Sub-processor List

    Last updated: June 1, 2026

    GTM Heroes engages third-party sub-processors to deliver the Service. This page lists every sub-processor that processes customer or end-user personal data, the purpose of processing, the data categories involved, and the geographic location of processing. We notify customers of material changes to this list at least 30 days in advance. To receive sub-processor change notifications, email [email protected] with the subject line "Subscribe."

    Application infrastructure

    Lovable / Supabase

    Purpose: Application hosting, database, authentication
    Data: All customer-entered data including prospect records, drafted communications, uploaded transcripts, account credentials, usage telemetry
    Location: United States (AWS us-east-1)
    Data residency: US-only by default. EU residency available on enterprise request.

    AI model providers

    Anthropic (Claude API)

    Purpose: LLM inference for behavioral analysis, communication drafting, prospect research, call prep
    Data: Customer-provided prospect data, email content, transcripts, behavioral profiles
    Location: United States
    Training posture: Anthropic does not train models on API customer data. Standard 30-day retention for abuse monitoring; Zero Data Retention available for qualified customers on request.

    OpenAI

    Purpose: LLM inference for behavioral analysis and communication drafting where Claude is not the model in use
    Data: Same as Anthropic
    Location: United States
    Training posture: OpenAI does not train models on API customer data by default. Standard 30-day retention for abuse monitoring; ZDR available on Enterprise tier.

    CRM and prospect data

    Apollo

    Purpose: Prospect contact data enrichment, visitor identification, behavioral analytics on the GTM Heroes marketing surface
    Data: Business contact information (name, title, company, email, phone), publicly available professional profile data, marketing-site visitor identifiers
    Location: United States
    Retention: Contact data retained for the duration of customer's GTM Heroes subscription plus 90 days. Visitor identification data follows Apollo's standard retention.
    Cookie banner control: Apollo only fires when "Analytics & Tracking" cookies are consented.

    HubSpot

    Purpose: CRM read-only integration for customer-side deduplication
    Data: Customer's CRM records that the customer chooses to surface to GTM Heroes (read-only)
    Location: United States

    Payments

    Stripe

    Purpose: Payment processing for customer subscriptions
    Data: Billing contact information, payment method tokens (we do not store full card numbers)
    Location: United States
    PCI compliance: Stripe is PCI-DSS Level 1 certified. GTM Heroes does not handle or store cardholder data directly.

    Productivity and communication

    Google Workspace

    Purpose: Internal email, calendar, document storage for GTM Heroes team. Where customers connect a Gmail account to GTM Heroes for outreach drafting, Google's APIs are the access mechanism.
    Data: Email content (when customer connects Gmail), calendar metadata (when customer connects Calendar)
    Location: United States and EU per Google's standard architecture

    Slack

    Purpose: Internal team communications. Some customer-facing Slack notifications when customers opt into a connected Slack workspace integration.
    Data: Notification payload content (when customer opts in)
    Location: United States

    Data sourcing clarification

    GTM Heroes uses publicly available professional profile data to enrich prospect records. This enrichment is performed through our own data pipelines using authorized API and aggregated data partners; we do not engage third-party scrapers as sub-processors and we do not direct sub-processors to perform unauthorized data collection on our behalf.

    Contact