Sub-processors
The services we rely on to run QuoteBolt
QuoteBolt uses the third-party services below to operate. Each is a sub-processor: it processes customer data on our instructions, under a contract that limits what it may do with that data. Each has its own privacy policy and security practices.
This page accompanies our Privacy Policy, which explains what we collect and why.
Current sub-processors
| Service | Purpose | Data processed | Retention |
|---|---|---|---|
| SupabaseUnited States | Database, authentication, file storage | Account details, business records (contacts, properties, quotes, invoices, jobs), Bolt conversation history | For the life of the account. Bolt threads inactive for 12 months are deleted automatically; all Bolt history is purged on account deletion. |
| GoogleUnited States | Sign-in (Google account); optional connected services (Gmail send, Calendar, Contacts) when you connect them; Maps Platform (maps, Places autocomplete, geocoding) for addresses and property location in the product | Basic profile for sign-in; email content you ask us to send; calendar events you ask us to manage; contact fields you allow us to read; address text and location data you enter or select for properties and jobs (including Places suggestions) | Per Google's policies for your Google Account and Maps Platform. We do not keep Google mailbox or calendar contents as long-term training data. Revoke OAuth connections via QuoteBolt settings and/or your Google Account permissions. Map/Places queries follow Google Maps Platform terms. |
| xAIUnited States | AI model inference for Bolt (text) | Your message, the relevant portion of the conversation, and the record data Bolt needs to answer | None. Zero Data Retention is enabled on our account, so xAI does not retain prompts or responses after a request completes. |
| PostHogUnited States | Product analytics, AI observability, error tracking | Usage events, and for Bolt turns the message text, the response, model, latency and cost | Message and response content is removed after 30 days. Aggregate figures (counts, latency, cost) are kept longer and contain no message content. |
| VercelUnited States (global edge network) | Application hosting and edge delivery | Requests to the application, including IP address and request metadata | Per Vercel's log retention for our plan. |
| StripeUnited States | Payment processing and payouts | Payment details, billing information. Card numbers are handled by Stripe and never reach QuoteBolt. | Per Stripe's retention policy, subject to financial regulation. |
| ResendUnited States | Transactional email delivery | Recipient address and the contents of quote, invoice and account emails | Per Resend's retention policy. |
What Bolt sends to our AI provider
When you use Bolt, your message and the record data needed to answer it are sent to xAI. We have Zero Data Retention enabled on our xAI account, which means xAI does not keep your prompts or Bolt's responses once a request completes — they are not stored, and they are not used to train foundation models.
Your conversation history is stored by us, in Supabase, so that Bolt can remember the thread. It is not stored by xAI. Bolt's help articles are searched in our own database, not by a third party.
Changes to this list
We will give at least 30 days' notice before adding a new sub-processor that processes customer data, by email to account owners and by updating this page. If you object to a new sub-processor, contact us and we will work with you on it.
Data processing agreement
If your business needs a Data Processing Agreement covering Article 28 of the UK/EU GDPR, contact us at hello@quotebolt.app and we will arrange one. Our sub-processors are US-based, so transfers of EU or UK personal data would rely on Standard Contractual Clauses.