Data Processing Addendum
How HailMate processes personal information on a customer's behalf. This Addendum forms part of the Terms of Service and is incorporated into every Order Form.
Last updated: August 1, 2026
1. Roles
Customer is the controller (or “business”) of the personal information it submits to the Service. HailMate is the processor (or “service provider”) and processes that information only on Customer's documented instructions.
Use of the Service constitutes Customer's instruction to process personal information as necessary to provide the Service.
2. What is processed
| Category | Whose | Examples |
|---|---|---|
| Contact details | Customer's customers (homeowners) | Name, property address, phone, email |
| Property and claim data | Customer's customers | Job records, insurance claim and policy numbers, adjuster details |
| Photographs | Customer's customers' property | Job site photos, including GPS location and capture time |
| Financial data | Customer's customers | Invoices, payment records, amounts |
| Communications | Customer's customers | Text messages, emails and call records made through the Service |
| User account data | Customer's employees | Name, email, phone, role |
HailMate does not require, and Customer should not submit, Social Security numbers, government identification numbers, payment card numbers, or health information. Payment card and bank details are collected directly by Stripe and never pass through or rest in the Service.
3. HailMate's obligations
HailMate will:
- process personal information only to provide the Service, or as required by law
- not sell personal information, and not share it for cross-context behavioral advertising
- not use personal information for its own purposes, including training or marketing, except as anonymized aggregate data that cannot identify any individual
- ensure personnel with access are bound by confidentiality obligations
- implement and maintain the technical and organizational measures in §5
- assist Customer, at Customer's reasonable request, in responding to individual rights requests and regulatory inquiries
- make available information reasonably necessary to demonstrate compliance
4. Customer's obligations
Customer will:
- ensure it has a lawful basis, and all necessary notices and consents, for the personal information it submits — including data migrated from prior systems
- respond to individual rights requests from its own customers, with HailMate's assistance
- obtain and maintain consent before sending marketing or automated messages, as required by the TCPA and other applicable law — see Terms of Service §11
- not submit special categories of personal information, or the categories excluded in §2
5. Security measures
HailMate maintains measures appropriate to the risk, including:
- Encryption in transit (TLS) for all connections to the Service
- Encryption at rest for the database and file storage
- Tenant isolation enforced at the database layer, so each workspace's data is segregated by policy rather than by application logic alone
- Role-based access control within each workspace
- Credential handling — administrative keys are held server-side only and are never distributed in client applications
- Access logging and automated error monitoring
- Automated testing on every change before it reaches production
Further detail is available in the Security Overview, provided on request.
6. Personal data breach
HailMate will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a breach affecting Customer's personal information, and will provide the nature of the breach, the categories and approximate volume of data affected, likely consequences, and remediation steps — supplementing as information becomes available.
7. Sub-processors
Customer authorizes the following sub-processors. HailMate will give 30 days' notice before adding a new one; Customer may object on reasonable data-protection grounds under Terms of Service §9.3.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage, application services | All Customer Data |
| Vercel | Web application hosting | Application traffic |
| Expo / EAS | Mobile application delivery | Application traffic, crash data |
| Twilio | Text messaging and voice calling | Phone numbers, message and call content |
| Stripe | Payment processing | Payment details (collected directly by Stripe) |
| Resend | Transactional email | Email addresses and content |
| BoldSign | Electronic signature | Documents sent for signature, signer details |
| OpenRouter / OpenAI | AI assistant features | Job and customer context submitted to the assistant |
| Deepgram | Voice transcription for the AI assistant | Audio submitted by Users |
| Google Maps Platform | Mapping, geocoding, address lookup | Property addresses |
| Sentry | Error monitoring | Diagnostic data, which may incidentally include identifiers |
| PostHog | Product analytics and session replay | Usage events keyed to User and workspace identifiers, and screen recordings of the application as Users see it, which may include Customer Data displayed on screen |
| Axiom | Server log retention | Diagnostic logs containing record identifiers, statuses and timings |
| EagleView / Hover | Roof measurement reports | Property addresses, where Customer orders a report |
| Intuit (QuickBooks) | Accounting sync | Financial records, where Customer connects it |
Note on AI features. Where Customer uses the AI assistant, the relevant job and customer context is transmitted to the AI provider in order to generate a response. HailMate does not use Customer Data to train any model, and does not authorize its providers to do so. Customer should nonetheless consider this transmission before entering sensitive information into assistant conversations. The AI features are optional; Customer may simply not use them, and the rest of the Service is unaffected.
8. International transfers
The Service is operated in the United States. Customer's data is stored in US East (N. Virginia) — AWS us-east-1. Where any sub-processor transfers data internationally, it does so under an appropriate transfer mechanism.
9. Deletion and return
On termination, HailMate will retain Customer Data for 60 days and make it available for export, then delete it, except where retention is required by law. Backup copies are deleted on their ordinary rotation cycle. Certified deletion is available on written request.
10. Audit
On reasonable written request, no more than once per year, HailMate will provide information reasonably necessary to demonstrate compliance with this Addendum.
11. Order of precedence
In a conflict between this Addendum and the Terms of Service, this Addendum controls as to the processing of personal information.
Questions about this Addendum: contact@hailmate.ai.