Subprocessors
Last updated July 31, 2026
Third parties that process data on our behalf. Core subprocessors apply to every workspace. Optional ones only receive data if a workspace explicitly connects them.
Draft — not yet in effect
This document is a prepared baseline awaiting legal review and the registered entity details. It does not yet form a binding agreement. Self-serve signup remains closed until it does.
Core subprocessors
Used by every workspace. Operating the product is not possible without these.
- Supabase
- Primary database, authentication, and file storage
- Data handled: Account details, workspace records, CRM data, uploaded media
- Vercel
- Application hosting, edge routing, and product analytics
- Data handled: Request metadata, IP addresses in transit, aggregate page analytics
- Anthropic
- The Claude models behind Arc's reasoning and drafting
- Data handled: Prompt content: the records and instructions Arc reasons over
- Google Cloud (including Gemini)
- Agent runner execution, object storage, and generative models
- Data handled: Prompt content, generated assets, run logs
- Stripe
- Subscription billing and payment processing
- Data handled: Billing contact and payment details — handled by Stripe, never stored by us
- Resend
- Transactional email and approved campaign delivery
- Data handled: Recipient addresses and message content for approved sends
- Sentry
- Error monitoring and diagnostics
- Data handled: Error traces and limited request context
Optional subprocessors
Only involved when a workspace enables the corresponding connector. If you never turn one on, it never receives your data.
- Higgsfield
- Generative media, when a workspace enables the connector
- Data handled: Generation prompts and resulting assets
- HubSpot
- CRM import, when a workspace connects it
- Data handled: Contact and company records the workspace chooses to import
- Mailchimp
- Audience import, when a workspace connects it
- Data handled: List and contact records the workspace chooses to import
- Slack
- Operational alerts to a workspace's own channel
- Data handled: Alert content only
- Meta (Ad Library)
- Competitor ad intelligence, when enabled
- Data handled: Public ad-library queries — no customer data sent
- Google Business Profile
- Review monitoring, when a workspace connects it
- Data handled: Public review content for the workspace's own listings
- NOAA / National Weather Service
- Severe-weather signals for a workspace's service area
- Data handled: Geographic queries only — no customer data sent
Changes
This list is maintained alongside the code rather than as a separate document, so a new dependency or connector is added here before it ships. We will give notice of material additions to core subprocessors.
