Current providers
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | United States / configured cloud region |
| Vercel | Application hosting, delivery, and aggregate web analytics | United States / global infrastructure |
| OpenAI | AI-assisted features invoked by authorized users | United States |
| Stripe | Subscriptions, payments, invoicing, and fraud prevention | United States / global infrastructure |
| Google Workspace | Company email and support communications | United States / global infrastructure |
| Paubox | Transactional email delivery | United States |
PHI conditions
A provider receives PHI only when needed for an enabled feature and when SessionSteps has determined the provider's agreement and configuration are appropriate for that use. Customers should not send PHI through payment fields, general support email, or an integration not approved for PHI.
Changes
We may add or replace providers as the service evolves. We will update this page and provide additional notice where a customer agreement or law requires it. Questions or objections may be sent to privacy@sessionsteps.com.