Grit Board GRIT BOARD
Games How it works About Playbook Open app ↗
See pricing Pricing
LEGAL · SUBPROCESSORS

Subprocessors

LAST UPDATED · August 21, 2026

The complete list of providers that process customer data for Grit Board — and, just as deliberately, the categories we don't use at all.

01 · Overview02 · Current Subprocessors03 · Customer-Enabled Destinations04 · What We Don't Run05 · International Processing06 · Changes07 · Contact

01Overview

This page lists every third-party provider Grit Board LLC uses to provide, secure, support, and improve the Grit Board service. These providers process personal data as subprocessors when Grit Board processes customer-controlled personal data on behalf of a customer.

This list reflects Grit Board's production stack. We keep it current — if a provider is on this page, it is in use today; if it is not on this page, it does not receive customer data.

02Current Subprocessors

Every provider that can receive customer personal data, what it does, what it touches, and where it processes.

  • Vercel (Vercel Inc., US) — hosting and edge infrastructure for gritboard.io and app.gritboard.io; runs every API route and holds runtime logs. Customer data passes through it in transit during imports, syncs, and board rendering. Processes in the United States, with a global edge network for static assets. DPA: vercel.com/legal/dpa.
  • Supabase (Supabase Pte. Ltd.) — database and authentication (magic-link sign-in). Holds the customer data at rest: rep names, work emails, activity metrics, scores, season history, and account records. Hosted on AWS in the United States (us-east-2, Ohio). DPA: supabase.com/legal/dpa.
  • Stripe (Stripe, LLC, US) — billing and checkout. Receives the purchasing manager's billing details and email only — never sales-rep performance data. Card numbers go directly to Stripe's hosted checkout and never touch Grit Board's servers. United States. DPA: stripe.com/legal/dpa.
  • Resend (Plus Five Five, Inc., US) — transactional email: sign-in links, player invites, the weekly standings digest, and upload nudges. Receives recipient email addresses, and the rep names, teams, and point totals inside a digest. United States. DPA: resend.com/legal/dpa.
  • Nango (Nango Inc., US) — CRM connection infrastructure. When a customer connects HubSpot, Salesforce, or Pipedrive, Nango holds the OAuth credentials for that connection and relays Grit Board's read requests to the CRM, so CRM activity records pass through Nango on their way to us. Grit Board's own database never stores the tokens. United States. Data processing terms apply to Nango cloud accounts; details at nango.dev.
  • PostHog (PostHog, Inc., US) — product analytics, in the app only (the marketing site runs no analytics). Receives account and organization identifiers and page paths — never rep names, performance numbers, or file contents. No cookies, no session replay. PostHog US Cloud, United States. DPA: posthog.com/dpa.

03Customer-Enabled Destinations

Slack — optional, and only if you turn it on. If you paste an incoming-webhook URL from your own Slack workspace into Grit Board, we post standings, upload notices, and game events — including player names and point totals — into the channel you chose. That is your Slack workspace under your own agreement with Slack, not a provider we selected; you can disconnect it at any time from the account page.

Connected CRMs (HubSpot, Salesforce, Pipedrive) are your own systems and a data source, not subprocessors — Grit Board reads from them and never writes to them.

04What We Don't Run

Just as informative as the list above: there is no error-monitoring or APM vendor, no helpdesk or chat widget, no object or file storage (uploaded CSVs are parsed in memory and never stored as files), no ad tech or marketing pixels, no AI or LLM vendor, and no third-party scripts or fonts on the marketing site. Grit Board does not sell customer data.

05International Processing

Every provider above processes in the United States. If you or your reps are outside the US, your data is processed in the US; the transfer safeguards we rely on are described in the Privacy Policy and the DPA.

06Changes

We will post any new subprocessor here at least 30 days before it starts processing customer data, and email the account owner of every customer on a paid plan. If you object on reasonable data-protection grounds within those 30 days, tell us at hello@gritboard.io and we will either work around it for your account or let you cancel without penalty for the remainder of your term.

07Contact

Questions about subprocessors can be sent to hello@gritboard.io.

Notices may be sent to Grit Board LLC, 6378 W 9890 N, Highland, UT 84003, United States.

Grit Board GRIT BOARD
Open app About Playbook Docs Glossary Integrations Compare Partners Privacy Terms DPA Subprocessors Cookies Security AUP hello@gritboard.io

© 2026 Grit Board LLC · Q3