Vercel, Inc.
Application hosting and deployment.
Website and app request metadata, hosted app content, diagnostics, and operational logs.
United States / global edge infrastructure
Infrastructure
Deepline uses the subprocessors below to provide, secure, monitor, bill, and support the service. We review vendors before use, keep the list current, and provide required notice for material additions or replacements.
Last updated July 11, 2026. This page is provided for procurement and security review.
Application hosting and deployment.
Website and app request metadata, hosted app content, diagnostics, and operational logs.
United States / global edge infrastructure
Infrastructure
Edge networking, Workers runtime, R2 artifact storage, and runtime harness infrastructure.
Request metadata, runtime traffic, staged files, artifacts, runtime payloads, and operational logs.
Global edge infrastructure
Infrastructure
Application backend, realtime state, workflow metadata, run ledger, and dashboard state.
Account data, workspace and org identifiers, API key metadata, OAuth metadata, encrypted credential or token ciphertext, play and run metadata, bounded run logs, and summaries.
United States
Infrastructure
Managed Postgres data planes for runtime sheets, persisted row state, play outputs, and ingestion storage.
Customer data including row data, step outputs, dataset previews, provider or tool results, and tenant database metadata.
United States / selected cloud regions as configured
Infrastructure
Runtime worker infrastructure for scheduler profiles and receipt gateway services.
Customer data needed for play execution, scheduler metadata, run receipts, runtime logs, and operational metadata.
United States / selected Fly regions as configured
Infrastructure
Sandbox and runtime infrastructure for supported workflow execution profiles.
Customer data made available to a sandboxed play run, bounded execution logs, and runtime authority metadata.
United States / selected runtime regions as configured
Infrastructure
AI model and API services when Deepline AI features are used.
Prompts, instructions, inputs, outputs, and related metadata sent to AI features.
United States / provider infrastructure
AI provider
AI model and API services when Deepline AI features are used.
Prompts, instructions, inputs, outputs, and related metadata sent to AI features.
United States / provider infrastructure
AI provider
Gemini, Google AI, or Google API services where used by Deepline features.
Prompts, outputs, request metadata, or customer-authorized Google data, depending on the feature.
United States / global provider infrastructure
AI provider / integration provider
Billing, checkout, payment processing, invoices, subscription state, and billing webhooks.
Account data, billing contact details, payment method metadata, Stripe customer, subscription, and payment identifiers, invoice records, and transaction records. Deepline does not store raw card numbers.
United States
Business operations
Transactional email, magic links, onboarding, and service notifications.
Account data including recipient email, message metadata, and message content.
United States
Business operations
Logs, observability, and operational diagnostics.
Request metadata, operational logs, error logs, and limited user or workspace identifiers where logged by application code.
United States / configured Axiom region
Business operations
Browser and server-side product analytics.
Account data, anonymous identifiers, page and product event metadata, organization grouping events, and device or browser metadata.
United States / configured data plane
Business operations
CRM, website forms, sales/support workflows, partner intake, and customer communications.
Account data submitted through forms, business contact details, message content, and CRM metadata.
United States
Business operations
Compliance automation and control monitoring.
Account data for procurement/security review, employee and vendor evidence, and limited customer contact metadata during compliance workflows.
United States
Compliance
Independent SOC 2 audit and assurance services.
Account data and security/compliance evidence needed for audit review.
United States
Compliance / audit
Deepline may use general written authorization for subprocessors in customer DPAs. When Deepline adds or replaces a core subprocessor that materially processes customer data, Deepline provides notice through the contract, security portal, email, or this page with a reasonable period for customer objections.
For customer-enabled integrations, connecting or invoking the integration is the customer's instruction and authorization to transmit selected data to that provider, subject to the customer's agreement with that provider.
Questions about this list can be sent to team@deepline.com. See also the Privacy Policy.