Skip to content

GoRefer Trust Center

Sub-processors

Updated April 2026

GoRefer uses the following third-party sub-processors to deliver the service. This register shows what data flows to each provider. The certifications listed are the ones each provider publishes; we have not independently verified every vendor agreement or certification. You can request the provider terms and data-processing agreements that apply to your account.

Encryption in transit is not the same as redaction. Some providers must process readable data to perform their service: document recognition receives uploaded documents, messaging services receive message content, and payment services receive billing information. Removing identifiers from case details does not remove them from the original documents sent for recognition.

AWS services
Provider terms on request
GDPR rights & policies
Data Flows Disclosed

4

High Sensitivity

4

Medium Sensitivity

6

Low Sensitivity

Sub-processors by Category

Updated April 2026

Change notification

GoRefer provides 30 days notice before adding or replacing a sub-processor that processes customer personal data. Customers on Growth, Scale, or Enterprise plans can object to new sub-processors in writing. Subscribe by emailing privacy@gorefer.io.

Infrastructure

4 vendors
VendorData SensitivityPurposeData ProcessedRegionCertifications
Amazon Web ServicesHighApplication hosting, compute, and file storage
User data
Firm data
Uploaded documents
Session data
PII (encrypted at rest)
United States (us-east-1)
SOC 1 / 2 / 3
ISO 27001
HIPAA BAA eligible
PCI DSS Level 1
MongoDB AtlasHighPrimary database (multi-tenant, per-firm isolated databases)
User data
Referral records
Commission data
Audit logs
Encrypted PII
United States (AWS us-east-1)
SOC 2 Type II
ISO 27001
GDPR compliant
CloudflareLowDNS management, DDoS mitigation, and CDN acceleration
IP addresses
Request metadata processed at the network edge
Global edge network
SOC 2 Type II
ISO 27001
PCI DSS
TwilioHighClient SMS delivery, phone number provisioning and porting, and A2P 10DLC brand/campaign registration
Client phone numbers
SMS message content
Firm business identity and address data (A2P registration)
Authorized representative contact details
Delivery metadata
United States / Global

Payments

1 vendor
VendorData SensitivityPurposeData ProcessedRegionCertifications
StripeHighSubscription billing, platform fee collection, preparer payouts via Stripe Connect
Billing information
Bank account details (Stripe-hosted)
Transaction records
United States / Global
PCI DSS Level 1
SOC 1 Type II
SOC 2 Type II

AI / ML

2 vendors
VendorData SensitivityPurposeData ProcessedRegionCertifications
Microsoft AzureMediumMicrosoft Foundry (Gio's only AI generation path), Azure OpenAI as the fallback deployment behind it, and document recognition for uploaded tax documents
Uploaded document content, including identifiers present in the source document
Gio prompts and AI chat messages; provider retention follows the applicable service configuration
Client names and case narrative inside those prompts
Case-context prompts redact supported identifiers; raw document recognition is a separate data flow
United States (East US)
SOC 1 / 2 / 3
ISO 27001
HIPAA BAA eligible
GDPR compliant
ElevenLabsLowAI voice generation for voice-enabled features
Voice interaction text; provider retention depends on the service terms
United States
SOC 2 Type II

Analytics

2 vendors
VendorData SensitivityPurposeData ProcessedRegionCertifications
HeyCatchLowProduct analytics on the public marketing website only (gorefer.io). Not loaded inside the signed-in application, and not loaded at all when the browser sends Do Not Track or Global Privacy Control.
Page URL and referrer (marketing site only)
Interaction events on public pages
Browser/OS metadata, screen size, language, time zone
Approximate location derived from IP
United States
Meta PlatformsMediumAdvertising measurement on the public marketing website (gorefer.io) and webinar registration pages (app.gorefer.io/webinar/). The marketing Pixel honors DNT/GPC; the separate webinar Pixel currently does not. Not loaded inside the signed-in application.
Meta click identifiers (_fbp, _fbc)
IP address and browser user agent
Hashed email, phone and first/last name (SHA-256) — webinar registrations only
Public marketing and webinar page URLs and event names
United States / Global

Email

2 vendors
VendorData SensitivityPurposeData ProcessedRegionCertifications
Amazon Web Services (SES)MediumTransactional email delivery (notifications, invitations, receipts, dunning emails)
Email addresses
Email content (notification messages)
Delivery metadata
United States (us-west-2)
SOC 1/2/3
ISO 27001/17/18
PCI DSS Level 1
HIPAA-eligible
BeehiivLowMarketing newsletter and waitlist subscriptions from the public website
Email addresses
Signup source / UTM metadata
United States

Identity / Auth

1 vendor
VendorData SensitivityPurposeData ProcessedRegionCertifications
GoogleMediumOAuth 2.0 sign-in (optional), Google Calendar integration for appointment scheduling
OAuth tokens
Calendar event metadata (when integration enabled)
Global
SOC 1 / 2 / 3
ISO 27001

Error Tracking

1 vendor
VendorData SensitivityPurposeData ProcessedRegionCertifications
SentryLowReal-time application error tracking, performance monitoring, and sampled session replay (all text masked, all media blocked)
Stack traces
Request metadata
User ID (anonymized)
Browser/OS metadata
Masked session replay (DOM structure and interactions; text and media redacted in the browser)
United States
SOC 2 Type II
GDPR compliant

Storage

1 vendor
VendorData SensitivityPurposeData ProcessedRegionCertifications
SanityLowHeadless CMS storing and serving public blog content
Published blog content
Author names (published bylines)
United States / Global

Data Processing Agreements

Updated April 2026

GoRefer DPA available on request

All customers can request a Data Processing Agreement (DPA) from GoRefer. Enterprise customers receive a custom DPA reviewed with their legal team. Growth and Scale plans use our standard DPA. Request via the Trust Portal or by emailing privacy@gorefer.io.