Privacy
Subprocessors
These providers may process limited information for GridHand. A provider receives only the categories reasonably needed for its listed purpose. Conditional providers do not receive pilot data until their workflow is enabled.
Last updated July 26, 2026
Current provider list
| Provider | Purpose | Data categories |
|---|---|---|
| Vercel | Application hosting, request delivery, and limited performance measurement | Request, device, network, application, and performance data |
| Supabase | Authentication and hosted Postgres database | Owner accounts, tenant profiles, callbacks, message drafts, approvals, and activity records |
| Twilio | Provider webhook validation and controlled SMS delivery when messaging is enabled | Phone numbers, message content, event identifiers, delivery status, and timestamps |
| Make.com | Owner-authorized account identity connection; inactive until an owner connects it | Make account identifier, granted identity scope, connection timestamps, and provider security activity; scenario data is not requested in the first connection slice |
| Cloudflare Turnstile | Bot and sign-in abuse prevention | Browser, device, network, and challenge signals |
| Upstash | Durable abuse-prevention counters for security-sensitive requests | HMAC-pseudonymized rate-limit keys, counters, and expiration times |
Changes
GridHand may update this list when a provider or product workflow changes. We will update the date above and provide additional notice when contract or law requires it. Questions may be sent to privacy@gridhand.ai.