Subprocessors
These are the third-party services StrategyHub™ uses to deliver the product. Production customer strategy data is stored only in the first row: AWS us-west-2 (Oregon, United States).
Last updated September 29, 2026
Subprocessors that may process customer data
| Subprocessor | Purpose | Data processed | Processing region |
|---|---|---|---|
| Lovable Cloud (managed Supabase on AWS) | Database, authentication, object storage, serverless functions | All customer strategy content and account data | AWS us-west-2 — Oregon, United States |
| Sinch Email (Mailgun) — contracted directly by StrategyHub | Invitations, reminders, notifications, unsubscribe and suppression handling | Recipient email addresses, message subject and body, and delivery metadata | Mailgun U.S. region — United States (sending domain mail.strategyhub.io) |
| Lovable AI Gateway → Google Gemini | Customer AI: plan Q&A, executive summaries, plan import, meeting copilot and transcripts, benchmarks, Chief of Staff, and similar workspace drafting | Only the strategy text needed for the specific request. Failover stays on Google Gemini. StrategyHub does not use customer data to train models. Lovable’s Business data processing agreement excludes Customer Content from model training by default. No retention period or zero-data-retention claim for gateway payloads | Gateway entrypoint: European Union. Inference: United States (provider endpoints). Not EU-only end to end |
| Paddle | Subscription billing and payment processing (Merchant of Record) | Billing contact and payment details; StrategyHub does not store card data | Provider-managed |
| GoDaddy (VPS hosting) | U.S. application front door at strategyhub.io | Request traffic only; no separate data store | United States |
Lovable publishes the subprocessors on its side of the platform, including the AI Gateway, at trust.lovable.dev/subprocessors. That list is authoritative for Lovable's own vendors. This page lists the services StrategyHub engages.
Services that do not process customer data
| Subprocessor | Purpose | Data processed | Processing region |
|---|---|---|---|
| Answer-engine APIs (e.g. Perplexity) | StrategyHub's own marketing visibility monitoring | No customer data is sent — public marketing questions only | Provider-managed |
| OpenAI | StrategyHub marketing-copy rewrite for answer-engine visibility only | No customer workspace, plan, meeting, or KPI data. StrategyHub's own published marketing answers, buyer questions, and verified public site facts only. Each request is sent with OpenAI storage disabled so it is not kept in platform logs | Provider-managed |
Customer-configured connections
Workspaces may optionally connect their own external data sources — Google Sheets, BigQuery, Snowflake, Jira, Asana, Monday.com — to refresh KPI values or sync tasks. Those connections are configured, authorized and scoped by the customer's own workspace and are not StrategyHub subprocessors.
Change notification
This page is the authoritative subprocessor list and carries a "last updated" date. Customers who ask to be notified of changes receive an email when a subprocessor that may process customer data is added or replaced. To join that list, email privacy@strategyhub.io with the subject "Subprocessor notifications".
Related: Security & U.S. data residency · Incident response · Privacy notice
