Sub-processor List
Version: 2026-10-05.v3. Effective date: 5 October 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
This list names every third party that processes personal data on Hail Pilot's behalf in delivering the Service, where it processes that data, what it receives and why. It forms part of the Data Processing Agreement at /legal/dpa and supports the Privacy Policy at /legal/privacy. Terms in capitals have the meaning given in the Terms of Service at /legal/terms.
1. How to read this list
1.1 A Sub-processor is a third party that Hail Pilot engages to process Merchant Data (including Buyer Data) on Hail Pilot's instructions. Platforms and carriers that exchange data with Hail Pilot on your instruction are not Sub-processors; they are listed separately in Section 6.
1.2 "Data received" uses these classes: (a) Merchant User data: the names, email addresses, phone numbers, sign-in details and IP addresses of the people who use your account; (b) Buyer Data, as defined in the Terms: personal data about your customers, including names, contact details, addresses, order and delivery details, messages, and evidence files; (c) other Merchant Data: your business records, settings, knowledge content, product images and files that are not Buyer Data; (d) Billing data: your billing contact and payment records.
1.3 "Country or region of processing" is the location where the provider processes the data we send it, as far as we have been able to establish. Where a provider operates from more than one location, both are named.
1.4 Every Sub-processor is engaged under data processing terms with the provider that require it to protect personal data to a standard comparable to Singapore's Personal Data Protection Act, to process it only for the purpose stated, and to name the countries in which it processes the data. Hail Pilot remains responsible to you for each Sub-processor's handling of your data.
1.5 Hail Pilot's production systems run in Singapore, on infrastructure that Hail Pilot itself operates. That infrastructure is listed in Section 2 for transparency; the hosting provider supplies servers and does not receive instructions to process personal data.
2. Hosting and infrastructure
| Name | Service | Country or region of processing | Data received | Purpose |
|---|---|---|---|---|
| Unihost | Virtual server on which Hail Pilot runs its own application, database, cache, task workers and AI gateway | Singapore | All data classes, at rest and in processing, on servers Hail Pilot administers | Production hosting. Unihost supplies the machine; Hail Pilot operates the software and holds the encryption keys. |
2.1 Malware scanning of uploaded files is performed by software Hail Pilot runs on this infrastructure; uploaded files are not sent to a third party for scanning (see VirusTotal in Section 4.2 for the hash lookup that precedes it).
2.2 Until 5 October 2026, production ran on servers rented from AlphaVPS in London, United Kingdom. Those servers are kept, under our control, as a fallback until 12 October 2026, when the data on them is securely deleted and AlphaVPS stops being a provider.
3. Edge, security, storage and backup
| Name | Service | Country or region of processing | Data received | Purpose |
|---|---|---|---|---|
| Cloudflare, Inc. | DNS, content delivery, web application firewall and bot protection for hailpilot.com and api.hailpilot.com | Global edge network | IP addresses and request data of every visitor and API caller | Routing, caching and protection of the Service |
| Cloudflare, Inc. (Turnstile) | Bot detection on sign-in and registration forms | Global edge network | Visitor IP address, browser signals and a challenge token | Preventing automated sign-up and sign-in abuse |
| Cloudflare, Inc. (R2) | Object storage | Cloudflare's distributed storage network | Evidence files, product and generated images, and weekly database backups (all data classes) | File storage and short-term backup |
| Cloudflare, Inc. (Workers AI) | Hosted language model for buyer-intent classification in Southeast Asian languages | Global edge network | Buyer message text | Classifying the intent of incoming Buyer messages |
| Backblaze, Inc. (B2) | Cold object storage | United States | Monthly database backups (all data classes), encrypted before upload with keys Hail Pilot holds | Long-term backup |
| Qdrant Solutions GmbH (Qdrant Cloud) | Vector database | United States (us-west-1) | Vector embeddings and associated text snippets of knowledge sources, conversation and memory items, held in a separate collection per Merchant | Retrieval for AI Features |
4. AI model providers, image analysis and observability
4.1 Hail Pilot routes AI requests through a gateway it operates itself. The providers below receive the text or images that a given AI Feature needs, for the duration of the request. Hail Pilot does not use Merchant Data or Buyer Data to train any model used for more than one Merchant. As the AI Transparency Notice 4.3 describes, the AI Features learn from each Merchant's own data for that Merchant's workspace only, which may include fine-tuning a model used only for that workspace. The providers below are used under API terms that exclude training on the data we send, except a provider named here as performing workspace-only fine-tuning, whose terms restrict the resulting model to that Merchant.
