Subprocessors
R.ai uses a small set of vetted third-party service providers (“subprocessors”) to operate the Service. Each one processes data only on R.ai's documented instructions and under a written contract that includes appropriate confidentiality and security obligations. This page is the current, authoritative list.
Subprocessor list
| Vendor | What it does | Data processed | Region | Privacy / DPA |
|---|---|---|---|---|
| Vapi (Vapi Labs, Inc.) | Voice AI orchestration — real-time speech-to-text, LLM, text-to-speech | Call audio (excluding payment portion), transcripts, prompt and response data, caller phone number | United States | Privacy · DPA |
| Twilio Inc. | Inbound and outbound telephony and SMS — carrier of record for the R.ai-provisioned number that forwarded calls arrive on, sender of order-confirmation messages | Caller phone number, call metadata (start, end, duration), SMS recipient numbers, SMS body | United States | Privacy · DPA |
| Stripe, Inc. | Payment processor for customer card payments and for restaurant subscription billing. We never store card numbers, CVV, or expiration dates — Stripe tokenizes | Caller-provided card payment tokens, restaurant billing card tokens, transaction metadata | United States | Privacy · DPA |
| Resend (Resend, Inc.) | Transactional email — account confirmations, password resets, billing notices, system alerts | Customer email address, email content | United States | Privacy · DPA |
| Pusher (Pusher Ltd., a MessageBird company) | Realtime message delivery — pushes dashboard updates to signed-in restaurant staff, and delivers marketing-site live-chat messages to the R.ai inbox | Live-chat visitor message text and session identifier, order and inbox update payloads, restaurant identifiers | United States and European Union | Privacy · DPA |
| Clerk (Clerk, Inc.) | Authentication and user-session management for the Dashboard | Email address, hashed password, session metadata, sign-in events | United States | Privacy · DPA |
| Neon (Neon, Inc.) | Managed Postgres database hosting — primary data store for all account, menu, call, and order records | All Customer Data, Order Data, and Caller records, stored encrypted at rest | United States | Privacy · DPA |
| Vercel Inc. | Application hosting, edge networking, and Vercel Blob storage for call audio recordings | Server logs (IP, user agent), call audio recordings (retained while the account is active, deleted on verified request), uploaded assets | United States | Privacy · DPA |
| OpenAI, L.L.C. | Large-language-model inference for the telephone Agent, speech transcription (Whisper), and text embeddings for semantic search | Call transcripts, call audio, system prompts, and caller order history | United States | Privacy · DPA |
| Anthropic (Anthropic, PBC) | Large-language-model inference for the Ask R.ai dashboard assistant, call summaries, inbound-message handling, and de-identification | Prompt and response data — call transcripts, system prompts, and assistant queries. Anthropic does not use this data to train its models. | United States | Privacy · DPA |
| Meta Platforms, Inc. | WhatsApp Business Platform — delivery of WhatsApp ordering, reservation, and order-status messages (reached via Twilio). Applies only to restaurants that enable the WhatsApp add-on or the WhatsApp-only plan | Recipient WhatsApp phone number, message body, delivery metadata | United States | Privacy · DPA |
| ItsaCheckmate (Checkmate Labs, Inc.) | Point-of-sale order aggregation — routes an order ticket into the restaurant’s POS where R.ai has no native adapter. Used only for restaurants configured on this path | Order contents, caller name, caller phone number, delivery address where applicable | United States | Privacy |
| Sentry (Functional Software, Inc.) | Application error monitoring — stack traces and limited request metadata for the marketing site and dashboard | Stack traces, error context, redacted request metadata | United States | Privacy · DPA |
| PostHog (PostHog, Inc.) | Product analytics — page views, button clicks, and funnel events for joinrai.com and the dashboard | Page-view events, click events, anonymized session metadata; account identifier for authenticated users | United States | Privacy · DPA |
Point-of-sale providers you designate
Where a restaurant connects a point-of-sale system directly — currently Toast, Square, or Clover — R.ai transmits the order, the caller's name, the caller's phone number, and any delivery address to that provider using credentials the restaurant supplies, under the restaurant's own agreement with that provider. Those providers are not R.ai subprocessors, because R.ai does not select or contract with them; they are listed here so the data flow is not a surprise. Where R.ai routes an order through its own aggregator relationship instead, that vendor (ItsaCheckmate) is listed in the table above.
Sub-tier vendors
Some subprocessors above use their own vendors to deliver part of their service. In particular, Vapi uses third-party speech-to-text and text-to-speech providers (currently including Deepgram and Cartesia) to process call audio. R.ai does not contract with those vendors directly; they are governed by Vapi's own subprocessor terms, and are named here for transparency.
How we vet subprocessors
Before R.ai engages a new subprocessor, R.ai reviews the vendor's security program, available compliance attestations (SOC 2, ISO 27001, PCI-DSS where applicable), data-processing terms, sub-tier vendor practices, and data-residency commitments. R.ai will not engage a subprocessor that cannot meet R.ai's contractual privacy and security commitments to Customers.
Customer DPA
Customers who require a standalone Data Processing Agreement may request one by emailing ezra@joinrai.com. R.ai's standard DPA incorporates this Subprocessors list by reference and is updated automatically as this page is updated.
© 2026 REVAAI LLC. For data-handling details, see the Privacy Policy and the Terms of Service.