For everyone
Subprocessors
- Version
- 2.0
- Effective
- August 15, 2026
- Last updated
- July 26, 2026
ShowRunner LLC uses the third-party providers listed below to deliver the Service. This page is incorporated into the Data Processing Addendum as Annex III.
Every subprocessor on this list processes personal data in the United States. ShowRunner does not transfer Contact Data outside the United States.
1.1. What a subprocessor is
ShowRunner processes Contact Data for its customers as a processor and service provider. A subprocessor is a company it engages to help do that work — hosting the application, storing the database, delivering a text message — under ShowRunner's instructions, not for its own purposes.
Before a subprocessor receives Contact Data, ShowRunner enters a written contract imposing data-protection obligations no less protective than those in the Data Processing Addendum. ShowRunner remains responsible for each subprocessor's performance, to the same extent as if it did the work itself, subject to the limitations of liability in the Terms of Service.
No provider on this list may sell Contact Data, share it for cross-context behavioral advertising, or use it to train generalized or publicly available artificial-intelligence models.
2.2. Current subprocessors
| Subprocessor | What it does | Personal data it receives | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and serverless execution | All data in transit through the application | United States |
| Supabase, Inc. | Primary database, authentication, and file storage — the system of record | All Contact Data, account records, message logs, consent records, and stored files | United States |
| Twilio Inc. | SMS and MMS delivery and inbound message handling | Recipient phone numbers and message content | United States |
| Resend | Marketing and transactional email delivery and engagement webhooks | Recipient name, email address, and message content | United States |
| Google LLC | Gmail send and Calendar read, for customers who connect a Google account | Recipient email addresses and message content; calendar availability | United States |
| OpenAI, L.L.C. | The in-product help assistant, and business-card extraction where a customer enables it | For the help assistant, an allowlisted context containing no contact records. For card extraction, the card image and a roster of first names and last-four phone digits | United States |
| ZeroBounce (Hertza, LLC) | Email deliverability verification | Email address only | United States |
| U.S. Census Bureau geocoder | Converts a street address to map coordinates | Street address only, with no name or contact details | United States |
| Expo (650 Industries, Inc.), Apple Push Notification service, and Google Firebase Cloud Messaging | Push notifications to the customer's mobile app | Notification payloads that may include a contact name and inbound message text | United States |
| Cloudflare, Inc. | Bot protection on public forms (Turnstile) | Visitor IP address only | United States |
| Upstash, Inc. | Rate limiting | Rate-limit keys only; no personal data | United States |
| Stripe, Inc. | Subscription billing | The customer's own billing contact and payment details; no Contact Data | United States |
3.3. Internal operational tools
ShowRunner uses Slack for internal team communication and GitHub for source code and change management. Neither is designed to receive Contact Data, and no feature of the Service routes Contact Data to either one.
They are named for transparency rather than as subprocessors. If a support conversation ever led an operator to paste a contact detail into one, ShowRunner's handling rules treat that as an exception to be avoided, not a designed flow.
4.4. How changes are announced, and the right to object
ShowRunner posts any new or replacement subprocessor here, with an updated effective date, before that provider processes Contact Data. Customers who subscribe to change notices, by writing to privacy@showrunnercrm.com, also receive an email.
- A customer may object to a new subprocessor on reasonable data-protection grounds by writing to privacy@showrunnercrm.com within 30 days after the change is posted.
- On a timely objection, ShowRunner will work in good faith to offer a reasonable alternative — a configuration change, a feature exclusion, or another provider.
- If it cannot within a reasonable period, the customer may terminate the affected portion of the Service without penalty and receive a pro-rata refund of fees prepaid for that portion of the then-current subscription term.
- If a subprocessor must be replaced urgently — it ceases operating, fails on security, or must change to keep the Service running — ShowRunner may engage the replacement immediately and will post and notify as soon as practicable, with the 30-day window running from that notice.
The full terms, including flow-down obligations and ShowRunner's responsibility for subprocessor performance, are in Section 7 of the Data Processing Addendum.
5.5. Contact
Questions about this list, requests to subscribe to change notices, and objections to a new subprocessor go to privacy@showrunnercrm.com. Procurement questions go to legal@showrunnercrm.com.
Related documents: the Data Processing Addendum, the Privacy Policy, the Guest Privacy Notice, and the Consumer Health Data Privacy Policy.
Related policies
- Terms of Service
The agreement between ShowRunner LLC and the businesses that subscribe to ShowRunner. Covers accounts and seats, ownership of Customer Data, messaging and consent obligations, the prohibition on protected health information, fees, warranties, liability limits, indemnities, and binding individual arbitration under Minnesota law.
- Privacy Policy
How ShowRunner LLC handles personal information for the businesses that use our CRM, the guests who register for their seminars, and visitors to our website — what we collect, who receives it, how long we keep it, and how to exercise your rights.
- Acceptable Use Policy
What Customers may and may not send, collect, claim and do with ShowRunner: prohibited content, list-sourcing rules, data restrictions, health-claim limits, geofencing limits, and how ShowRunner investigates and enforces.
- Messaging Terms
The consent, record-keeping, opt-out, A2P 10DLC registration, carrier, email and do-not-call obligations that apply to every Customer who sends SMS, MMS or email through ShowRunner.
- Data Processing Addendum
The terms governing how ShowRunner processes contact and guest data on a customer's behalf: instructions, security, subprocessors, breach notice, deletion, and assessment rights.
- Consumer Health Data Policy
The standalone notice required by Washington's My Health My Data Act: the categories of consumer health data ShowRunner processes, where it comes from, who receives it, and how to exercise your rights to confirm, access, withdraw consent, delete, and appeal.
- Guest Privacy Notice
A plain-language explanation for people who registered for a seminar dinner: what the form asked for, how it is used, how to stop text messages and email, who can see your information, and how to have it deleted.