| Name | Service | Country or region of processing | Data received | Purpose |
|---|---|---|---|---|
| Anthropic, PBC | Large language models | United States | Buyer message text, order and case context, evidence summaries, Merchant User questions to the copilot | Drafting replies, dispute defence drafting, verifying other models' output, merchant analytics questions |
| OpenAI, L.L.C. | Large language models, content moderation and image generation | United States | Buyer message text on fallback routes; every outbound Buyer draft (moderation screening); image prompts and product images; content for fact-checking | Fallback drafting, moderation of outbound drafts, product image generation, fact-checking |
| OpenRouter, Inc. | Model routing gateway | United States | Buyer message text and other prompts on fallback, embedding and image routes | Fallback access to models when a primary provider is unavailable |
| Alibaba Cloud (Model Studio, Qwen models) | Large language models | Singapore | Buyer message text, order and case context, Merchant knowledge content | Primary model for reply drafting and content generation |
| Together AI | Embeddings | United States | Merchant knowledge content and memory items for embedding | Producing embeddings for retrieval |
| Replicate, Inc. | Image generation models | United States | Image prompts and source product images supplied by the Merchant | Product image generation |
| Jina AI | Reranking of retrieved documents; fetching public web pages for our own content | United States and Germany | Retrieved documents and page text submitted for reranking; public web pages fetched for our own content | Improving retrieval relevance for AI Features |
| Hugging Face, Inc. | Model file distribution | United States | None in the default configuration (model files are downloaded and run on Hail Pilot's own infrastructure). If the hosted transport is enabled, the text being screened for prompt injection. | Prompt-injection screening model |
| Sightengine | Automated image and video analysis | France | Evidence photographs and videos, sent only when a Merchant User asks for an image check on that item; location and other metadata are removed from photographs and from most videos (MP4/MOV) before they are sent | Detecting AI-generated or manipulated evidence images and videos |
| Langfuse GmbH (Langfuse Cloud) | AI observability | United States | Prompts and model outputs for each AI request, which may contain Buyer Data and Merchant Data, with token counts and costs | Tracing, cost tracking and quality review of AI Features |
| Functional Software, Inc. (Sentry) | Error monitoring and session replay | Germany | Error reports, stack traces, Merchant User identifiers and IP addresses; for a sample of signed-in sessions, a replay with text masked and media blocked | Detecting and fixing faults |
4.2 Malware and search
| Name | Service | Country or region of processing | Data received | Purpose |
|---|---|---|---|---|
| Google LLC (VirusTotal) | Known-malware hash lookup | United States | The SHA-256 hash of an uploaded file only; the file itself is never sent | Screening uploads before they are stored |
| Serper / Brave Software | Web search | United States | Search queries generated by Hail Pilot's own content pipeline; no Merchant User data or Buyer Data | Researching public articles Hail Pilot publishes |
| Cronitor | Scheduled-job monitoring | United States (Cronitor, Inc., Berkeley, California; infrastructure providers in the United States) | None. Receives job names and run timestamps only; no personal data | Detecting failed scheduled jobs |
5. Messaging, payments, identity and analytics
| Name | Service | Country or region of processing | Data received | Purpose |
|---|---|---|---|---|
| Resend, Inc. | Transactional email | United States and European Union | Merchant User email addresses and the content of account, billing, case and alert emails | Sending email the Service needs to send |
| Twilio, Inc. | SMS verification | United States | Merchant User phone numbers and one-time verification codes | Verifying phone numbers at registration and for security |
| Telegram | Bot messaging | Not stated by Telegram for users outside the EEA and UK; Telegram Messenger Inc. is established outside the EEA | Merchant User Telegram chat identifiers, chosen by the Merchant User, and the content of notifications | Push notifications the Merchant User opts in to |
| HitPay | Payment processing and subscription billing | Singapore | Billing data; card and bank details are entered on HitPay's pages and are not received by Hail Pilot | Charging Fees, refunds, saved payment methods |
| Google LLC (Sign in with Google) | Identity provider | United States | Merchant User Google account email address and basic profile at sign-in | Optional sign-in |
| Plausible Insights OÜ | Website analytics | European Union | Visitor IP address, page address, referrer and browser type; no cookies | Aggregated page-view statistics. See the Cookie & Tracking Notice at /legal/cookies. |
| Cloudflare, Inc. (Email Routing) | Forwarding of email sent to our @hailpilot.com addresses | Global edge network | The content and sender details of email sent to those addresses, including data-subject requests | Delivering our mailboxes |
5.1 Advertising tags described in the Cookie & Tracking Notice (Meta Pixel, LinkedIn Insight Tag) collect data for the advertising platforms' own purposes and are not Sub-processors. They are disclosed there rather than here.
