← Knack

Subprocessors

Last updated 13 September 2026

These are the third-party service providers Knack relies on to run the service, what each processes, and where each is located.

Active subprocessors

Knack uses the third-party providers below to operate the service. Each processes personal information only to provide its service to us, under our instructions and the provider's terms. We put data-processing agreements in place with these providers as we bring them on. This list may change; we will update it here.

ProviderPurposeData processedLocation
SupabasePrimary application databaseAll account data — contractor and customer names, contacts, addresses, quotes, transcripts, acceptance recordsAustralia (Sydney)
Fly.ioApplication hostingAll data in transit through the app; acceptance IP addressesAustralia (Sydney)
VercelWeb application hostingAll data in transit through the web app, and through our iPhone and Android apps, which render their workspace from itAustralia (Sydney)
Cloudflare R2File storageVoice recordings, site photos, plan documents, generated PDFs, forwarded supplier invoicesGlobal (Cloudflare network)
ResendEmail delivery and inbound emailOutbound: customer name and email; email content; PDF attachments with acceptance details; replies a contractor sends to an enquirer from Knack, with any files attached. Inbound: mail sent to a contractor's private capture addresses — forwarded work enquiries and supplier invoices — including the sender's name and email, subject, message content, and attachmentsUnited States
TwilioText messages (SMS) — only for accounts with texting turned onOutbound: the customer's mobile number and the text a contractor types to them from a job. Inbound: the sender's mobile number and their replyUnited States
GroqSpeech-to-textVoice audio, which may contain spoken customer names, phones, and addresses; plus a short recognition-context list of the account's brand/product terms and (for job captures) customer namesUnited States
OpenAIAI drafting and extractionTranscript text; customer name, phone, email, and address extracted from voice notes; the content of supplier invoices a contractor forwards to us; a short excerpt of a forwarded work enquiry when automatic sorting cannot decide which queue section it belongs in; and the subject and message text of a forwarded work enquiry when the contractor chooses to start a job from itUnited States
ClerkAuthenticationContractor name, email, and login/session dataUnited States
StripeSubscription billingContractor billing name and email (card data is handled entirely by Stripe)United States
GeoapifyAddress lookup and geocodingAddress text typed or stored for a customer or siteEurope (Germany)
AddressFinderAddress lookup (New Zealand fallback)Address textNew Zealand
Google (Solar API)Roof geometry for solar design (solar-enabled accounts only)The site's latitude and longitude — a customer's property locationUnited States

Alternate and failover providers

The following are present in the software but are not in the default path. They may process the same categories of data as their primary equivalent if selected as an alternative or used as a failover: Google (Gemini) and xAI (Grok) as alternatives for AI drafting; OpenAI as a speech-to-text failover; and OpenStreetMap Nominatim for address lookup only if the providers above are unconfigured.

Infrastructure providers

Sentry captures application errors with personal information scrubbed before sending (no request bodies, no client IP), from the United States. LINZ Basemaps provides aerial map imagery (map tile coordinates only, no personal information) from New Zealand. Browser push services (Google, Apple, Mozilla, Microsoft) deliver notifications using an encrypted device subscription and a payload that contains no personal information. For our iPhone and Android apps, Expo (Expo's push service, United States) relays notifications using a device push token and the same payload contract — the payload contains no personal information.

Knack staff

Knack's own staff are not a subprocessor, but for completeness: a small, named group of authorised Knack staff can access an account's state — settings, statuses, delivery records and error messages, not the content of quotes, notes, photos or messages by default — to provide support and investigate problems. Every such access is logged and the log is kept permanently. Knack staff never sign in as you or act in your name. See section 6 of our Privacy Policy.

Integrations you choose to connect

Business software a contractor connects to their own account — currently Xero (accounting) and Fergus (job management) — is not a subprocessor: it does not work for us, and it receives information only at the connecting contractor's direction (typically the customer's name and email and the line details of an accepted quote, so the contractor can raise their invoice or run the job there). Knack does not read information back from Fergus. From Xero it reads back only the status of the invoices it drafted there (awaiting payment, part paid or paid, the amount still due and the due date), keeping each invoice's current status only. Once received, information sent to either provider is governed by that provider's own terms and privacy policy. See section 4 of our Privacy Policy.

The same applies to an AI assistant a contractor connects to their own account with a token they create in Settings, or by signing in from the AI app (for example Claude, ChatGPT, Grok or Cursor, on a subscription they hold): it is not a subprocessor, Knack sends it nothing — the contractor's tool fetches a job's working material from Knack with that credential — and where the tool sends what it read is governed by that AI provider's own terms. See section 4 of our Privacy Policy.

A calendar provider a team member subscribes to their schedule with — for example Google Calendar, Apple Calendar or Outlook — is likewise not a subprocessor: it does not work for us, and it receives information only because that member chose to point it at their own private feed link. Unlike the integrations above the transfer is a pull: Knack sends nothing, and the provider fetches the member's bookings (job and customer name, site address, visit notes, non-job time) for as long as the subscription lasts. Revoking the feed link stops future fetches. See section 4 of our Privacy Policy.

The same applies to a contractor's own Google Drive, which they can connect so copies of the compliance certificates they issue are saved into a folder there. Knack uses the narrowest Google permission available (access only to files Knack itself created), the transfer is one-way, and the contractor can disconnect at any time — files already saved remain theirs, in their own Drive.

CertPilot, the certification software an electrical contractor can hand a job to, is further still from a subprocessor: it is self-hosted, one instance per contractor, so the contractor supplies the address and the access token and runs the system themselves. A handoff sends that instance the job's identity and site address, the customer's name, email and phone, a description of the work, and which installed products the compliance documents rely on — no pricing, no test results. One-way, at the contractor's direction, disconnectable at any time.

The calendar import is the one connection that runs inward. A team member can paste the private address of another calendar of their own, and Knack fetches it periodically for busy times only — start and end, never titles, locations or attendees. Knack sends that provider nothing but the request, and disconnecting deletes the times Knack had cached. See section 1 of our Privacy Policy.