Data & Compliance
Your data is your business. RafterCore is built for roofing contractors who trust us with their customer records, job data, and financial information. We take that responsibility seriously — this page explains exactly how we protect it, who can access it, and what rights you have.
Overview
RafterCore is operated by RafterCore LLC, a Arizona limited liability company doing business as RafterCore, headquartered in Phoenix, AZ. We provide a B2B SaaS roofing contractor management platform accessed at raftercore.com.
We act as a data controller for the personal information of merchant (contractor) account holders, and as a data processor on behalf of our merchant customers for the homeowner data they collect and manage through our platform.
Security Controls
RafterCore employs layered security controls across infrastructure, application, and operational levels.
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS.
All database records, file uploads, and backups are encrypted at rest using AES-256 encryption via Supabase's managed PostgreSQL infrastructure.
Every merchant account is isolated at the database level using Supabase Row-Level Security (RLS). No merchant can access another merchant's data under any circumstances.
Merchant accounts use Supabase Auth with bcrypt-hashed passwords. OAuth 2.0 is supported for Google sign-in. Session tokens expire after periods of inactivity.
All API endpoints require authentication. Webhook payloads are signed with HMAC-SHA256. API keys use the rfc_live_ prefix and are hashed before storage.
All credentials and API keys are stored as environment variables in Netlify's encrypted secrets vault. No secrets are hardcoded in application source code.
Internal access to production systems is restricted to authorized personnel only. All administrative actions are logged and auditable.
RafterCore is deployed on Netlify's global CDN with DDoS protection. The database is hosted on Supabase (AWS us-east-1) with automated backups and point-in-time recovery.
All API keys and credentials are rotated on a scheduled basis and immediately upon any suspected compromise. Rotation logs are maintained internally.
GDPR Compliance
RafterCore is compliant with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR. If you are located in the European Economic Area (EEA) or the United Kingdom, the following applies.
Lawful Basis for Processing
| Processing Activity | Lawful Basis |
|---|---|
| Account creation and management | Contract (Art. 6(1)(b)) |
| Billing and payment processing | Contract (Art. 6(1)(b)) |
| Sending transactional emails | Contract (Art. 6(1)(b)) |
| Platform analytics and improvement | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Legal compliance and fraud prevention | Legal obligation (Art. 6(1)(c)) |
| Processing homeowner data on behalf of merchants | Contract — processor role (Art. 6(1)(b)) |
Data Transfers Outside the EEA
RafterCore's infrastructure is hosted in the United States (AWS us-east-1). Where we transfer personal data from the EEA to the US, we rely on Standard Contractual Clauses (SCCs) and the data processing agreements maintained by our sub-processors (Supabase, Stripe, Resend, and others listed below).
Data Protection Officer
RafterCore does not currently meet the thresholds requiring a mandatory DPO appointment under GDPR Article 37. However, all data protection inquiries should be directed to privacy@raftercore.com.
CCPA / CPRA (California)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights regarding your personal information.
Categories of Personal Information Collected
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email address, IP address, account ID | Yes |
| Commercial information | Subscription plan, payment history, job records | Yes |
| Internet activity | Pages visited, features used, session duration | Yes |
| Geolocation data | Address-level data for job locations | Yes |
| Professional information | Contractor license number, business name | Yes |
| Sensitive personal information | Payment card data (tokenized via Stripe only) | Yes (tokenized) |
| Biometric data | None | No |
| Health information | None | No |
Do We Sell Personal Information?
No. RafterCore does not sell, rent, or share personal information with third parties for cross-context behavioral advertising. We do not have data broker relationships.
California Privacy Rights
Request disclosure of the categories and specific pieces of personal information we have collected about you.
Request deletion of your personal information, subject to certain exceptions required by law or contract.
Request correction of inaccurate personal information we hold about you.
Opt out of the sale or sharing of personal information (we do not sell data).
We will not discriminate against you for exercising any of your CCPA rights.
Request that we limit use of sensitive personal information to what is necessary to perform the services.
Data We Hold
The following summarizes the categories of data stored on the RafterCore platform by data subject type.
Merchant (Contractor) Data
| Data Type | Purpose | Storage Location |
|---|---|---|
| Name, email, phone | Account identity and communication | Supabase (encrypted) |
| Business name, license number | Platform verification | Supabase (encrypted) |
| Billing information (tokenized) | Subscription billing | Stripe (tokenized) |
| Subscription plan and status | Access control and billing | Supabase |
| API keys (hashed) | Third-party integrations | Supabase (SHA-256 hashed) |
| Feature flags | Platform feature access | Supabase |
| Platform usage analytics | Product improvement | Google Analytics (GA4) |
Homeowner (Customer) Data
| Data Type | Purpose | Storage Location |
|---|---|---|
| Name, email, phone | Job communication and portal access | Supabase (encrypted) |
| Property address | Job site identification and aerial measurements | Supabase (encrypted) |
| Job records, photos, documents | Project management and homeowner portal | Supabase + Supabase Storage |
| Insurance claim details | Insurance supplement workflow | Supabase (encrypted) |
| Payment records | Job billing (if applicable) | Stripe (tokenized) |
| Chat messages | Contractor-homeowner communication | Supabase (encrypted) |
Data Retention
We retain your data only as long as necessary to provide the services and meet our legal obligations.