6. Platforms and carriers (not Sub-processors)
6.1 The parties below exchange data with Hail Pilot because you connected them or instructed Hail Pilot to use them. They act under their own terms with you, not under Hail Pilot's instructions. Hail Pilot sends and receives data with them only to the extent your instruction and their terms allow.
| Name | Role | Country or region | Data exchanged | Basis |
|---|---|---|---|---|
| Shopee (Open Platform) | Source and destination | Singapore and the Platform's regional systems | Orders, Buyer details, returns, disputes, chat messages, advertising and listing data, in both directions | Your connection of your Shopee seller account |
| Lazada (Open Platform) | Source and destination | Singapore and the Platform's regional systems | Orders, Buyer details, returns, disputes, chat messages, advertising and listing data, in both directions | Your connection of your Lazada seller account |
| Shopify | Source and destination | United States and global | Orders, customer records, dispute and chargeback notices, in both directions; Shopify's mandatory privacy requests (customers/data_request, customers/redact, shop/redact) | Your installation of the Hail Pilot app on your store |
| WhatsApp (Meta) | Source and destination | Meta's systems | Buyer messages sent to your connected WhatsApp Business Account (phone number, profile name, content, delivery status), and replies you send or allow us to send; also chat exports you upload yourself | Your connection of your WhatsApp Business Account, or your own upload of a chat export |
| Instagram (Meta) | Source and destination | Meta's systems | Buyer direct messages to your connected Instagram professional account (Instagram-scoped identifier, Instagram username, content), and replies you send or allow us to send | Your connection of your Instagram professional account |
| DHL Express | Carrier | Germany and the countries a shipment passes through | Tracking numbers; delivery and proof-of-delivery records returned (recipient name, signature, address) | Your instruction, using your carrier account |
| FedEx | Carrier | United States and the countries a shipment passes through | Tracking numbers; delivery and proof-of-delivery records returned | Your instruction, using your carrier account |
| UPS | Carrier | United States and the countries a shipment passes through | Tracking numbers; delivery and proof-of-delivery records returned | Your instruction, using your carrier account |
6.2 Hail Pilot gives no warranty that any Platform or carrier authorises a particular use of the data it returns. You are responsible for your agreements with them, as set out in the Terms of Service and the Platform & Card-Network Compliance Addendum at /legal/platforms.
7. Changes to this list
7.1 We will give you at least 30 days' notice by email to the billing contact on your account before we add or replace a Sub-processor that processes Merchant Data, or change the country in which an existing Sub-processor processes your data. The notice will name the Sub-processor, the data it will receive and the purpose.
7.2 You may object within the notice period on reasonable data-protection grounds by writing to business@hailpilot.com and stating the grounds.
7.3 If we cannot resolve your objection before the change takes effect, you may terminate the affected feature or Plan, and we will refund Fees paid in advance for the period after termination on a pro-rata basis. The Refund & Cancellation Policy at /refund-policy describes how refunds are paid.
7.4 Removing a Sub-processor, or a change that only reduces the data a Sub-processor receives, is published here without advance notice.
7.5 Every version of this list is kept on the legal changelog at /legal/changelog, so you can see what applied on any date.
8. Contact
8.1 Questions about this list go to our Data Protection Officer at business@hailpilot.com.