, and crew schedules when Customer connects a Google Calendar account. | Event titles, times, locations (job-site addresses), and notes derived from the Customer's jobs and appointments. | United States |
| Google LLC (Google People / Contacts API) | Sync of customer and lead contact records when Customer connects Google Contacts. | Contact names, phone numbers, email addresses, and postal addresses for the synced subset. | United States |
| Google LLC (Google Drive API) | Storage and retrieval of documents, photos, and generated PDFs when Customer connects Google Drive. | Files the Customer or its Authorized Users choose to sync to or from the connected Drive. | United States |
Payments, accounting & suppliers
| Vendor | Purpose | Data processed | Region |
| Stripe, Inc. | Online invoice payment processing (card, ACH, Apple Pay, Google Pay); platform-side subscription billing for Kontracks itself; dispute and refund handling. | Cardholder data tokenized by Stripe (Kontracks does not store card numbers); payment intent IDs; payout-related metadata. | United States |
| Intuit Inc. (QuickBooks Online) | Two-way synchronization of customers, invoices, payments, credit memos, and refund receipts between Kontracks and the Customer's own QuickBooks Online company, only when Customer connects QBO. | Contact identity, invoice line items, payment records, credit-memo records, and refund records for the synced subset. | United States |
| QXO, Inc. (building-materials distribution) | Live wholesale materials catalog and pricing, and order placement, when Customer connects a QXO supplier account. | Product SKUs and quantities; when an order is placed, the job-site delivery address and the ordering contact's name and phone number. | United States |
Maps & addresses
| Vendor | Purpose | Data processed | Region |
| Google LLC (Maps Platform, Places, Geocoding) | Address autocomplete on intake forms; address-to-coordinate geocoding for the satellite measurement tool. | Partial or complete street addresses entered into Kontracks address fields. | United States |
| Apple Inc. (MapKit JS) | Satellite imagery rendering for the in-app roof and surface measurement tools. | Approximate property coordinates derived from geocoded addresses. | United States |
AI providers
The Service exposes AI features (in-app assistant, pricing math, draft email, supplement writer, photo material identification, dormant-lead scoring, sentiment scanning, and others). Each AI feature routes only the minimum payload required to compute the result to the provider configured by the Customer. AI providers do not train on Customer Data: each provider's API contract excludes Kontracks-routed data from model training by default.
| Vendor | Purpose | Data processed | Region |
| Anthropic, PBC (Claude) | Default LLM for assistant features, draft email, supplement writer, pricing-math narrative, photo vision identification. | Redacted text and image payloads necessary to compute the requested result. | United States |
| OpenAI, L.L.C. | Alternative LLM when Customer selects OpenAI in the AI Settings. | Redacted text payloads necessary to compute the requested result. | United States |
| Google LLC (Gemini / Vertex AI) | Alternative LLM when Customer selects Google AI in the AI Settings. | Redacted text payloads necessary to compute the requested result. | United States |
Operations, observability, deliverability
| Vendor | Purpose | Data processed | Region |
| Cloudflare, Inc. | DNS resolution, edge WAF, DDoS mitigation, and bot detection on public-facing routes where engaged. | Connection metadata (IP address, user-agent, request headers). | United States |
| Google LLC (Workspace) | Internal corporate email, document management, and support inbox at the kontracks.com domain. | Inbound support correspondence Customer or End Customers send to Kontracks email addresses. | United States |
Notes
- Self-hosted by the Customer. Where Customer provides its own API keys or connects its own account for a Third-Party Service (e.g., Customer-owned QuickBooks Online connection, Customer-owned Gmail/Microsoft account, Customer-owned Google Calendar/Contacts/Drive connection, Customer-owned QXO supplier account, Customer-owned AI provider account), the Customer is the controller of that integration's data flow and the Third-Party Service is engaged under the Customer's contract with that provider — not as a Kontracks Sub-processor.
- Measurement report import (not a Sub-processor). When a Customer uploads an EagleView or Roofr measurement report (PDF) that the Customer generated using its own EagleView or Roofr account, Kontracks reads the measurement data out of that file to populate the job. No Customer Data is transmitted to EagleView or Roofr by Kontracks, and neither company is a Kontracks Sub-processor.
- Calendar feeds (not a Sub-processor). Kontracks can publish a read-only calendar feed (iCal / .ics) that the Customer subscribes to in Apple Calendar or another calendar application. This is a one-way feed delivered to the Customer's own device and does not engage a Sub-processor.
- Optional Sub-processors. Sub-processors listed above for features that the Customer must explicitly enable (e.g., Telnyx for SMS, Intuit for QBO sync) are only engaged when the Customer enables the corresponding feature.
- Cookies and analytics. See the Cookie Policy for details on first-party and any third-party cookies.
- Successors in interest. If a Sub-processor is acquired or merged, the successor entity is considered the Sub-processor for purposes of this list, subject to the notification process above.
Historical record
For audit purposes, a record of past changes to this list is available on request to privacy@kontracks.com.