Sub-processors
The short version
- Four companies, and only four, are involved in running EzyCrm.
- Your CRM records sit in Canada, in the ca-central-1 region. Email is the one thing that leaves it — the table below says exactly where and why.
- We tell account owners 30 days before we add one, so you have time to object.
Current sub-processors
These are the third parties that may process data on our behalf in the course of delivering the service. Each is bound by a written agreement requiring them to process data only on our instructions, with security no weaker than our own commitments to you.
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| Supabase SUPABASE PTE. LTD., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 |
Database, authentication and API hosting — the primary store for everything in the product | All account data and all customer data, encrypted at rest | Canada (ca-central-1, Montréal) |
| Resend Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA |
Sending transactional email: booking confirmations, reminders, invitations, password resets. Also receives mail sent to a workspace's private logging address, if that feature is switched on. | Recipient name and address, and the content of the message we send. For inbound logging, the content of any message you deliberately copy to your logging address. | United States (us-east-1) |
| Vercel Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA |
Serving the website and the application files | Request metadata only — IP address, timestamp, the file requested. No CRM content passes through it. | United States, served from a global edge network |
| GoDaddy Domain registrar and authoritative DNS for ezycrm.ca |
Domain registration and DNS | No customer data. Resolves the name only. | United States |
Optional, and only if you turn them on
These are not our sub-processors. They are services you may choose to connect, under your own account and your own agreement with them.
The two are not alike, and the blanket sentence that used to sit here was wrong about one of them. AI providers are called straight from your browser on your own key — we do not proxy that traffic and we keep no copy of it. An inbound calendar feed is different: our server fetches it on a schedule and stores the busy blocks it returns, including event titles, so the scheduler can work when your browser is closed. That copy sits in your workspace under the same row-level security as your records and is deleted when you disconnect the feed.
| Provider | When it is involved | What it receives |
|---|---|---|
| An AI model provider of your choosing — a local Ollama, Google AI Studio, Groq, OpenRouter or OpenAI | Only if you configure one in settings. The product works without any of them. | The text of the question you ask and the CRM context needed to answer it, sent from your browser directly to them on your own key |
| Your own calendar provider — Outlook, Google Calendar, Apple Calendar | Only if you subscribe to your EzyCrm feed, or point EzyCrm at one of your calendars | The events in the feed you connected, and nothing else. Fetched by our server, not your browser, and the busy blocks are stored in your workspace until you disconnect it. |
Changes
We will email account owners at least 30 days before a new sub-processor starts handling data. If you object on reasonable grounds, tell us within that window and we will either find another way or let you cancel without penalty for the unused part of your term.
To be told about changes to this page, write to evankorial7@gmail.com.
Written to be read. If any part of this is unclear, say so and we will rewrite it — that is a bug like any other.