Subprocessors
Effective: September 17, 2026 | Last reviewed: September 17, 2026
The vendors below support infrastructure, communications, payments, analytics, and reliability for GenLP.ai. This list is intended to stay aligned with our Privacy Policy and DPA.
Current vendor list
Provider
Role
Data
Purpose
Location
Transfers / Notes
Google Cloud (Firestore, Cloud Run, Cloud Storage)
Infrastructure and storage
Account data, generated content, public assets, logs
Host and secure the service
United States and regional locations as configured
Contractual safeguards and regional hosting controls as applicable
Hosts public-by-default assets for customer pages.
Cloudflare
DNS, CDN, and custom-domain delivery
IP addresses, request metadata, TLS and routing data
Deliver published pages and protect availability
Global network
Contractual safeguards and regional controls as applicable
Used for custom hostname and edge delivery flows.
Google Analytics
Optional analytics
Cookie and usage data when analytics is enabled
Measure site usage and performance
United States and other Google-operated regions
Google contractual safeguards as applicable
Analytics events are blocked until consent is granted on this surface.
Stripe
Payment processor
Payment details, billing metadata, transaction status
Process subscriptions, refunds, and fraud checks
United States, EU, and other Stripe-operated regions
Stripe contractual safeguards as applicable
Card details are provided directly to Stripe at checkout.
Resend
Transactional email delivery
Email address and message-delivery metadata
Send service notices and operational messages
United States
Contractual safeguards as applicable
Transactional email tracking pixels are not enabled by default.
Sentry
Error monitoring
Error reports and limited runtime metadata
Monitor reliability and investigate incidents
United States and EU regions
Contractual safeguards as applicable
Captures technical diagnostics, not payment content.
Google Cloud Vertex AI (Gemini)
Generative AI for site content and editing
Business profile inputs, page content, editor chat messages and uploaded reference material submitted for generation
Generate and edit site content, translations and image briefs on request
United States and regional locations as configured
Google Cloud contractual safeguards and regional controls as applicable
Prompts are processed under Google Cloud's data processing terms; they are not used to train Google models.
TypeSafe AI
Request classification for the editor assistant
Editor assistant chat messages with emails, phone numbers, URLs and quoted wording masked, plus page control labels and section names
Classify what an editing request asks for so the right editing step runs
United States
EU Standard Contractual Clauses and UK Addendum under TypeSafe's Data Processing Addendum
Receives no page text, media or account identifiers; inputs are not used to train TypeSafe models.
Runware
AI image generation
Image briefs derived from site content and the resulting generated images
Generate hero, portrait and gallery images on request
United States and other Runware-operated regions
Contractual safeguards as applicable
Receives the generation brief only, not account or contact details.
Bright Data
Public web and social profile retrieval
Public profile and website URLs supplied for site generation and the public content retrieved from them
Collect public business information used as site-generation input
United States, Israel and other Bright Data-operated regions
Contractual safeguards as applicable
Only public pages named by the customer are retrieved.
Parallel Web Systems
Web research for site generation
Business name, website URL and research queries derived from the site-generation brief
Research public information about the business being described
United States
Contractual safeguards as applicable
Used during site generation; receives no account or payment data.
Jina AI
Web page reading for site generation
Public website URLs supplied for site generation and the page text retrieved from them
Read public pages named by the customer as site-generation input
Germany and United States
Contractual safeguards as applicable
Receives URLs only, not account or contact details.
Provider:Google Cloud (Firestore, Cloud Run, Cloud Storage)
Role:Infrastructure and storage
Data:Account data, generated content, public assets, logs
Purpose:Host and secure the service
Location:United States and regional locations as configured
Transfers / Notes:
Contractual safeguards and regional hosting controls as applicable
Hosts public-by-default assets for customer pages.
Provider:Cloudflare
Role:DNS, CDN, and custom-domain delivery
Data:IP addresses, request metadata, TLS and routing data
Purpose:Deliver published pages and protect availability
Location:Global network
Transfers / Notes:
Contractual safeguards and regional controls as applicable
Used for custom hostname and edge delivery flows.
Provider:Google Analytics
Role:Optional analytics
Data:Cookie and usage data when analytics is enabled
Purpose:Measure site usage and performance
Location:United States and other Google-operated regions
Transfers / Notes:
Google contractual safeguards as applicable
Analytics events are blocked until consent is granted on this surface.
Provider:Stripe
Role:Payment processor
Data:Payment details, billing metadata, transaction status
Purpose:Process subscriptions, refunds, and fraud checks
Location:United States, EU, and other Stripe-operated regions
Transfers / Notes:
Stripe contractual safeguards as applicable
Card details are provided directly to Stripe at checkout.
Provider:Resend
Role:Transactional email delivery
Data:Email address and message-delivery metadata
Purpose:Send service notices and operational messages
Location:United States
Transfers / Notes:
Contractual safeguards as applicable
Transactional email tracking pixels are not enabled by default.
Provider:Sentry
Role:Error monitoring
Data:Error reports and limited runtime metadata
Purpose:Monitor reliability and investigate incidents
Location:United States and EU regions
Transfers / Notes:
Contractual safeguards as applicable
Captures technical diagnostics, not payment content.
Provider:Google Cloud Vertex AI (Gemini)
Role:Generative AI for site content and editing
Data:Business profile inputs, page content, editor chat messages and uploaded reference material submitted for generation
Purpose:Generate and edit site content, translations and image briefs on request
Location:United States and regional locations as configured
Transfers / Notes:
Google Cloud contractual safeguards and regional controls as applicable
Prompts are processed under Google Cloud's data processing terms; they are not used to train Google models.
Provider:TypeSafe AI
Role:Request classification for the editor assistant
Data:Editor assistant chat messages with emails, phone numbers, URLs and quoted wording masked, plus page control labels and section names
Purpose:Classify what an editing request asks for so the right editing step runs
Location:United States
Transfers / Notes:
EU Standard Contractual Clauses and UK Addendum under TypeSafe's Data Processing Addendum
Receives no page text, media or account identifiers; inputs are not used to train TypeSafe models.
Provider:Runware
Role:AI image generation
Data:Image briefs derived from site content and the resulting generated images
Purpose:Generate hero, portrait and gallery images on request
Location:United States and other Runware-operated regions
Transfers / Notes:
Contractual safeguards as applicable
Receives the generation brief only, not account or contact details.
Provider:Bright Data
Role:Public web and social profile retrieval
Data:Public profile and website URLs supplied for site generation and the public content retrieved from them
Purpose:Collect public business information used as site-generation input
Location:United States, Israel and other Bright Data-operated regions
Transfers / Notes:
Contractual safeguards as applicable
Only public pages named by the customer are retrieved.
Provider:Parallel Web Systems
Role:Web research for site generation
Data:Business name, website URL and research queries derived from the site-generation brief
Purpose:Research public information about the business being described
Location:United States
Transfers / Notes:
Contractual safeguards as applicable
Used during site generation; receives no account or payment data.
Provider:Jina AI
Role:Web page reading for site generation
Data:Public website URLs supplied for site generation and the page text retrieved from them
Purpose:Read public pages named by the customer as site-generation input
Location:Germany and United States
Transfers / Notes:
Contractual safeguards as applicable
Receives URLs only, not account or contact details.
Payment processing note
Merchant of record
GenLP AI LLC is the merchant of record. Stripe processes payment information directly at checkout, while GenLP receives limited billing metadata needed for subscription management, refunds, and fraud review.
Change notices
We publish updates at /subprocessors/changes. Notification and objection handling are currently reviewed manually by the privacy team via privacy@genlp.ai.