Skip to main content

Sub-processors

Last updated: August 20, 2026

KeyBolt relies on the third-party services below to deliver the platform. Each that processes personal data on our behalf is contractually bound by data processing terms equivalent to or stronger than those in our Privacy Policy. A few are public data sources or infrastructure that receive no customer or personal data — noted as such in their description.

We will provide at least 30 days' notice at this URL before adding a new sub-processor. To receive notifications by email, write to [email protected].

ServiceRoleCountry
SupabasePrimary database, authentication, file storage. Stores all customer records, jobs, invoices, key codes, photos, and identity-verification uploads.United States (Northern Virginia, AWS us-east-1)
StripePayment processing for subscription billing and shop-to-customer invoices. Stripe Connect routes payouts to the locksmith’s bank account; Stripe Terminal handles in-person card readers.United States
Intuit (QuickBooks Online)Optional accounting integration. When a locksmith connects their own QuickBooks Online company, KeyBolt sends the records needed to keep those books current: customer names and contact details, billing and service addresses, invoices and their line items, estimates, payments and refunds, credit memos, vendors, bills, and inventory items and quantities. KeyBolt stores the shop’s encrypted QuickBooks tokens and company identifier. Stripe remains the payment processor and sends customer receipts; KeyBolt does not charge cards through QuickBooks. Payroll access is read-only and is not enabled.United States
SquareOptional support-assisted payment processor. When a locksmith uses their own Square account, KeyBolt can process that shop’s customer invoice payments through Square instead of Stripe. KeyBolt stores the shop’s encrypted Square access tokens and merchant/location identifiers to send payable invoices and reconcile payments; card details are entered on Square-hosted pages and are never stored by KeyBolt.United States
TelnyxTelecommunications carrier for KeyBolt Pro — voice calls, SMS, MMS, A2P 10DLC registration, call recording, and Whisper-based transcription. Acts as the underlying carrier for the shop’s business phone number. Where a shop enables the AI phone receptionist, caller audio on those calls is processed within Telnyx’s AI assistant platform using speech-recognition and language models Telnyx makes available (currently Deepgram for speech to text and the Kimi language model), as configured by KeyBolt.United States
ResendTransactional email delivery — invoices, payment receipts, team invites, password resets.United States
Cloudflare TurnstileCAPTCHA on signup, contact form, password reset, and customer-portal flows. No tracking cookies.United States (with global edge)
SentryError tracking and (with consent in EU/UK) session replay for debugging. Replay records anonymized DOM interaction; PII is scrubbed at the SDK before transmission.United States
VercelApplication hosting, edge runtime, and analytics. Receives request metadata (IP, user-agent, geo) for serving the application.United States
Google (Local Services Ads)Optional integration on KeyBolt Pro. When connected, KeyBolt pulls LSA leads via the Google Ads API v24 and posts replies on the locksmith’s behalf. Google’s sub-processor when handling LSA conversation content.United States
Google (Merchant Center / Merchant API)Optional integration on any KeyBolt plan. When a locksmith connects a Google Merchant Center account, KeyBolt syncs the shop’s online-storefront product listings (titles, descriptions, prices, availability, and product images) to Google so they can appear in Google’s free product listings. Only product-catalog data is sent; no customer or order information is shared through this integration.United States
OpenStreetMap Foundation (Nominatim)Address autocomplete and geocoding. Address text typed into address fields is sent to the public Nominatim service to return suggestions, and the shop address, saved service-location addresses, and Minnesota sales-tax lookup addresses are geocoded to lat/lng. Results are cached to avoid repeat lookups (a cached result older than 30 days is refreshed on next use); the geocode cache is keyed on a one-way hash of the address — the address itself is never stored in that cache.United Kingdom
OpenFreeMapMap tile rendering for the in-app jobs map. The user’s browser fetches vector tiles directly from the tile CDN, which receives the user’s IP and the map area being viewed. OpenFreeMap is donation-funded and does not log requests or run analytics.European Union
Project OSRMMulti-stop route optimization for the field-tech route planner. Only the stop coordinates (lat/lng pairs) are sent — no customer names, addresses, or contact information.Germany
AI model providers via the Vercel AI Gateway (currently Google Gemini, OpenAI)Powers the optional in-app AI helper, the drafting of jobs from inbound emails, the junk classification that keeps ads and verification codes out of the shop inbox, and (on KeyBolt Pro) call-transcript summaries and field suggestions. Conversation text, inbound email content (sender, subject, and body; plus, for job-draft generation only, selected PDF attachments such as work orders that Google reads using optical character recognition when scanned), and call transcripts are routed through the Vercel AI Gateway, currently to Google (Gemini models, for the chat helper, job-draft generation, email classification, and call summaries) and to OpenAI (text-embedding models, for search indexing). The structured key-code, bitting, and safe-combination fields on customer records are never sent. The providers are directed, via the Vercel AI Gateway, not to use content for model training; brief provider-side retention for abuse monitoring under standard API terms, then deleted.United States (provider routing may vary)
Cloudflare (Email Routing + Workers)Receives inbound emails sent or forwarded to your KeyBolt inbox address ([email protected]). A Cloudflare Worker reads the message and any attachments and files them into KeyBolt for routing to the Colab inbox. Distinct from Cloudflare Turnstile (CAPTCHA), which is listed separately.United States (with global edge)
Google (Business Profile API)Optional integration. When a locksmith connects their Google Business Profile, KeyBolt reads the shop’s own review data to display it inside the app. Connected via OAuth; disconnectable at any time from Settings.United States
PowerSync (JourneyApps)Offline sync service for the KeyBolt mobile app. Changes between the encrypted offline copy on a team member’s device and the KeyBolt database synchronize through PowerSync, which processes the organization’s business data in transit for that purpose.United States
Apple (Push Notification service)Delivers mobile push notifications to team devices. Receives the device push token, deliberately generic notification text, notification type, and pseudonymous record identifiers used to open the relevant screen. Notification text never includes an end customer’s name or phone number.United States
Google (Firebase Cloud Messaging and Play Integrity)Delivers deliberately generic push notifications to Android team devices and verifies Android app, license, and device integrity before a device can register for push. Google receives the device push token, notification text, notification type, and pseudonymous record identifiers used to open the relevant screen. Integrity checks receive the app package name, signing certificate information, device integrity and license signals, plus a one-way request hash; KeyBolt does not send the request contents to Google.United States
Expo (EAS Update)Application-code updates for the KeyBolt mobile app. Receives the device’s update request (app version and platform) — no business data.United States
UpstashRate limiting. Short-lived request counters keyed by identifiers such as IP address, account identifier, or sender email address. No message content is stored.United States
Esri (ArcGIS Online)Public reference-data source for the Minnesota sales-tax rate lookup — not a recipient of your data. To fill in the correct rate for a Minnesota job, KeyBolt geocodes the job or customer address (through OpenStreetMap Nominatim, above) and matches the resulting location against Minnesota Department of Revenue tax-area boundaries within our own systems. KeyBolt retrieves those public boundary files in bulk from Esri’s ArcGIS Online; it sends Esri no customer, business, or personal data, and none is sent to any tax authority.United States

Data Processing Addendum

A standard Data Processing Addendum (DPA) incorporating the EU Standard Contractual Clauses and UK Addendum is available on request. Email [email protected] to receive a countersignable copy.