Privacy

Subprocessor List

Third parties SessionSteps uses to provide, secure, support, and bill for the service.

Last updated October 5, 2026

Current providers

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storageUnited States / configured cloud region
VercelApplication hosting, delivery, and aggregate web analyticsUnited States / global infrastructure
OpenAIAI-assisted features invoked by authorized usersUnited States
StripeSubscriptions, payments, invoicing, and fraud preventionUnited States / global infrastructure
Google WorkspaceCompany email and support communicationsUnited States / global infrastructure
PauboxTransactional email deliveryUnited States

PHI conditions

A provider receives PHI only when needed for an enabled feature and when SessionSteps has determined the provider's agreement and configuration are appropriate for that use. Customers should not send PHI through payment fields, general support email, or an integration not approved for PHI.

Changes

We may add or replace providers as the service evolves. We will update this page and provide additional notice where a customer agreement or law requires it. Questions or objections may be sent to privacy@sessionsteps.com.