Trust & Security

Data & Compliance

Last updated: July 4, 2026  ·  Applies to all RafterCore merchants, homeowners, and partners

Your data is your business. RafterCore is built for roofing contractors who trust us with their customer records, job data, and financial information. We take that responsibility seriously — this page explains exactly how we protect it, who can access it, and what rights you have.

Overview

RafterCore is operated by RafterCore LLC, a Arizona limited liability company doing business as RafterCore, headquartered in Phoenix, AZ. We provide a B2B SaaS roofing contractor management platform accessed at raftercore.com.

We act as a data controller for the personal information of merchant (contractor) account holders, and as a data processor on behalf of our merchant customers for the homeowner data they collect and manage through our platform.

🔒 TLS 1.2+ Encryption in Transit
🛡️ AES-256 Encryption at Rest
🏗️ Row-Level Security (Supabase RLS)
🌐 GDPR Compliant
🇺🇸 CCPA / CPRA Compliant
🔑 Multi-Factor Authentication

Security Controls

RafterCore employs layered security controls across infrastructure, application, and operational levels.

🔐
Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS.

💾
Encryption at Rest

All database records, file uploads, and backups are encrypted at rest using AES-256 encryption via Supabase's managed PostgreSQL infrastructure.

🏗️
Row-Level Security

Every merchant account is isolated at the database level using Supabase Row-Level Security (RLS). No merchant can access another merchant's data under any circumstances.

🔑
Authentication

Merchant accounts use Supabase Auth with bcrypt-hashed passwords. OAuth 2.0 is supported for Google sign-in. Session tokens expire after periods of inactivity.

🌐
API Security

All API endpoints require authentication. Webhook payloads are signed with HMAC-SHA256. API keys use the rfc_live_ prefix and are hashed before storage.

🔍
Secrets Management

All credentials and API keys are stored as environment variables in Netlify's encrypted secrets vault. No secrets are hardcoded in application source code.

🚦
Access Controls

Internal access to production systems is restricted to authorized personnel only. All administrative actions are logged and auditable.

🛡️
Infrastructure Security

RafterCore is deployed on Netlify's global CDN with DDoS protection. The database is hosted on Supabase (AWS us-east-1) with automated backups and point-in-time recovery.

🔄
Key Rotation Policy

All API keys and credentials are rotated on a scheduled basis and immediately upon any suspected compromise. Rotation logs are maintained internally.

GDPR Compliance

RafterCore is compliant with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR. If you are located in the European Economic Area (EEA) or the United Kingdom, the following applies.

Lawful Basis for Processing

Processing ActivityLawful Basis
Account creation and managementContract (Art. 6(1)(b))
Billing and payment processingContract (Art. 6(1)(b))
Sending transactional emailsContract (Art. 6(1)(b))
Platform analytics and improvementLegitimate interests (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
Legal compliance and fraud preventionLegal obligation (Art. 6(1)(c))
Processing homeowner data on behalf of merchantsContract — processor role (Art. 6(1)(b))

Data Transfers Outside the EEA

RafterCore's infrastructure is hosted in the United States (AWS us-east-1). Where we transfer personal data from the EEA to the US, we rely on Standard Contractual Clauses (SCCs) and the data processing agreements maintained by our sub-processors (Supabase, Stripe, Resend, and others listed below).

Data Protection Officer

RafterCore does not currently meet the thresholds requiring a mandatory DPO appointment under GDPR Article 37. However, all data protection inquiries should be directed to privacy@raftercore.com.

CCPA / CPRA (California)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights regarding your personal information.

Categories of Personal Information Collected

CategoryExamplesCollected
IdentifiersName, email address, IP address, account IDYes
Commercial informationSubscription plan, payment history, job recordsYes
Internet activityPages visited, features used, session durationYes
Geolocation dataAddress-level data for job locationsYes
Professional informationContractor license number, business nameYes
Sensitive personal informationPayment card data (tokenized via Stripe only)Yes (tokenized)
Biometric dataNoneNo
Health informationNoneNo

Do We Sell Personal Information?

No. RafterCore does not sell, rent, or share personal information with third parties for cross-context behavioral advertising. We do not have data broker relationships.

California Privacy Rights

📋
Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected about you.

🗑️
Right to Delete

Request deletion of your personal information, subject to certain exceptions required by law or contract.

✏️
Right to Correct

Request correction of inaccurate personal information we hold about you.

🚫
Right to Opt-Out

Opt out of the sale or sharing of personal information (we do not sell data).

⚖️
Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights.

🔒
Limit Sensitive Data Use

Request that we limit use of sensitive personal information to what is necessary to perform the services.

Data We Hold

The following summarizes the categories of data stored on the RafterCore platform by data subject type.

