Last updated: 17 July 2026
To run ProposalBolt we rely on a small set of trusted infrastructure providers ("subprocessors"). Each processes only the data it needs to perform its function, under its own security program and data-processing terms. This is the current list; we'll update this page before adding a new subprocessor that handles customer data.
| Subprocessor | Purpose | Data processed | Primary hosting |
|---|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage | Account, workspace, proposal, signature and payment-record data; uploaded files | AWS (region configured for the project) |
| Vercel | Application hosting, CDN and serverless functions | HTTP request metadata; content in transit | Global edge network |
| Razorpay | Payment collection, subscriptions and payouts | Payment and payout details, transaction records | India |
| Resend | Transactional & notification email | Recipient email address and message content | United States / EU |
| Google (Gemini API) | AI proposal drafting and editing | The prompt text and document context you submit for generation | Google Cloud |
Data is encrypted in transit (TLS) to and from every subprocessor, and at rest within our database provider. Access to production systems is limited and authenticated. Each subprocessor is engaged under its own data-processing agreement.
When you use AI features, the text you choose to generate or edit is sent to the AI provider to produce a response. We do not sell your data, and we do not use your client documents to train models.
We will post material changes to this list here. Enterprise customers can request advance email notice of new subprocessors as part of their agreement — contact us to arrange it.
Questions about this list or our data practices? Email our team. See also our Data Processing Addendum, Security overview and Privacy Policy.