Security overview
You trust us with utility bills and spend data. Here is exactly how that data is handled - answered before you have to ask. Questions: contact@sendrow.app
Where your data lives
All data is stored in a managed Postgres database (Neon) hosted in the United States, encrypted at rest (AES-256) and in transit (TLS 1.2+). Application hosting is on Vercel with the same encryption-in-transit guarantees.
Who can see it
Your data is visible only to your own account and, if you work with one, the consultant you have explicitly linked. Every consultant-client relationship is verified on every request - there is no cross-tenant access path. Sendrow staff access production data only for support you request, and every such access is logged.
Authentication
Sign-in is handled by Clerk (SOC 2 Type II certified), supporting Google OAuth. Sendrow never stores passwords. Client data-upload links are single-purpose tokens that expire after 30 days and grant access only to the specific request they were created for.
Audit trail
Every data change is logged with who, what, when, and the before/after values. Every calculated figure records its inputs, the emission factor and factor vintage used, and the formula - replayable at any time.
Your data is yours
Export everything (ZIP or JSON) from Settings at any time, no questions asked. Request deletion from Settings and we remove your data from production within 30 days, confirmed by email.
Subprocessors
Neon (database), Vercel (hosting), Clerk (authentication), Resend (email), Stripe (payments). Each is bound by its own data processing agreement.
See also: Data Processing Agreement template · Privacy policy · Terms