---
title: "Subprocessors"
description: "Third-party service and support providers that may process customer information to help Autopilot provide, secure, support, maintain, and operate the service."
source: "https://legal.aplt.ai/legal/subprocessors"
updated: "2026-07-08T22:26:38.205202+00:00"
product: Autopilot
content_type: legal
---

# Subprocessors

Third-party service and support providers that may process customer information to help Autopilot provide, secure, support, maintain, and operate the service.

This Subprocessors page describes third-party providers used by Autopilot Limited ("Autopilot", "we", "our", or "us") to help provide, secure, support, maintain, and operate the Autopilot service.

Autopilot uses selected third-party service providers to help provide, secure, support, maintain, and operate the Autopilot service. The providers listed below may process customer information in connection with service delivery, billing, support, security, maintenance, or operational activities. We group these providers into service subprocessors, internal operations and support providers, and other third-party service providers that support product functionality but may process certain data as independent controllers or equivalent legal roles under their own terms.

This page should be read with the [Privacy Policy](/legal/privacy) and [Security & Trust](/legal/security-trust) page for related privacy and security information.

In this documentation, internal operations and support providers may also be referred to as Operational Providers. Other third-party service providers may be described separately where their terms identify them as independent controllers or equivalent legal roles rather than conventional service subprocessors.

Not every provider processes every category of customer information. Provider access depends on the enabled Autopilot features, customer configuration, support activity, and the specific data a user chooses to submit.

Provider location is a high-level provider location indicator only. It does not promise data residency or limit processing to one country, region, or facility.

## Service subprocessors

These providers are involved in delivering Autopilot itself. Customers will most commonly care about this category because these services can be part of the core product, infrastructure, email, billing, or customer-facing AI feature path.

| Subprocessor | Provider category | Purpose | Customer information that may be processed | Provider location | Vendor information |
| --- | --- | --- | --- | --- | --- |
| Vercel Inc. | Hosting / deployment | Hosting, deployment, edge network, observability, and related infrastructure for Autopilot web properties. | Application content, usage data, IP addresses, device/browser data, logs, and diagnostic data processed through hosted services. | Provider-operated regions; see provider documentation. | [Vercel Trust Center](https://security.vercel.com) and [Vercel DPA](https://vercel.com/legal/dpa) |
| Supabase, Inc. | Database / authentication / storage | Managed database, authentication, storage, APIs, and related backend services. | Account, user, customer, dealership, workflow, and application information stored or processed by Autopilot features. | Provider-operated regions; see provider documentation. | [Supabase DPA](https://supabase.com/legal/dpa) and [Supabase Trust Center](https://trust.supabase.io) |
| Plus Five Five, Inc. (Resend) | Email / communications | Transactional email delivery and email-related service operations. | Email addresses, message metadata, delivery events, and message content needed to send or process email. | Provider-operated regions; see provider documentation. | [Resend Subprocessors](https://resend.com/legal/subprocessors) and [Resend DPA](https://resend.com/legal/dpa) |
| Stripe, Inc. | Payment processing | Payment processing, subscriptions, billing, tax, invoicing, and related financial operations. | Customer and billing contact details, payment identifiers, transaction metadata, tax information, invoices, and subscription status. | Provider-operated regions; see provider documentation. | [Stripe Service Providers, Sub-Processors & Affiliates](https://stripe.com/legal/service-providers) and [Stripe DPA](https://stripe.com/legal/dpa) |
| Anthropic, PBC | AI model provider | AI model services for user-requested assistant, analysis, drafting, or summarisation features where enabled. | Prompts, responses, and the limited application context a user or enabled Autopilot feature submits for processing. | Provider-operated regions; see provider documentation. | [Anthropic Trust Center](https://trust.anthropic.com) and [Anthropic Subprocessors](https://trust.anthropic.com/subprocessors) |

## Internal operations and support providers

These providers are not part of the core Autopilot application path, but customer information may be processed by them when we use them for support, operations, engineering, incident response, or internal administration.

