Subprocessors
Last updated August 3, 2026.
This is the complete list of third parties Freehold Cloud sends data to in order to run the service, what each one does, and what they can see. We add a vendor here the same day we start sending it data, not months later. If you self-host Freehold, none of this applies: your data goes nowhere but your own server, and you choose your own infrastructure.
E-signature is built in, not outsourced. Freehold runs its own instance of OpenSign (the open-source e-signature project) on our own infrastructure (DigitalOcean, listed below). That means signing documents is included with every plan: no separate e-signature subscription, no per-envelope fee, no account to create with another company. If you'd rather use your own Documenso account or DocuSign, you can connect one from Settings. At that point you have a direct vendor relationship with them, not us, and this page doesn't cover what they do with your data.
Infrastructure & hosting
| Subprocessor | What it does | What it sees | Location |
|---|---|---|---|
| Vercel Inc. | Runs the application: every page load and API request. | All traffic passing through Freehold, including session cookies. | United States |
| Neon, Inc. | Primary Postgres database. | Every workspace record: transactions, contacts, tasks, and encrypted credentials. | United States |
| Cloudflare, Inc. (R2) | Object storage for uploaded documents. | Every uploaded file, envelope-encrypted before it leaves our servers, so Cloudflare holds ciphertext, not readable documents. | United States / global edge |
| DigitalOcean, LLC | Hosts Freehold's own OpenSign instance for e-signatures (see the note below). | Documents sent for signature and signer names/emails. | United States |
AI & voice
| Subprocessor | What it does | What it sees | Location |
|---|---|---|---|
| Anthropic, PBC | Claude powers contract extraction, the site assistant, and the optional Claude connector (MCP) for asking about your own workspace from Claude Desktop or Claude Code. | Contract/document text submitted for extraction; workspace data returned to a query you make through chat or the connector. Anthropic does not train on this data under the API terms we operate under. | United States |
| Deepgram, Inc. | Speech-to-text behind voice search and the dictation button. | Audio while you're speaking into the mic, and the resulting transcript. | United States |
| ElevenLabs | Text-to-speech for voice search's spoken answers. | The text of the answer being read aloud. | United States / European Union |
| LiveKit, Inc. | Realtime audio transport for voice search sessions. | Your live audio stream for the duration of a voice session. | United States |
Communications
| Subprocessor | What it does | What it sees | Location |
|---|---|---|---|
| Resend | Sends transactional email from your workspace's address and receives replies for thread-back-to-transaction. | Recipient addresses, message content, and inbound replies. | United States |
| Slack Technologies, LLC | Internal alerts to the Freehold team: new signups, support tickets, payment issues. | Operational alerts, which sometimes include a customer's name or email. Never document contents or contract data. | United States |
Payments & location
| Subprocessor | What it does | What it sees | Location |
|---|---|---|---|
| Stripe, Inc. | Processes Freehold Cloud subscription payments. | Billing details and payment method. We never see or store your card number. | United States |
| Mapbox, Inc. | Address autocomplete on every address field. | The text you type while searching for an address. | United States |
Two things not on this list on purpose. First, optional sign-in with Google or Microsoft: if you choose one of those at login, that provider only ever sees what any OAuth sign-in shares (your name and email), and only if you pick it. Second, any integration you connect yourself (Follow Up Boss, Twenty CRM, Zapier, ERPNext, your own Documenso or DocuSign account) is a relationship between you and that vendor. We send data there because you told us to; we don't add a step of our own in between.
We use no third-party advertising or analytics trackers, and we do not sell data to anyone, subprocessor or otherwise. See the full privacy policy for how we handle what you put into Freehold.
Questions, or want notice before we add a new subprocessor: open an issue on GitHub or email hello@freeholdtc.dev.