Legal Pages

Subprocessor List

Likely vendors and service providers used for hosting, payments, SMS, email, analytics, advertising, AI, and monitoring.

Version 2026.06.07 | Effective June 7, 2026 | Last updated June 7, 2026

Current and likely subprocessors

  • Amazon Web Services (Hosting and infrastructure): Application hosting, storage, database, backups, logging, and infrastructure security. Data: Account data, restaurant data, customer records, request records, logs, and service metadata. Enabled when: Production infrastructure is deployed on AWS.
  • Stripe (Payments): Checkout, subscriptions, invoices, taxes, payment authorization, fraud checks, and payment records. Data: Billing contact details, payment metadata, transaction details, tax information, and Stripe customer identifiers. HostKit does not store full card numbers. Enabled when: Paid checkout, subscriptions, refunds, disputes, or invoices are enabled.
  • Twilio (Messaging): SMS/MMS delivery, STOP/HELP handling, delivery receipts, quiet-hour enforcement, and phone-number compliance. Data: Phone numbers, message content, consent state, delivery status, opt-out events, and campaign metadata. Enabled when: SMS, missed-call, review request, reservation, campaign, or support texting is enabled.
  • SendGrid (Email): Transactional email, verification tokens, support notifications, marketing email, unsubscribe handling, and compliance notices. Data: Email addresses, message content, template data, delivery metadata, unsubscribe events, and suppression records. Enabled when: Transactional, support, verification, or marketing email is enabled.
  • Google Analytics and Google Ads (Analytics): Traffic measurement, attribution, conversion reporting, retargeting, and advertising campaign performance. Data: Online identifiers, device/browser data, usage events, page views, campaign source, and conversion metadata. Enabled when: Analytics or advertising tags are configured and the user has not opted out.
  • Meta Ads (Advertising): Advertising attribution, retargeting, lookalike measurement, and campaign optimization. Data: Online identifiers, hashed contact data where configured, conversion events, campaign metadata, and device/browser data. Enabled when: Meta advertising pixels, conversions API, or audience sync is configured and the user has not opted out.
  • OpenAI or AWS Bedrock (AI and automation): AI drafts, summaries, recommendations, analytics explanations, review response drafts, and internal product improvement using aggregated or de-identified data. Data: Prompt inputs, restaurant content, operational context, review/message snippets when enabled, and de-identified aggregate analytics. Sensitive details are excluded from ads and model training. Enabled when: AI features are enabled for a restaurant or internal workflow.
  • Sentry or AWS monitoring services (Security and monitoring): Error monitoring, uptime checks, abuse detection, security logs, and incident response. Data: Application logs, device/browser metadata, IP-derived security signals, user/account identifiers, and error context. Enabled when: Production monitoring, logging, or security alerting is configured.

Changes

  • HostKit may add, replace, or remove subprocessors as the service evolves.
  • Material subprocessor changes should be reflected on this page and, where required, notified to affected customers.
  • Customers with a signed DPA may have additional notice or objection rights.
Questions: support@hostkitapp.comMailing address: HostKit Legal, North Carolina, United StatesRequest pricing