Legal

Data Processing Addendum

How HailMate processes personal information on a customer's behalf. This Addendum forms part of the Terms of Service and is incorporated into every Order Form.

Last updated: August 1, 2026

1. Roles

Customer is the controller (or “business”) of the personal information it submits to the Service. HailMate is the processor (or “service provider”) and processes that information only on Customer's documented instructions.

Use of the Service constitutes Customer's instruction to process personal information as necessary to provide the Service.

2. What is processed

CategoryWhoseExamples
Contact detailsCustomer's customers (homeowners)Name, property address, phone, email
Property and claim dataCustomer's customersJob records, insurance claim and policy numbers, adjuster details
PhotographsCustomer's customers' propertyJob site photos, including GPS location and capture time
Financial dataCustomer's customersInvoices, payment records, amounts
CommunicationsCustomer's customersText messages, emails and call records made through the Service
User account dataCustomer's employeesName, email, phone, role

HailMate does not require, and Customer should not submit, Social Security numbers, government identification numbers, payment card numbers, or health information. Payment card and bank details are collected directly by Stripe and never pass through or rest in the Service.

3. HailMate's obligations

HailMate will:

  • process personal information only to provide the Service, or as required by law
  • not sell personal information, and not share it for cross-context behavioral advertising
  • not use personal information for its own purposes, including training or marketing, except as anonymized aggregate data that cannot identify any individual
  • ensure personnel with access are bound by confidentiality obligations
  • implement and maintain the technical and organizational measures in §5
  • assist Customer, at Customer's reasonable request, in responding to individual rights requests and regulatory inquiries
  • make available information reasonably necessary to demonstrate compliance

4. Customer's obligations

Customer will:

  • ensure it has a lawful basis, and all necessary notices and consents, for the personal information it submits — including data migrated from prior systems
  • respond to individual rights requests from its own customers, with HailMate's assistance
  • obtain and maintain consent before sending marketing or automated messages, as required by the TCPA and other applicable law — see Terms of Service §11
  • not submit special categories of personal information, or the categories excluded in §2

5. Security measures

HailMate maintains measures appropriate to the risk, including:

  • Encryption in transit (TLS) for all connections to the Service
  • Encryption at rest for the database and file storage
  • Tenant isolation enforced at the database layer, so each workspace's data is segregated by policy rather than by application logic alone
  • Role-based access control within each workspace
  • Credential handling — administrative keys are held server-side only and are never distributed in client applications
  • Access logging and automated error monitoring
  • Automated testing on every change before it reaches production

Further detail is available in the Security Overview, provided on request.

6. Personal data breach

HailMate will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a breach affecting Customer's personal information, and will provide the nature of the breach, the categories and approximate volume of data affected, likely consequences, and remediation steps — supplementing as information becomes available.

7. Sub-processors

Customer authorizes the following sub-processors. HailMate will give 30 days' notice before adding a new one; Customer may object on reasonable data-protection grounds under Terms of Service §9.3.

Sub-processorPurposeData involved
Supabase (on AWS)Database, authentication, file storage, application servicesAll Customer Data
VercelWeb application hostingApplication traffic
Expo / EASMobile application deliveryApplication traffic, crash data
TwilioText messaging and voice callingPhone numbers, message and call content
StripePayment processingPayment details (collected directly by Stripe)
ResendTransactional emailEmail addresses and content
BoldSignElectronic signatureDocuments sent for signature, signer details
OpenRouter / OpenAIAI assistant featuresJob and customer context submitted to the assistant
DeepgramVoice transcription for the AI assistantAudio submitted by Users
Google Maps PlatformMapping, geocoding, address lookupProperty addresses
SentryError monitoringDiagnostic data, which may incidentally include identifiers
PostHogProduct analytics and session replayUsage events keyed to User and workspace identifiers, and screen recordings of the application as Users see it, which may include Customer Data displayed on screen
AxiomServer log retentionDiagnostic logs containing record identifiers, statuses and timings
EagleView / HoverRoof measurement reportsProperty addresses, where Customer orders a report
Intuit (QuickBooks)Accounting syncFinancial records, where Customer connects it

Note on AI features. Where Customer uses the AI assistant, the relevant job and customer context is transmitted to the AI provider in order to generate a response. HailMate does not use Customer Data to train any model, and does not authorize its providers to do so. Customer should nonetheless consider this transmission before entering sensitive information into assistant conversations. The AI features are optional; Customer may simply not use them, and the rest of the Service is unaffected.

8. International transfers

The Service is operated in the United States. Customer's data is stored in US East (N. Virginia) — AWS us-east-1. Where any sub-processor transfers data internationally, it does so under an appropriate transfer mechanism.

9. Deletion and return

On termination, HailMate will retain Customer Data for 60 days and make it available for export, then delete it, except where retention is required by law. Backup copies are deleted on their ordinary rotation cycle. Certified deletion is available on written request.

10. Audit

On reasonable written request, no more than once per year, HailMate will provide information reasonably necessary to demonstrate compliance with this Addendum.

11. Order of precedence

In a conflict between this Addendum and the Terms of Service, this Addendum controls as to the processing of personal information.

Questions about this Addendum: contact@hailmate.ai.