Cloudflare
Object storage
Why we use it
Canonical binary object storage in R2 for uploaded media and files.
Data involved
Uploaded media/files and the bounded request metadata needed to store, retrieve or delete those objects.
Updated 28 September 2026. This page describes the main external providers represented in the current product architecture. A provider listed as "where enabled" only processes a user's data when that configured feature is actually used.
Object storage
Why we use it
Canonical binary object storage in R2 for uploaded media and files.
Data involved
Uploaded media/files and the bounded request metadata needed to store, retrieve or delete those objects.
Core backend
Why we use it
Primary PostgreSQL database, authentication, row-level authorization, protected RPC and Edge Function infrastructure.
Data involved
Account identifiers, profile/application records, assessment and workflow data, authorization metadata, and provider-facing feature context required by ClockIN.
Web hosting
Why we use it
Web application hosting, deployment and request delivery for the Next.js product.
Data involved
Web requests and application data needed to render or process a request.
AI and moderation provider
Why we use it
Configured AI-assisted hiring, transcription and public/community moderation features.
Data involved
Only the feature context needed for the configured task, such as bounded hiring context, interview audio/transcript material, or public/community text and public image URLs used for moderation.
Transactional email
Why we use it
Transactional email delivery for ClockIN account, verification, notification, calendar, early-access and hiring workflows.
Data involved
Recipient address, delivery metadata, and the message content needed for the requested or service-related email.
Meeting provider
Why we use it
Meeting-room functionality when a ClockIN meeting opens the supported Jitsi experience.
Data involved
Meeting/session information and browser media you intentionally provide to the meeting service under its own service terms.
Pre-Beta feedback
Why we use it
Collect structured Pre-Beta product feedback outside ClockIN.
Data involved
Answers testers choose to submit in the feedback form, plus metadata Google processes under its own service terms.
Payment provider where enabled
Why we use it
Payment processing for supported India checkout and subscription/payment workflows when enabled.
Data involved
Transaction identifiers, amount/currency, payment or subscription state, and provider-required billing/payment information.
Payment provider where enabled
Why we use it
Payment/subscription processing for supported international checkout where enabled.
Data involved
Transaction identifiers, amount/currency, subscription state, and provider-required billing/payment information.
Supabase is ClockIN's primary structured-data and authentication backend. Cloudflare R2 is the canonical binary-object store for uploaded media and files. D1 is retained only as a non-primary migration/test copy and is not the production source of truth.
Provider terms, processing locations and subprocessors can change. ClockIN reviews this list when material infrastructure or payment/model providers change and before launches that require additional transfer or processor documentation.