Merchant (Contractor) Data

Data TypePurposeStorage Location
Name, email, phoneAccount identity and communicationSupabase (encrypted)
Business name, license numberPlatform verificationSupabase (encrypted)
Billing information (tokenized)Subscription billingStripe (tokenized)
Subscription plan and statusAccess control and billingSupabase
API keys (hashed)Third-party integrationsSupabase (SHA-256 hashed)
Feature flagsPlatform feature accessSupabase
Platform usage analyticsProduct improvementGoogle Analytics (GA4)

Homeowner (Customer) Data

Data TypePurposeStorage Location
Name, email, phoneJob communication and portal accessSupabase (encrypted)
Property addressJob site identification and aerial measurementsSupabase (encrypted)
Job records, photos, documentsProject management and homeowner portalSupabase + Supabase Storage
Insurance claim detailsInsurance supplement workflowSupabase (encrypted)
Payment recordsJob billing (if applicable)Stripe (tokenized)
Chat messagesContractor-homeowner communicationSupabase (encrypted)

Data Retention

We retain your data only as long as necessary to provide the services and meet our legal obligations.

Data CategoryRetention PeriodBasis
Active account dataDuration of subscription + 90 daysService delivery
Billing records7 years after last transactionTax and legal compliance
Job records and documentsDuration of subscription + 90 daysService delivery
Deleted account data30 days after deletion requestRecovery period
Server access logs90 daysSecurity monitoring
Analytics data (GA4)14 months (Google default)Product improvement
Backup snapshots30 days rollingDisaster recovery
API access logs90 daysSecurity and debugging

To request early deletion of your data, visit our account deletion page or email privacy@raftercore.com.

Sub-processors

RafterCore uses the following third-party sub-processors to deliver our services. Each is bound by data processing agreements and applicable privacy regulations.

Sub-processorPurposeData LocationPrivacy Policy
SupabaseDatabase, authentication, file storageAWS us-east-1 (USA)supabase.com/privacy
NetlifyWeb hosting, serverless functions, CDNUSA / Global CDNnetlify.com/privacy
StripePayment processing and billingUSAstripe.com/privacy
ResendTransactional email deliveryUSAresend.com/privacy
Vonage / TwilioSMS notifications and phone verificationUSAvonage.com/privacy
Anthropic (Claude AI)AI supplement writing, roof analysisUSAanthropic.com/privacy
Google MapsAerial roof measurements, address lookupUSA / Globalpolicies.google.com
Google Analytics (GA4)Website analytics and usage trackingUSA / Globalpolicies.google.com
Google Tag ManagerTag and tracking script managementUSA / Globalpolicies.google.com
VAPIAI voice assistant for lead handlingUSAvapi.ai/privacy

We review our sub-processors regularly and update this list when new processors are added or existing ones are removed. Last reviewed: July 4, 2026.

Data Processing Agreement (DPA)

Enterprise customers and any merchant who processes personal data of EU/EEA residents through RafterCore may request a Data Processing Agreement (DPA) that satisfies GDPR Article 28 requirements.

What the DPA Covers

RafterCore's full Data Processing Agreement is available at raftercore.com/dpa. All merchants accept the DPA as part of the Terms of Service at account creation. Enterprise customers requiring a countersigned version may email legal@raftercore.com with the subject line "DPA Request — [Your Company Name]". We respond within 5 business days.

Incident Response

RafterCore maintains a documented incident response procedure to detect, contain, and communicate data security incidents promptly.

Response Timeline

PhaseTimelineAction
Detection & ContainmentWithin 1 hourIdentify scope, isolate affected systems, preserve logs
Internal AssessmentWithin 24 hoursDetermine data types affected, number of individuals, root cause
Merchant NotificationWithin 48 hoursNotify affected merchants via email with incident details
Regulatory Notification (GDPR)Within 72 hoursNotify relevant supervisory authority if required under Art. 33
Individual Notification (GDPR)Without undue delayNotify affected individuals if high risk to rights and freedoms (Art. 34)
Post-Incident ReviewWithin 14 daysRoot cause analysis, remediation steps, policy updates

Reporting a Security Issue

If you discover a security vulnerability or suspect a data breach, please contact us immediately at security@raftercore.com. We take all reports seriously and respond within 24 hours.

Your Rights

Depending on your location, you have the following rights regarding your personal data. We honor all requests free of charge within 30 days.

👁️
Access

Request a copy of all personal data we hold about you in a portable, machine-readable format.

✏️
Rectification

Request correction of inaccurate or incomplete personal data we hold.

🗑️
Erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

Restriction

Request that we restrict processing of your data while a dispute is resolved.

📦
Portability

Receive your data in a structured, commonly used format and transfer it to another provider.

Object

Object to processing based on legitimate interests or for direct marketing purposes.

🤖
Automated Decisions

Request human review of any decisions made solely by automated processing that significantly affect you.

↩️
Withdraw Consent

Withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise any of these rights, email privacy@raftercore.com or use our account deletion page for erasure requests. We verify your identity before processing requests. We respond within 30 days (extendable by 60 days for complex requests with notice).

Contact & Data Requests

For any data protection, privacy, or compliance inquiries:

Privacy & Data Requestsprivacy@raftercore.com
Security Vulnerabilitiessecurity@raftercore.com
DPA & Legal Requestslegal@raftercore.com
General Contactcontact@raftercore.com
Mailing AddressRafterCore LLC
PO Box 6308, Phoenix, AZ 85009
Response TimeWithin 2 business days for general inquiries; 30 days for formal data subject requests