Skip to content
Pricing

Trust

Subprocessors and service providers

List effective: August 24, 2026

This page lists the service providers and subprocessors behind the Haultro website and the Haultro product, and the data each receives. Providers marked activation-gated process customer data only after the operating customer activates the capability, supplies or approves credentials, and accepts the configuration; until then they receive nothing. This list is maintained by Trunnion AI, LLC and updated when the provider set changes.

Website and infrastructure (active)

  • Render: Static site hosting, lead API hosting, and the managed PostgreSQL database. Data received: Form submissions, privacy-request records, service logs. Hosting region: United States.
  • Cloudflare: Edge network, caching, and DNS in front of this website. Data received: Request metadata, including IP address, for delivery and security. Hosting region: Global edge, US-controlled account.
  • Google Workspace: Business email delivery of form notifications and correspondence. Data received: Submitted form contents and related correspondence. Hosting region: United States.
  • Trunnion lead registry: Affiliated private reporting and tenant-scoped review of submitted contact requests. Data received: A reporting copy of submitted contact-form fields, independent of optional analytics consent. Hosting region: United States.

Website analytics and advertising (consent-gated)

These load only after the corresponding consent choice, and the current configured status is stated on the Cookie Policy.

  • Google Analytics 4: Optional site analytics. Data received: Usage events, only after analytics consent.
  • Trunnion analytics: Optional first-party website analytics. Data received: Site events excluding name, email, phone, company, and message text, only after analytics consent.
  • Meta Pixel: Optional advertising measurement. Data received: Page views and form conversions, only after advertising consent.

Product payments (configured)

  • Stripe: PCI DSS-scoped payment processing for self-serve signup and billing. Data received: Payment and billing information.

Product providers (activation-gated)

Configured providers that receive customer data, voice audio, or location traces must be configured with training and secondary-use exclusions consistent with their commercial terms. See the sensitive data section of the Security page.

  • Twilio: Telephony and call control for the voice agent. Data received when activated: Call audio, phone numbers, call metadata.
  • ElevenLabs (including Scribe): Voice synthesis and realtime or batch transcription. Data received when activated: Call audio and transcripts.
  • LLM providers (per customer configuration): Intent interpretation and tool calls; no LLM provider is currently configured in production. Data received when activated: Workflow text under required data-from-training exclusions.
  • Telematics providers (Samsara, Geotab, Verizon Connect, Motive): Vehicle GPS, engine, and ELD data through configured adapters. Data received when activated: Vehicle location, driver assignment, engine and hours-of-service data.
  • Intuit QuickBooks: Accounting synchronization. Data received when activated: Invoice and billing records.

Change notification

We update this page when the provider set changes. For contracted deployments, we give at least 30 days notice before a new subprocessor begins handling customer personal information, through the notice mechanism in the Data Processing Addendum, so a customer can review and object before the change takes effect.

Related: Security, Privacy Notice, Acceptable Use Policy.

Necessary technology is always active because it provides security and remembers this choice.