Sub-processors
Effective Date: July 27, 2026
This page is the single source of truth for the third-party companies Raileon LLC uses to run the Service. If another Raileon document, contract, or support answer disagrees with this page, this page is correct.
1. What a Sub-processor Is
When you use Raileon, you are the controller of your business data and we process it on your behalf. To deliver the Service we in turn rely on other companies — hosting providers, a database platform, a payment processor, third-party AI providers, and so on. Those companies are our sub-processors: they process your data under our instructions, for a defined purpose, under a written contract.
We publish this list so you can see exactly who touches your data before you decide to trust us with it, and so you can keep your own vendor records accurate without having to ask us.
What is not on this list
- Tools you connect yourself. When you link an external account to your workspace, your agents access it under your credentials and your agreement with that vendor. That vendor is not our sub-processor. The one exception is Google, which appears below because we also use it for AI model processing.
- Our own internal tools. Software we use to run the company that never receives customer data is out of scope.
How we vet them
We choose sub-processors that offer a data processing agreement, encrypt data in transit and at rest, and support US-based processing. We review that documentation before onboarding a vendor and again when their terms change. To be plain about the limits: Raileon holds no SOC 2 report, no ISO 27001 certification, and no third-party penetration test report, and we do not sign HIPAA business associate agreements. Some vendors below hold certifications of their own; ours are theirs, not ours, and we do not claim them.
2. Current Sub-processors
All processing takes place in the United States. Our contracts with AI providers are configured so that your data is not used to train their models.
| Sub-processor | Purpose | Data categories processed | Processing location |
|---|---|---|---|
| Anthropic | AI language-model processing for agent tasks | Prompt and task content sent by your agents, which may include any business content, documents, or messages you route through them. Training on your data is disabled at the API level. | United States |
| AI model processing, plus access to the Google Workspace tools you choose to connect | Prompt and task content sent by your agents. If you connect Workspace, also the mail, calendar, and file data your agents are scoped to read or write. Training on your data is disabled at the API level. | United States | |
| Convex | Application database and backend platform | Account and organization records, workspace and agent configuration, chat and conversation history, uploaded attachments, activity logs, and token-usage counters. | United States |
| Clerk | Authentication and user-account management | Name, email address, and authentication metadata — sessions, sign-in timestamps, IP address, and device or browser identifiers. No business content. | United States |
| Stripe | Subscription billing, setup fees, and payment processing | Billing contact details and payment metadata: plan, amounts, invoices, tax details, card brand, and last four digits. Full card numbers are entered directly into Stripe and are held by Stripe — they never reach Raileon systems. No business content. | United States |
| Vercel | Hosting and delivery of the Raileon web application | HTTP request data handled in transit: IP address, user agent, requested URL, and referrer. Also cookieless, aggregate page analytics that set no identifiers. | United States |
| Hostinger | Server hosting for your dedicated instance | Everything stored on your dedicated container: agent configuration, workflow inputs and outputs, integration credentials, and logs. Stored on an encrypted volume and backed up daily. | United States |
| Cloudflare | Network security, DNS, TLS termination, and bot protection | HTTP request data handled in transit: IP address, user agent, requested URL, TLS and connection metadata, and security event logs. Content is passed through, not stored as a record. | United States |
| Resend | Transactional and notification email delivery | Recipient name and email address, plus the subject and body of the messages we or your agents send — which can include business content you put in an email. | United States |
| Sentry | Application error monitoring and diagnostics | Error diagnostics: stack traces, browser and operating system, route, and request metadata. These may incidentally include a user identifier or a fragment of the input present when the error occurred. | United States |
Each sub-processor is bound by a written agreement limiting it to the purpose above. Access inside Raileon is separately restricted — see the security section of our Privacy Policy for how per-customer isolation, encryption, and backups work.
3. Advance Notice and Your Right to Object
Before we add a new sub-processor, or materially change what an existing one does with your data, we will publish the change on this page and give at least 30 days’ notice before the new sub-processor starts processing customer data. The only exception is an emergency replacement needed to keep the Service running or secure, in which case we will notify you as soon as we can and no later than the switchover.
Subscribe to change notices
Email privacy@raileon.comwith the subject line “Sub-processor notices” and the address you want us to use. We will email that address every time this list changes. There is no charge, the list is used for nothing else, and you can unsubscribe by replying.
Objecting to a new sub-processor
If you have a reasonable, good-faith objection to a new sub-processor on data-protection grounds, tell us at privacy@raileon.com within 30 days of the notice. We will then:
- Work with you in good faith to find a workaround — for example, keeping your workspace on the existing provider or scoping the new one out of your data.
- If no reasonable workaround exists, let you terminate the affected part of your subscription without penalty, with a pro-rated refund of any prepaid subscription fees for the period after termination. Setup fees remain non-refundable.
- Give you the standard 30-day export window before deletion, as described in our Privacy Policy.
These rights are available to every customer, wherever you are. We do not gate them by country.
4. Change Log
Every addition, removal, or material change to the list above is recorded here, newest first.
- July 27, 2026— Initial published list.
5. Related Documents and Contact
- Data Processing Agreement— the contractual terms that govern how we process your data, including sub-processor obligations.
- Privacy Policy— what we collect, how we use it, how long we keep it, and your rights.
Questions about this list, a specific vendor, or a due-diligence questionnaire:
Raileon LLC
Miami, Florida
privacy@raileon.com— data-protection matters
security@raileon.com— security questions and disclosures
admin@raileon.com— general and billing