Subprocessors & Integrations Register
1. How to read this register
This register identifies providers supported by CoveCRM's implementation and distinguishes their roles. Actual processing depends on the contracted service, enabled features, customer directions and provider terms. A technology or optional integration appearing here does not mean every customer's data is sent to it.
Not every vendor is a subprocessor: some act as independent providers or customer-directed recipients for particular activities. Before executing a DPA or relying on a location- specific requirement, request the actual contracting entity, processing locations and applicable arrangements for your service. This page does not assert unverified certifications or fixed residency.
2. Service-delivery providers
- Twilio — communications delivery, telephone numbers, call routing and recording, SMS/MMS, and telecommunications/A2P registration. Relevant data may include contact details, content/media, audio, metadata, consent/registration information and business contact details. Carrier/network activities can have distinct legal roles.
- OpenAI — enabled AI voice/text, transcription, summaries, coaching, analysis and support features. Relevant data may include audio, prompts, lead/conversation context, transcripts, notes, outputs and support context.
- Resend — platform/customer email where that sending path is used. Relevant data includes recipient/sender details, content and delivery/engagement metadata.
- Expo — mobile push delivery where enabled, including device push identifiers and notification payloads.
Cove uses MongoDB database technology and cloud/application, voice and realtime hosting infrastructure. The technology name alone does not identify every contracted hosting operator. The applicable hosting entities, locations and processing arrangements must be confirmed for a contractual subprocessor schedule; this register does not substitute guessed provider names.
3. Customer-directed integrations and independent services
- Stripe / Stripe Connect — subscriptions, payment methods, invoices, usage billing and affiliate payments; account/contact, transaction and payment information. Stripe may act independently for regulated payment and fraud-prevention functions.
- Google — identity and Calendar connections, and customer-directed Google Sheets/Apps Script workflows. Relevant data includes authorized identity, calendar/events, account tokens and rows customers choose to import.
- Customer-selected SMTP providers — customer email content, recipient/sender details and delivery information under the customer's sending configuration.
- LinkedIn / Instagram — optional customer-directed social/recruiting activity where available and enabled. Platform accounts, professional profiles and interactions are governed by relevant permissions and platform terms.
4. Advertising and analytics providers
- Meta / Facebook — Lead Ads, pages/ad accounts/forms, advertising management, configured Pixel and enabled Conversions API measurement. Data may include leads, campaign identifiers, hashed contact identifiers, IP/browser/cookie identifiers and conversion outcomes.
- Microsoft Clarity — website behavioral analytics and session replay; device/browser details, identifiers, page interactions and session information. Microsoft's analytics/advertising purposes and terms can affect its role.
These providers are not categorically represented as service providers acting solely on Cove's instructions. See the Privacy Policy and Cookie Policy for data-flow descriptions and current control limitations.
5. Optional or inactive implementations
- Browserbase — optional hosted browser contexts for customer-directed recruiting/social workflows. If enabled, it may process browser session/account context and profile/interactions data. Its inclusion is not a claim that live execution is enabled for every customer or deployment.
- Telnyx — isolated alternate-provider implementation. It is not identified as an active production subprocessor on the basis of that implementation and is not represented as receiving current production data.
6. Changes and requests
Check this page's version and last-updated date for the current published register. Providers and enabled integrations may change. A signed DPA may establish additional notice, information or objection procedures; this page does not claim that an automated change-notification subscription is available.
For the providers used for your account, contracting entities, locations, or a proposed DPA schedule, contact legal@covecrm.com. See the Data Processing Addendum for written-incorporation requirements.