Skip to content

Legal

Subprocessors

The vetted third-party vendors Updrone relies on to deliver the Service, grouped by function, with the purpose of each engagement and the types of data involved. Updrone sells software; these vendors help us host, bill, message, and power the AI features you use.

Last updated August 28, 2026· Version 2026-08-28

1. About this page

A “subprocessor” is a third-party vendor that Updrone, Inc. (“Updrone,” “we,” “us,” or “our”) engages to help operate the Updrone platform and that may process data — including personal data — on our behalf in the course of delivering the Service. This page lists the subprocessors we currently rely on, grouped by the function they perform, together with the purpose of the engagement and the types of data involved.

We keep this list deliberately short and describe every engagement plainly. Where we can operate a function ourselves, we do; we bring in a subprocessor only where a specialized vendor is the responsible choice, such as payment rails, email transport, and the cloud infrastructure that runs the platform. This page supplements, and should be read together with, our Privacy Policy (/privacy) and our Data Processing Addendum (/dpa), which governs how we process personal data on your behalf.

2. Payments — Stripe

We use Stripe to handle subscription billing for the Service and, through Stripe Connect, to enable tenant payouts and payments collected from your end customers. In that role Stripe processes billing contact details and payment metadata — for example, the amounts, dates, and references associated with a transaction — needed to charge, settle, and reconcile payments.

Card and bank details are collected and processed directly by Stripe under its own terms and security practices; Updrone does not receive or store full payment card numbers. Where your workflow collects a deposit or other payment from your end customer, you remain responsible for the terms of that transaction, and Stripe acts as the payment processor for it.

3. Email delivery — Resend

We use Resend to deliver transactional and customer-facing email, such as account notifications, message alerts, and the communications your workflow sends to your customers. To deliver a message, Resend processes recipient email addresses and the content of the message being sent.

Resend handles this data solely to transmit email on our behalf and under its own terms and security practices. You are responsible for having the permissions and lawful basis to send the communications you generate through the Service.

4. Cloud compute and object storage

The Service runs on third-party cloud infrastructure that provides the hosting, GPU-accelerated compute, and object storage behind the platform and the capture-processing pipeline. These providers process and store the data you and your end customers submit — including imagery, scenes, meshes, point clouds, and account and operational records — so that the Service can host, process, and serve it back to you.

This infrastructure is located in the United States. We describe these providers by the function they perform rather than by name; they process data only to operate the infrastructure on our behalf and are bound to the data-protection obligations described below.

5. AI features — Anthropic

We use Anthropic to power the product’s AI features, such as the in-product assistant and generated summaries. When you use one of these features, Anthropic processes the prompt and the context needed to produce a response — for example, the records or text you are asking the assistant to work with.

This data is processed to generate the requested response. It is not used to train models on your data without your consent, and Anthropic processes it under its own terms and security practices as our subprocessor for these features.

6. Mapping and solar data — Google

Where your workflow uses an address- or location-based feature — geocoding a property address to coordinates, or pulling a building's solar and roof characteristics — we send that address or those coordinates to Google (Google Maps Platform, including its Geocoding and Solar APIs) to return the corresponding map, place, or solar-resource data. In that role Google receives the property address and/or geographic coordinates for the location you are working with, and returns the requested result.

Google processes this data to fulfill the specific lookup and under its own terms and security practices as our subprocessor for these features. The location data reflects the sites you choose to work with; it does not identify your end customers, and we send only what the lookup requires.

7. Solar-resource data — NREL / NLR

Our solar features draw on the National Solar Radiation Database (NSRDB) and related solar-resource services operated by the National Laboratory for Renewables (NLR, formerly the National Renewable Energy Laboratory). When you run a solar estimate, we send the site's geographic coordinates to retrieve the modeled irradiance and solar-resource values for that location.

NLR receives only the coordinates needed to return the solar-resource data for the site, and processes them to fulfill that request. This is a location lookup for a site you choose to analyze; it does not include your end customers' personal data.

8. How we vet and bind subprocessors

Before engaging a subprocessor, we assess whether it is the responsible choice for the function and review its security and data-protection practices. We limit each subprocessor to the data it needs for its function, and we contractually bind each one to confidentiality obligations and to data-protection commitments consistent with our own — including handling data only on our documented instructions and maintaining appropriate technical and organizational safeguards such as encryption in transit and at rest, access controls, tenant isolation, and logging.

Engaging a subprocessor does not relieve Updrone of its obligations to you. We remain responsible to you for the performance of our subprocessors’ obligations, as set out in our Data Processing Addendum (/dpa).

9. Changes and notice

We may add, replace, or remove subprocessors as the Service evolves. When we make a change, we will update this page and the “Last updated” date, and we will provide notice of new subprocessors in accordance with our Data Processing Addendum (/dpa), including any right you have to object to a change.

We encourage you to check this page for the current list. Where you rely on the Service to process personal data on behalf of your own customers, the notice and objection process in the Data Processing Addendum (/dpa) governs how changes to this list take effect.

10. Contact

Questions about our subprocessors, or requests to be notified of changes to this list, can be sent to support@updrone.com. This page is part of the family of agreements that includes our Terms of Service (/terms), Privacy Policy (/privacy), Data Processing Addendum (/dpa), Acceptable Use Policy (/acceptable-use), and Cookie Policy (/cookies).