Subprocessors
Effective: May 12, 2026
To operate CoTrackPro, CoTrackPro, LLC. relies on a small set of vetted third-party services (“subprocessors”) for infrastructure, AI, communication, and analytics. This page lists each one — what it does, what data it touches, where it operates, and what compliance certifications it maintains.
This list is updated independently of our Privacy Policy and Terms of Serviceso changes are easy to track. Material additions or removals are announced to active subscribers by email and reflected in the “Effective” date above.
If you require a Data Processing Addendum or specific transfer documentation, email admin@cotrackpro.com.
Infrastructure
Amazon Web Services (AWS)
Privacy policy ↗- Purpose
- Primary data storage (DynamoDB), file storage (S3), transactional email (SES), AI embeddings (Bedrock), secrets (SSM Parameter Store), and event delivery (SNS).
- Data accessed
- Account records, Your Content, PHI tables, AI embedding requests, transactional email metadata.
- Location
- United States — region us-east-1 (Northern Virginia).
- Certifications
- SOC 1/2/3, ISO 27001/27017/27018, PCI-DSS, HIPAA-eligible.
Vercel
Privacy policy ↗- Purpose
- Application hosting, serverless function execution, edge middleware, Speed Insights (anonymous page-performance telemetry).
- Data accessed
- Server request logs (IP, path, status), function invocation logs (anonymized error context, structured stage logs), Speed Insights metrics.
- Location
- United States and global edge POPs.
- Certifications
- SOC 2 Type II, ISO 27001.
Clerk
Privacy policy ↗- Purpose
- User authentication, session management, magic-link sign-in, user metadata storage.
- Data accessed
- Email address, display name, authentication credentials, session cookies.
- Location
- United States.
- Certifications
- SOC 2 Type II.
Stripe
Privacy policy ↗- Purpose
- Payment processing, subscription management, Payment Links checkout, webhook events for billing state changes.
- Data accessed
- Payment method (handled entirely on Stripe — we never receive card numbers), customer + subscription IDs, billing email, country, amount, plan key.
- Location
- United States and EU; transfer mechanisms governed by Stripe DPA.
- Certifications
- PCI-DSS Level 1, SOC 1/2.
AI Providers
All AI providers below operate under commercial API terms that prohibit retention and training on data submitted through their APIs. AI output is probabilistic and reviewed by you before any external use — see Terms §8 and Privacy §6.
Anthropic (Claude)
Privacy policy ↗- Purpose
- AI-generated summaries, role recommendations, title cleanup, and the MCP integration. Models in use: claude-haiku-4-5 (default), claude-sonnet-4 (MCP/agent flows).
- Data accessed
- The text prompts we send for the feature in use; the model's generated response. No retention or model training per Anthropic's commercial API terms.
- Location
- United States.
- Certifications
- SOC 2 Type II.
Amazon Bedrock — Titan Text Embeddings V2
Privacy policy ↗- Purpose
- Semantic search over the content library. Model: amazon.titan-embed-text-v2:0.
- Data accessed
- Text snippets converted into vector embeddings for similarity search; embeddings (not the source text) are stored in DynamoDB.
- Location
- United States — region us-east-1.
- Certifications
- SOC 1/2/3, ISO 27001, HIPAA-eligible. No data retention beyond the request lifecycle.
OpenAI
Privacy policy ↗- Purpose
- Optional alternative AI provider, enabled per-environment via AI_DEFAULT_PROVIDER. Not in active use on the production environment as of the Effective date below.
- Data accessed
- Text prompts when active; generated responses. Zero retention configuration when used.
- Location
- United States.
- Certifications
- SOC 2 Type II.
Communication
Transactional email (receipts, access changes, security alerts) is sent via AWS SES under our Infrastructure subprocessor above. The vendor below is used only for non-transactional email when you have not opted out.
Mailchimp
Privacy policy ↗- Purpose
- Optional marketing-email sync. We push email + name + subscription tier to a Mailchimp audience only if you have not opted out of marketing email. Used for product updates and newsletters.
- Data accessed
- Email address, first/last name (if provided), tier/plan tags, subscribed/unsubscribed status.
- Location
- United States.
- Certifications
- SOC 2.
Twilio
Privacy policy ↗- Purpose
- Delivers SMS (one-time sign-in codes, reminders you have opted into) and telephone voice sessions. Named as our SMS provider in the Privacy Policy's mobile-messaging section.
- Data accessed
- Mobile phone number, message body, delivery status, and — for voice sessions — call audio in transit.
- Location
- United States.
- Certifications
- SOC 2, ISO 27001.
ElevenLabs
Privacy policy ↗- Purpose
- Speech synthesis for the voice center and for narrated library audio.
- Data accessed
- Text passed for synthesis. No account identifiers.
- Location
- United States.
- Certifications
- SOC 2.
Cloudflare (Turnstile)
Privacy policy ↗- Purpose
- Bot / abuse challenge on the sign-in and sign-up forms. Rendered by Clerk as part of the authentication flow.
- Data accessed
- Challenge telemetry from your browser, including IP address and user-agent.
- Location
- Global Cloudflare edge network.
- Certifications
- SOC 2, ISO 27001.
Analytics
We use server-side, aggregated analytics. No advertising cookies, no cross-site trackers.
Google Analytics 4
Privacy policy ↗- Purpose
- Aggregate funnel analytics (page views, trial starts, conversions). Loaded client-side in your browser — we do not run GA4's advertising features.
- Data accessed
- Event payloads and plan tier. We do not send an account identifier, so events are not linked to a CoTrackPro account. Google receives the request IP as it does for any browser-loaded script.
- Location
- United States and global Google infrastructure.
- Certifications
- Per Google's Cloud and Workspace certifications.
Vercel Speed Insights
Privacy policy ↗- Purpose
- Anonymized page-performance metrics (Core Web Vitals).
- Data accessed
- Performance metrics; no personal identifiers.
- Location
- Vercel-managed.
- Certifications
- Inherits Vercel SOC 2.
How We Vet Subprocessors
- Each vendor must publish current SOC 2, ISO 27001, or equivalent compliance documentation, or operate under an established Data Processing Addendum.
- AI providers must contractually disclaim retention and training on commercial-API data.
- Vendors must support TLS 1.2+ for all data in transit.
- We minimize data sent to each vendor to what they need for their specific function (least-privilege data sharing).
- Adding a new subprocessor that materially changes how your data is processed is announced before activation; this page is updated at activation.
Changes & History
This page is versioned via our public source repository — every change is captured in git history. To request a copy of the change log or to be notified when this page changes, email admin@cotrackpro.com.
Maintained by CoTrackPro, LLC. Cross-references: Privacy Policy · Terms of Service.