Where your data lives
Application data is stored in a managed PostgreSQL database run by Supabase, hosted in the United States. The application itself runs on Vercel. Both providers encrypt data at rest, and every connection to the site is encrypted in transit over TLS.
Who can reach it
Every record is scoped to your organization, and each request checks that the signed-in user belongs to the organization whose data it is asking for. Database-level row security is enabled as a second layer behind those application checks.
Within Upspire Studio, administrative access is limited to a single named account. It exists so support requests and billing problems can actually be resolved, and it is used for that.
How people sign in
Coordinators sign in with a magic link sent to their email address. There is no password to choose, reuse, or leak, and we never store one.
Board members have no accounts at all. They reach their portal through a signed link that expires after 30 days. It carries no password and grants access only to that one member’s own information — their meetings, their onboarding, their documents.
Payments
Card details are handled entirely by Stripe and never reach our servers. We store a Stripe customer reference and your plan status, which is what billing needs and nothing more.
Who else processes your data
| Supabase | Database, file storage, and authentication |
|---|---|
| Vercel | Application hosting and delivery |
| Stripe | Subscription billing and card processing |
| Resend | Transactional email — invitations, reminders, alerts |
| Twilio | SMS reminders, when your organization enables them |
These are service providers processing data on our instructions. We do not sell your data, share it with advertisers, or use board rosters to train anything.
Getting your data out
Member records and the skills matrix export to CSV from inside the app at any time, without asking us. Board packet documents remain downloadable in their original form.
If you want your organization deleted, email us and we will remove the organization and its records — members, terms, committees, meetings, candidates, documents, and messages. Deletion is permanent, so export anything you want to keep first.
What we do not claim
Board Manager is a small independent product. We have not completed a SOC 2 audit, a penetration test by an outside firm, or HIPAA certification. If your organization requires any of those, we would rather tell you now than have you discover it during a review.
If you find a security problem, email us and we will respond. We would much rather hear about it from you than from someone else.