Core sub-processors
These vendors are part of the Service. We pre-vet each on encryption, access controls, breach-notification timelines, and data residency. New additions are announced 30 days in advance (see “Change notification” below).
| Vendor | Purpose | Region | Data classes |
|---|---|---|---|
| Render | Application hosting (web tier, Celery workers, Postgres, Redis). | United States (Oregon) | All customer data at rest & in transit. |
| OpenAI | AI scoring, parsing, deep analysis, interview-kit generation, email drafting. | United States | Resume text, job descriptions, recruiter prompts. Data-sharing for training is opted-out at the organisation level. |
| Sentry | Error monitoring (server + client). | United States (Frankfurt option for EU customers) | Stack traces, request paths, request IDs. PII is scrubbed via a before_send hook before transmission. |
| Razorpay | Subscription payments for INR billing. | India | Billing email, plan, invoice metadata. No card data ever touches CreamyHire. |
| Stripe | Subscription payments for USD/EUR/GBP billing. | United States, Ireland | Billing email, plan, invoice metadata. No card data ever touches CreamyHire. |
| Postmark | Transactional email (sign-up verification, scoring summaries, notifications). | United States | Recipient email, message body (recruiter-authored or AI-drafted). |
| Cloudflare | CDN + DDoS protection + bot mitigation. | Global edge. | Request metadata (IP, user-agent, path) — no request bodies are cached. |
| GitHub | Public-source enrichment for candidate verification (read-only public API). | United States | Candidate's GitHub username (extracted from resume, by recruiter intent). |
Customer-controlled processors
These vendors only receive your data if you opt in by connecting an integration. They are not part of the default Service.
| Vendor | Purpose | Notes |
|---|---|---|
| Greenhouse / Lever / Workable | ATS bidirectional sync (Phase 8). | Data leaves CreamyHire only when you connect an integration in Settings → Integrations. Credentials are encrypted and used solely to call your own ATS account. |
| Slack / Microsoft Teams | Notification webhooks. | Triggered only when you paste a webhook URL in Settings → Notifications. CreamyHire posts the configured event types and nothing else. |
Change notification
Material changes to this list (a new core sub-processor, a vendor change of region) are announced at least 30 days before the change takes effect, via email to your account's primary contact and an in-app banner. To object during the notice window, email privacy@creamyhire.com; we'll discuss alternative arrangements or wind-down terms.
Last updated: May 2026.