Trust
Subprocessors and service providers
List effective: August 24, 2026
This page lists the service providers and subprocessors behind the Haultro website and the Haultro product, and the data each receives. Providers marked activation-gated process customer data only after the operating customer activates the capability, supplies or approves credentials, and accepts the configuration; until then they receive nothing. This list is maintained by Trunnion AI, LLC and updated when the provider set changes.
Website and infrastructure (active)
- Render: Static site hosting, lead API hosting, and the managed PostgreSQL database. Data received: Form submissions, privacy-request records, service logs. Hosting region: United States.
- Cloudflare: Edge network, caching, and DNS in front of this website. Data received: Request metadata, including IP address, for delivery and security. Hosting region: Global edge, US-controlled account.
- Google Workspace: Business email delivery of form notifications and correspondence. Data received: Submitted form contents and related correspondence. Hosting region: United States.
- Trunnion lead registry: Affiliated private reporting and tenant-scoped review of submitted contact requests. Data received: A reporting copy of submitted contact-form fields, independent of optional analytics consent. Hosting region: United States.
Website analytics and advertising (consent-gated)
These load only after the corresponding consent choice, and the current configured status is stated on the Cookie Policy.
- Google Analytics 4: Optional site analytics. Data received: Usage events, only after analytics consent.
- Trunnion analytics: Optional first-party website analytics. Data received: Site events excluding name, email, phone, company, and message text, only after analytics consent.
- Meta Pixel: Optional advertising measurement. Data received: Page views and form conversions, only after advertising consent.
Product payments (configured)
- Stripe: PCI DSS-scoped payment processing for self-serve signup and billing. Data received: Payment and billing information.
Product providers (activation-gated)
Configured providers that receive customer data, voice audio, or location traces must be configured with training and secondary-use exclusions consistent with their commercial terms. See the sensitive data section of the Security page.
- Twilio: Telephony and call control for the voice agent. Data received when activated: Call audio, phone numbers, call metadata.
- ElevenLabs (including Scribe): Voice synthesis and realtime or batch transcription. Data received when activated: Call audio and transcripts.
- LLM providers (per customer configuration): Intent interpretation and tool calls; no LLM provider is currently configured in production. Data received when activated: Workflow text under required data-from-training exclusions.
- Telematics providers (Samsara, Geotab, Verizon Connect, Motive): Vehicle GPS, engine, and ELD data through configured adapters. Data received when activated: Vehicle location, driver assignment, engine and hours-of-service data.
- Intuit QuickBooks: Accounting synchronization. Data received when activated: Invoice and billing records.
Change notification
We update this page when the provider set changes. For contracted deployments, we give at least 30 days notice before a new subprocessor begins handling customer personal information, through the notice mechanism in the Data Processing Addendum, so a customer can review and object before the change takes effect.
Related: Security, Privacy Notice, Acceptable Use Policy.