NexLife CRM uses the following third-party service providers ("subprocessors") to deliver the Services. This list is maintained in good faith and will be updated when material changes occur. Each provider has its own privacy and security posture, links are included below.
Hosting & Infrastructure
- Lovable Cloud, application hosting and preview infrastructure. Privacy policy.
- Supabase (managed Postgres, auth, storage), primary application database, authentication provider, and file storage for generated PDFs. Data resides in the United States. Privacy policy.
- Cloudflare, edge network / TLS termination for served traffic. Privacy policy.
Payments
- Stripe, subscription billing and card processing. Card numbers and CVVs are collected and stored by Stripe in a PCI-DSS Level 1 environment; NexLife receives only tokenized references. Privacy policy.
Email Delivery
- Resend, transactional email delivery (intake links, carrier submissions, receipts). Privacy policy.
Agent-Configured Integrations (optional, per-agent)
- GoHighLevel (GHL), if an Agent enables the GHL integration in Settings, intake submissions from that Agent's clients are forwarded to the Agent's own GHL sub-account via the webhook URL the Agent provides. Data forwarded outside NexLife is governed by the Agent's agreement with GHL, not by NexLife. Privacy policy.
Operational Notifications
- Discord, internal-only staff notification webhooks (sign-ins, sales, admin events). No client PII is sent to Discord; only operational metadata such as event type, IP, and coarse geolocation. Privacy policy.
Changes
We will update this page when we add, remove, or replace a subprocessor. If you have contracted for advance notice of subprocessor changes, that notice will be sent to the email address on your account.
Questions: privacy@nexlifecrm.org.