| Data Category | Retention Period | Basis |
|---|---|---|
| Active account data | Duration of subscription + 90 days | Service delivery |
| Billing records | 7 years after last transaction | Tax and legal compliance |
| Job records and documents | Duration of subscription + 90 days | Service delivery |
| Deleted account data | 30 days after deletion request | Recovery period |
| Server access logs | 90 days | Security monitoring |
| Analytics data (GA4) | 14 months (Google default) | Product improvement |
| Backup snapshots | 30 days rolling | Disaster recovery |
| API access logs | 90 days | Security and debugging |
To request early deletion of your data, visit our account deletion page or email privacy@raftercore.com.
Sub-processors
RafterCore uses the following third-party sub-processors to deliver our services. Each is bound by data processing agreements and applicable privacy regulations.
| Sub-processor | Purpose | Data Location | Privacy Policy |
|---|---|---|---|
| Supabase | Database, authentication, file storage | AWS us-east-1 (USA) | supabase.com/privacy |
| Netlify | Web hosting, serverless functions, CDN | USA / Global CDN | netlify.com/privacy |
| Stripe | Payment processing and billing | USA | stripe.com/privacy |
| Resend | Transactional email delivery | USA | resend.com/privacy |
| Vonage / Twilio | SMS notifications and phone verification | USA | vonage.com/privacy |
| Anthropic (Claude AI) | AI supplement writing, roof analysis | USA | anthropic.com/privacy |
| Google Maps | Aerial roof measurements, address lookup | USA / Global | policies.google.com |
| Google Analytics (GA4) | Website analytics and usage tracking | USA / Global | policies.google.com |
| Google Tag Manager | Tag and tracking script management | USA / Global | policies.google.com |
| VAPI | AI voice assistant for lead handling | USA | vapi.ai/privacy |
We review our sub-processors regularly and update this list when new processors are added or existing ones are removed. Last reviewed: July 4, 2026.
Data Processing Agreement (DPA)
Enterprise customers and any merchant who processes personal data of EU/EEA residents through RafterCore may request a Data Processing Agreement (DPA) that satisfies GDPR Article 28 requirements.
What the DPA Covers
- Subject matter and duration of processing
- Nature and purpose of processing
- Type of personal data and categories of data subjects
- Obligations and rights of the data controller (you)
- RafterCore's obligations as data processor
- Sub-processor authorization and flow-down requirements
- Security measures and breach notification procedures
- International data transfer mechanisms (SCCs)
RafterCore's full Data Processing Agreement is available at raftercore.com/dpa. All merchants accept the DPA as part of the Terms of Service at account creation. Enterprise customers requiring a countersigned version may email legal@raftercore.com with the subject line "DPA Request — [Your Company Name]". We respond within 5 business days.
Incident Response
RafterCore maintains a documented incident response procedure to detect, contain, and communicate data security incidents promptly.
Response Timeline
| Phase | Timeline | Action |
|---|---|---|
| Detection & Containment | Within 1 hour | Identify scope, isolate affected systems, preserve logs |
| Internal Assessment | Within 24 hours | Determine data types affected, number of individuals, root cause |
| Merchant Notification | Within 48 hours | Notify affected merchants via email with incident details |
| Regulatory Notification (GDPR) | Within 72 hours | Notify relevant supervisory authority if required under Art. 33 |
| Individual Notification (GDPR) | Without undue delay | Notify affected individuals if high risk to rights and freedoms (Art. 34) |
| Post-Incident Review | Within 14 days | Root cause analysis, remediation steps, policy updates |
Reporting a Security Issue
If you discover a security vulnerability or suspect a data breach, please contact us immediately at security@raftercore.com. We take all reports seriously and respond within 24 hours.
Your Rights
Depending on your location, you have the following rights regarding your personal data. We honor all requests free of charge within 30 days.
Request a copy of all personal data we hold about you in a portable, machine-readable format.
Request correction of inaccurate or incomplete personal data we hold.
Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
Request that we restrict processing of your data while a dispute is resolved.
Receive your data in a structured, commonly used format and transfer it to another provider.
Object to processing based on legitimate interests or for direct marketing purposes.
Request human review of any decisions made solely by automated processing that significantly affect you.
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise any of these rights, email privacy@raftercore.com or use our account deletion page for erasure requests. We verify your identity before processing requests. We respond within 30 days (extendable by 60 days for complex requests with notice).
Contact & Data Requests
For any data protection, privacy, or compliance inquiries:
| Privacy & Data Requests | privacy@raftercore.com |
| Security Vulnerabilities | security@raftercore.com |
| DPA & Legal Requests | legal@raftercore.com |
| General Contact | contact@raftercore.com |
| Mailing Address | RafterCore LLC PO Box 6308, Phoenix, AZ 85009 |
| Response Time | Within 2 business days for general inquiries; 30 days for formal data subject requests |