To deliver the AiHeadshots service, we engage a small number of third-party data processors and content-delivery providers. We evaluate the security and privacy practices of each sub-processor and enter into a Data Protection Agreement (DPA) with them before they process customer data.
What is a sub-processor?
A sub-processor is a third-party data processor engaged by AiHeadshots that has, or potentially will have, access to or processes customer content containing personal information — for example, the cloud provider that hosts your generated headshots.
Due diligence & safeguards
Before engaging a sub-processor we review its security posture and data-handling practices, and we maintain a Data Protection Agreement with each one. Customers who need a copy of our DPA can email hello@aiheadshots.ai.
Changes to this list
We keep this page current as our vendor set evolves. Material changes to our sub-processors will be reflected here.
Infrastructure & AI processing
| Entity | Purpose | Location |
|---|---|---|
| Railway Corp. | Application hosting, compute, and database & image storage | US |
| Google LLC | AI headshot generation (Gemini image models) | US |
| OpenAI, L.L.C. | AI headshot generation (alternative image model) | US |
Service providers
| Entity | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | US |
| Resend, Inc. | Transactional & lifecycle email | US |
| Klaviyo, Inc. | Marketing email & newsletter | US |
| Google LLC | Authentication (Google sign-in) & product analytics (GA4) | US |
Content delivery
Public website assets and generated images are cached and served through our hosting providers' content-delivery networks so they load quickly wherever you are.
Contact
Questions about our sub-processors or data handling? Email hello@aiheadshots.ai. See also our Privacy Notice and Data Management & Retention policy.



