Security and data handling

Your roster holds personal details about volunteers who never chose this software. Here is exactly where that data lives and who can reach it.

Where your data lives

Application data is stored in a managed PostgreSQL database run by Supabase, hosted in the United States. The application itself runs on Vercel. Both providers encrypt data at rest, and every connection to the site is encrypted in transit over TLS.

Who can reach it

Every record is scoped to your organization, and each request checks that the signed-in user belongs to the organization whose data it is asking for. Database-level row security is enabled as a second layer behind those application checks.

Within Upspire Studio, administrative access is limited to a single named account. It exists so support requests and billing problems can actually be resolved, and it is used for that.

How people sign in

Coordinators sign in with a magic link sent to their email address. There is no password to choose, reuse, or leak, and we never store one.

Board members have no accounts at all. They reach their portal through a signed link that expires after 30 days. It carries no password and grants access only to that one member’s own information — their meetings, their onboarding, their documents.

Payments

Card details are handled entirely by Stripe and never reach our servers. We store a Stripe customer reference and your plan status, which is what billing needs and nothing more.

Who else processes your data

SupabaseDatabase, file storage, and authentication
VercelApplication hosting and delivery
StripeSubscription billing and card processing
ResendTransactional email — invitations, reminders, alerts
TwilioSMS reminders, when your organization enables them

These are service providers processing data on our instructions. We do not sell your data, share it with advertisers, or use board rosters to train anything.

Getting your data out

Member records and the skills matrix export to CSV from inside the app at any time, without asking us. Board packet documents remain downloadable in their original form.

If you want your organization deleted, email us and we will remove the organization and its records — members, terms, committees, meetings, candidates, documents, and messages. Deletion is permanent, so export anything you want to keep first.

What we do not claim

Board Manager is a small independent product. We have not completed a SOC 2 audit, a penetration test by an outside firm, or HIPAA certification. If your organization requires any of those, we would rather tell you now than have you discover it during a review.

If you find a security problem, email us and we will respond. We would much rather hear about it from you than from someone else.

The privacy policy covers the legal commitments, and the terms of service cover the agreement itself.