Trust Center
One place for how CGE Insights handles your data and what it agrees to. Each document also has its own page, so you can link straight to it.
Outside services that handle your data
These are the companies CGE Insights uses to run the service. This page is the public record of that list. A new service is added here before it handles any customer data.
Current as of 2026-08-03.
Required to run the service
The service cannot run without these.
| Service | What it does | What it handles |
|---|---|---|
| Supabase | Primary database | All Member and Customer data |
| Render | Backend hosting | Everything the API touches |
| Vercel | Frontend hosting + server-side proxy | Customer-user requests, session data, application responses |
| Stripe | Payments and billing | Billing contact and payment details |
| Resend | Transactional email | Recipient address and message content — magic links, notifications, form submissions |
Used only by certain features
Each of these supports one feature or one connection. If you would rather not use a service on this list, the feature that depends on it can be turned off for your account.
| Service | What it does | What it handles |
|---|---|---|
| Google Cloud (Gemini) | Strategy Advisor, Ask Cora | Behavioral signals and derived flags — no Member names or emails |
| Google SSO | Customer-user sign-in | Customer-user identity only — never Member data |
| Microsoft SSO | Customer-user sign-in | Customer-user identity only |
| Mailchimp / Mandrill | Email engagement in, outreach out | Member email and outreach content, when the Customer connects it |
| Novi AMS | Member roster sync | Roster fields synchronized both ways |
| Sentry | Application error monitoring | Error and diagnostic data |
Listed for openness
This one is part of how the service runs, but it never receives personal data. It is listed so nothing in the stack is unexplained.
| Service | What it does | Why it is not on the list above |
|---|---|---|
| cron-job.org | It triggers background work on a schedule | Receives no personal data — only authenticated requests telling the backend to run a job. Disclosed because an unexplained third party in the stack invites the question |
Places you send data yourself
If you set up a webhook, or connect Slack or Microsoft Teams, member data goes to a destination you chose. Those destinations are yours to manage, so they are not on this list.