Skip to document
Monopaly Back to Monopaly ↗

Monopaly / Legal

Subprocessors

The service providers that support Monopaly and the work they perform.

Last updated September 6, 2026

Terms of ServicePrivacy PolicyCookie PolicySubprocessors

On this page

  1. 1. Infrastructure and core services
  2. 2. Feature-dependent services
  3. 3. Customer-connected services
  4. 4. Processing scope and locations
  5. 5. Changes and contact

These providers support Monopaly, operated by Gravitate Software Incorporated. The data a provider receives depends on the features your organization uses and its configuration.

Hosting: AWS currently hosts production VPS infrastructure. DigitalOcean hosts staging infrastructure and is our planned production VPS host. Both are included below.

1. Infrastructure and core services

ProviderServiceInformation involved
Amazon Web Services (AWS)Current production VPS hosting for telephony infrastructure.Call media, connection metadata and application/runtime data processed on hosted infrastructure.
DigitalOceanStaging VPS hosting; planned production VPS hosting.Test and staging data and any service data processed in that environment. Production hosting would involve call media, connection metadata and associated runtime data.
CloudflareWebsite/application hosting, security, storage, database connectivity, background processing and email delivery.Request metadata; application data and files; messages/media; operational logs; invitation recipient and delivery information.
PlanetScaleManaged application database.Account and workspace data, contacts, messages, call records, outcomes and recording/transcript metadata.
WorkOSAuthentication and account identity.Account/profile information, authentication credentials and tokens, session information and sign-in request metadata.
PostHogApplication analytics, error diagnostics and session replay where enabled.Account/workspace identifiers, name/email, usage events, errors, call statistics, and replay/console information where enabled.
TwilioPhone numbers, carrier connectivity and messaging.Phone numbers, communication metadata, message content and media, and call data needed for the configured carrier service.

2. Feature-dependent services

These providers process information when the corresponding feature or integration is enabled. Listing a provider does not mean every workspace sends data to it.

ProviderFeatureInformation involved
AssemblyAISpeech-to-text transcription.Call audio and associated transcription data.
Google — Gemini APIBusiness-profile analysis, campaign generation and property research.Prompts, business context, website content and property-address information submitted for the feature.
Google — Maps / Street ViewProperty-location and imagery features.Coordinates, location queries and associated requests.
MapboxMaps, address search and geocoding.Addresses/search strings, coordinates, browser request metadata and map-usage events.
FirecrawlBusiness-website discovery and analysis.Submitted website URLs and website content retrieved for analysis.

3. Customer-connected services

Your organization may connect Meta/Facebook, select a carrier or configure outbound webhook destinations. These services receive information under your organization’s instructions and may act under their own terms and privacy policies. They are not automatically subprocessors for every Monopaly customer.

Your workspace administrator controls which integrations are used. A customer-selected destination, such as a webhook connected to another tool, may receive the event payloads your organization authorizes.

4. Processing scope and locations

This list identifies providers by their service names. A provider’s precise role depends on the data and service involved: for example, account administration and our own service analytics can differ from processing customer-controlled lead data.

Processing may occur in the United States and other countries, depending on the provider and service configuration. Contact us for the applicable contracting entity, processing locations and transfer information for your arrangement. Where a DPA applies, it governs subprocessor authorization, changes and any agreed notice or objection process. This page does not replace those contractual requirements.

LiveKit, Restate and other software operated on our own hosting infrastructure are not separately listed as managed service providers merely because their software is used.

5. Changes and contact

We update this list as our service providers and hosting arrangements change. A planned migration does not mean production data has already moved. Required contractual notices will be handled according to the applicable DPA or agreement.

For provider or data-processing questions, contact Gravitate Software Incorporated at thomas@gravitateinc.com.

Monopaly

A product of Gravitate Software Incorporated.

thomas@gravitateinc.com

© 2026 Gravitate Software Incorporated