These are the third-party services SHINE AI uses to deliver the platform. Every subprocessor has been reviewed against our vendor management policy and operates under a signed Data Processing Agreement. Vendor names link to each provider's own trust center where you can review their compliance posture.
We provide at least 30 days' notice of any material change to this list. To subscribe to updates, email shine@outsellconsulting.com.
| Vendor | Purpose | Data processed | Location | DPA |
|---|---|---|---|---|
| Google Cloud Platform | Primary API and application infrastructure, including the in-house authentication service and its identity database | All customer content and metadata, user authentication credentials, session data | US | Signed |
| Cloudflare | DNS, WAF, DDoS protection, edge compute (Workers), object storage (R2), D1 SQLite, AI Gateway for LLM request routing and observability | Request metadata (IP, headers), edge-processed request payloads, stored objects, LLM prompts and responses routed through AI Gateway | Global edge | Signed |
| DigitalOcean | Meeting bot infrastructure and supporting microservices | Meeting audio and metadata processed by bots | US | Signed |
| PlanetScale | Primary relational database (Postgres) | Customer account data, meeting metadata, and application state | US | Signed |
| Upstash | Serverless message queue for background job orchestration | Job payloads referencing customer content | US | Signed |
| Turbopuffer | Serverless vector and full-text search database for semantic retrieval over meeting content and account context | Vector embeddings, text chunks, and metadata derived from customer meetings and enrichment data | US | Signed |
| Voyage AI | Embedding model inference for semantic search and retrieval pipelines | Text snippets from meeting transcripts and enrichment data sent for embedding (no training use) | US | Signed |
| AssemblyAI | Speech-to-text transcription of meeting audio | Meeting audio recordings | US | Signed |
| OpenAI | LLM inference for meeting analysis and summarization; text-to-speech synthesis | Meeting transcripts, prompts, and text sent for speech synthesis (no training use) | US | Signed |
| Google Gemini | LLM inference for meeting analysis and summarization | Meeting transcripts and prompts (no training use) | US | Signed |
| ElevenLabs | Text-to-speech synthesis for voice features | Text sent for speech synthesis and generated audio output (no training use) | US | Signed |
| Reducto | Document parsing and structured data extraction from PDFs, spreadsheets, and slides shared in meeting workflows | Customer-uploaded documents and the parsed, structured output derived from them (no training use) | US | Signed |
| Exa AI | Web search for meeting intelligence enrichment (account and prospect context) | Search queries derived from meeting context | US | Signed |
| Twilio | SMS for 2FA authentication and call recording | Phone numbers, message content, and audio from recorded calls | US | Signed |
| Telnyx | Call recording | Audio from recorded calls | US | Signed |
| SignalWire | Call recording | Audio from recorded calls | US | Signed |
| HubSpot | CRM integration for syncing contacts, companies, deals, and meeting activity when enabled by the customer | Customer CRM records (contacts, companies, deals) and meeting metadata synced via the HubSpot API | US | Signed |
| Epicor P21 | ERP integration for industrial distribution customers — reads order, inventory, pricing, and account data from the customer's P21 instance to power sales intelligence and text-to-SQL retrieval | Customer ERP records (orders, invoices, inventory, pricing, account hierarchy) accessed from the customer's P21 instance under their authorization | US (customer-hosted or Epicor-hosted) | Signed |
| Rubber Tree Systems | ERP integration layer and reporting middleware (rubbertree.app, WebQuery) that surfaces Epicor P21 data for industrial distributor customers | Customer ERP records (orders, invoices, inventory, pricing, account hierarchy) accessed via Rubber Tree's integration layer on top of the customer's P21 instance | US | Signed |
| Better Stack | Application logging and observability | Application logs (may contain metadata references) | US | Signed |
| GitHub | Source code hosting and CI/CD | Source code (no customer data) | US | Signed |
| Google Workspace | Internal email, calendar, and document collaboration | Business contact information (no customer meeting content) | US | Signed |