— Subprocessors
Every third party that touches your data.
Last updated: 2026-08-17
These are the vendors Mallin uses to operate the service. Each one has a specific role, processes a specific subset of your data, and operates under its own data-processing terms. We update this page whenever we add or remove a vendor — we will not silently expand the list.
| Vendor | Purpose | What we send | Region | Status |
|---|---|---|---|---|
| Anthropic Privacy terms ↗ | AI model inference (Claude API) — brief generation, chat replies, stakeholder analysis | Deal substrate, call transcripts, your prompts, and the questions you ask the in-app help widget. No auth tokens, no PII outside deal context. | United States | Active |
| Supabase Privacy terms ↗ | Primary database (Postgres) + storage for customer data, accounts, deals, notes, audit logs | All customer data at rest. Encrypted with AES-256. | United States (AWS US-East) | Active |
| Clerk Privacy terms ↗ | Authentication, session management, multi-factor authentication, organization membership | Account email, hashed password, MFA secrets, session tokens. No deal data. | United States | Active |
| Vercel Privacy terms ↗ | Web hosting, edge runtime, serverless function execution, deployment platform | All HTTP traffic transits Vercel edge. Application logs (retained ~30 days). Secrets stored in encrypted env-var store. | United States (primary) + global edge for static assets | Active |
| Resend Privacy terms ↗ | Transactional email (pilot signup notifications, contact form deliveries, account emails) | Recipient email, message subject + body. No deal data. | United States | Active |
| RB2B (website visitor identification) Privacy terms ↗ | Identifies businesses visiting Mallin's public marketing pages and, for eligible U.S.-based visitors, may identify an associated professional profile, so Mallin can understand prospective-customer interest and conduct business-to-business outreach. Enabled only for visitors who geolocate to the United States; does not run on authenticated Mallin application pages. | Public-page visit information including IP address, browser/user-agent information, page and referring-page URLs, timestamps, cookies or similar identifiers, and professional/company information generated through RB2B's identification and enrichment services. Not connected by Mallin to authenticated account, deal, or workspace data. | United States-based service. Mallin enables RB2B only for visitors who geolocate to the United States; person-level identification is limited to U.S.-based visitors. | Active |
| LinkedIn (advertising and conversion measurement) Privacy terms ↗ | Measures which LinkedIn advertisements lead to visits to Mallin's public marketing pages, and supports advertising to people who have visited those pages. Loaded only for visitors who geolocate to the United States; does not run on authenticated Mallin application pages. Mallin does not upload customer, contact, or lead lists to LinkedIn. | Public-page visit information including IP address, browser/user-agent information, page and referring-page URLs, timestamps, and cookies or similar identifiers, which LinkedIn may associate with a LinkedIn member. No account, deal, call, or workspace content. | LinkedIn Corporation, United States, operating global infrastructure. Mallin loads the Insight Tag only for visitors who geolocate to the United States. | Active |
| Stripe Privacy terms ↗ | Subscription billing and payment processing | Billing email, subscription status, payment method details handled entirely by Stripe. No deal data, no transcripts. | United States | Active |
| Brandfetch Privacy terms ↗ | Company logo and brand asset lookup for briefs and decks | The public domain name of the company being researched. No customer data, no deal content. | United States | Active |
| Google (when connected) Privacy terms ↗ | Gmail drafting and Google Calendar reading. Two separate grants: you can hold either without the other. | Gmail: permission to create drafts in your Drafts folder, and to send one message at the moment you press Send. We never read your inbox or existing mail. Calendar: the events on your own calendar (time, title, invitees, meeting link). Read only by default; in workspaces that have turned on booking a call from inside Mallin, the grant also allows creating the single event you book, and never editing or deleting one it did not create. Your Google email address, to show which account is connected. | Determined by your Google Workspace account | Active |
| Microsoft (when connected) Privacy terms ↗ | Outlook drafting and Outlook Calendar reading. Two separate grants: you can hold either without the other, and an administrator can approve one without the other. | Calendar: the events on your own calendar (time, title, invitees, meeting link) read only. We do not request Calendars.ReadWrite, and we do not request access to calendars other people shared with you. Mail: permission to place a draft in your Drafts folder. We never request Mail.Send, so Mallin cannot send from your Outlook account. Your Microsoft email address, to show which account is connected. | Determined by your Microsoft 365 tenant | Active |
| HubSpot (when connected) Privacy terms ↗ | CRM integration — Mallin reads deal/contact/account data and writes back notes, activities, tasks per your write-through configuration | Whatever your HubSpot OAuth scopes grant. Governed by your HubSpot tenant's permissions and your CRM admin. | Determined by your HubSpot account | Active |
| Salesforce (when connected) Privacy terms ↗ | CRM integration (planned) — same pattern as HubSpot | Determined by your Salesforce OAuth scopes | Determined by your Salesforce org | Planned |
| Pipedrive (when connected) Privacy terms ↗ | CRM integration (planned) — same pattern as HubSpot | Determined by your Pipedrive OAuth scopes | Determined by your Pipedrive account | Planned |
| GitHub Privacy terms ↗ | Source code repository, deployment trigger (CI/CD), engineering audit trail | Source code only. No customer data. No deal substrate. | United States | Active |
How we evaluate subprocessors
- Each subprocessor must have a published data-handling policy or DPA we can review.
- Each must operate under encryption (in transit + at rest) standards equivalent to ours.
- Where possible, we choose subprocessors with current SOC 2 or equivalent third-party attestation.
- We minimize what we send to each — the data table above lists the actual scope, not the contractual maximum.
Changes
When we add a new subprocessor, this page is updated and the change appears in the "Last updated" date at the top. Customers on active pilots are notified by email of new subprocessors at least 14 days before they go live.
Questions
Subprocessor questions, DPA requests, customer-specific arrangements: brendan@mallin.io.