| Provider | Provider category | Purpose | Customer information that may be processed | Provider location | Vendor information |
| --- | --- | --- | --- | --- | --- |
| Google Workspace | Support / collaboration | Internal email, file collaboration, customer correspondence, and business operations. | Support emails, customer correspondence, internal notes, attachments, shared documents, and contact details. | Provider-operated regions; see provider documentation. | [Google Workspace Subprocessors](https://workspace.google.com/terms/subprocessors/) |
| Discord Inc. | Support / collaboration | Internal support coordination, customer issue triage, operational discussions, and support-related notifications. | Support tickets, customer issue reports, screenshots, logs, message excerpts, and internal discussion metadata when shared for support or operations. | Provider-operated regions; see provider documentation. | [Discord Privacy Policy](https://discord.com/privacy) and [Discord DPA](https://support.discord.com/hc/en-us/articles/37891902561687-Data-Processing-Agreement-Discord-as-a-Processor) |
| Railway Corp. | Automation / developer operations | Hosting and infrastructure for internal support tools, ticketing bots, webhook processing, and operational automations. | Ticket metadata, webhook payloads, diagnostic logs, and limited customer or account context needed for support workflows. | Provider-operated regions; see provider documentation. | [Railway DPA](https://railway.com/legal/dpa) |
| OpenAI, L.L.C. | Internal operations / AI model provider | Internal AI-assisted drafting, analysis, troubleshooting, and operational tooling used by Autopilot staff. | Prompts, responses, snippets, logs, support context, or customer information only where deliberately supplied by authorised Autopilot personnel and limited to what is reasonably necessary for troubleshooting, security, or operational support purposes consistent with this documentation. | Provider-operated regions; see provider documentation. | [OpenAI Trust Portal](https://trust.openai.com/) and [OpenAI Sub-processor List](https://openai.com/policies/sub-processor-list/) |

## Other third-party service providers and independent controllers

These providers support Autopilot functionality but may process some information as independent controllers or equivalent legal roles under their own terms. They are disclosed here for transparency because customer or user-supplied information may be sent to them when the relevant feature is used.

| Provider | Provider category | Purpose | Customer information that may be processed | Provider location | Vendor information |
| --- | --- | --- | --- | --- | --- |
| Google Maps Platform (Google Places API) | Address lookup / autocomplete | Address autocomplete and place/address lookup for customer, contact, or dealership address fields, including structured address components used for address display and reporting. | Address search text entered by authorised users, selected place IDs, formatted addresses, structured address components such as street, unit, suburb/city, region, and postcode, and usage or technical request metadata processed when the lookup is made. | Provider-operated regions; see provider documentation. | [Google Maps Platform Terms](https://cloud.google.com/maps-platform/terms), [Google Controller-Controller Data Protection Terms](https://business.safety.google/controllerterms/), and [Google Privacy Policy](https://policies.google.com/privacy) |

Google Maps Platform terms identify Google Maps APIs as Controller Services under Google's controller-controller data protection terms. Google may collect and receive data such as search terms, IP addresses, and latitude/longitude coordinates through Maps services and may use and retain that data to provide and improve Google products and services, subject to Google's terms and privacy documentation. Autopilot's current Places API use is server-side for address autocomplete and place details, rather than a browser-side map widget. Customer-visible address data returned by Google may be stored in Autopilot records when a user selects or saves an address.

## AI providers

Where Autopilot uses AI service providers, customer information submitted through Autopilot is not used by Autopilot as general product-training data or to train public AI models. AI prompts, responses, transcripts, feedback, and related context may be stored where reasonably needed to provide, support, secure, monitor, or troubleshoot the relevant feature, unless another specifically disclosed basis applies. AI providers are used only for the relevant feature, support, security, troubleshooting, or operational function.

## How providers are used

Autopilot limits provider access to what is needed for the relevant service or operational function. For example, hosting providers may process traffic and logging data to serve the application, email providers may process recipient and message data to deliver transactional emails, billing providers may process payment and subscription data, address lookup providers may process address search terms and selected place or address details, and AI providers may process prompts and context submitted to an enabled AI feature or limited context deliberately supplied for support, security, troubleshooting, or operational purposes.

Some providers may also process limited information as independent controllers or equivalent legal roles for their own compliance, security, fraud prevention, billing, tax, or legal obligations, as described in their own terms and privacy documentation.

Customers are responsible for deciding what information they enter into Autopilot and for ensuring they have the rights and notices needed for that use. Autopilot remains responsible for its use of subprocessors and support providers in accordance with applicable agreements and law.

## Updates

Last reviewed: 9 July 2026.

Autopilot may update this page as providers change. Material changes are handled in accordance with the [Data Processing Agreement](/legal/dpa). If a customer has a signed agreement with different notice terms, those agreement terms apply.

For questions about this list or privacy-related provider matters, please contact:

privacy@aplt.ai

For general questions, please contact your usual Autopilot representative or:

hello@aplt.ai
