GoRefer Trust Center
Sub-processors
Updated April 2026
GoRefer uses the following third-party sub-processors to deliver the service. This register shows what data flows to each provider. The certifications listed are the ones each provider publishes; we have not independently verified every vendor agreement or certification. You can request the provider terms and data-processing agreements that apply to your account.
Encryption in transit is not the same as redaction. Some providers must process readable data to perform their service: document recognition receives uploaded documents, messaging services receive message content, and payment services receive billing information. Removing identifiers from case details does not remove them from the original documents sent for recognition.
4
High Sensitivity
4
Medium Sensitivity
6
Low Sensitivity
Sub-processors by Category
Updated April 2026
Change notification
GoRefer provides 30 days notice before adding or replacing a sub-processor that processes customer personal data. Customers on Growth, Scale, or Enterprise plans can object to new sub-processors in writing. Subscribe by emailing privacy@gorefer.io.
Infrastructure
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Amazon Web Services | High | Application hosting, compute, and file storage | User data Firm data Uploaded documents Session data PII (encrypted at rest) | United States (us-east-1) | SOC 1 / 2 / 3 ISO 27001 HIPAA BAA eligible PCI DSS Level 1 |
| MongoDB Atlas | High | Primary database (multi-tenant, per-firm isolated databases) | User data Referral records Commission data Audit logs Encrypted PII | United States (AWS us-east-1) | SOC 2 Type II ISO 27001 GDPR compliant |
| Cloudflare | Low | DNS management, DDoS mitigation, and CDN acceleration | IP addresses Request metadata processed at the network edge | Global edge network | SOC 2 Type II ISO 27001 PCI DSS |
| Twilio | High | Client SMS delivery, phone number provisioning and porting, and A2P 10DLC brand/campaign registration | Client phone numbers SMS message content Firm business identity and address data (A2P registration) Authorized representative contact details Delivery metadata | United States / Global |
Payments
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Stripe | High | Subscription billing, platform fee collection, preparer payouts via Stripe Connect | Billing information Bank account details (Stripe-hosted) Transaction records | United States / Global | PCI DSS Level 1 SOC 1 Type II SOC 2 Type II |
AI / ML
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Microsoft Azure | Medium | Microsoft Foundry (Gio's only AI generation path), Azure OpenAI as the fallback deployment behind it, and document recognition for uploaded tax documents | Uploaded document content, including identifiers present in the source document Gio prompts and AI chat messages; provider retention follows the applicable service configuration Client names and case narrative inside those prompts Case-context prompts redact supported identifiers; raw document recognition is a separate data flow | United States (East US) | SOC 1 / 2 / 3 ISO 27001 HIPAA BAA eligible GDPR compliant |
| ElevenLabs | Low | AI voice generation for voice-enabled features | Voice interaction text; provider retention depends on the service terms | United States | SOC 2 Type II |
Analytics
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| HeyCatch | Low | Product analytics on the public marketing website only (gorefer.io). Not loaded inside the signed-in application, and not loaded at all when the browser sends Do Not Track or Global Privacy Control. | Page URL and referrer (marketing site only) Interaction events on public pages Browser/OS metadata, screen size, language, time zone Approximate location derived from IP | United States | |
| Meta Platforms | Medium | Advertising measurement on the public marketing website (gorefer.io) and webinar registration pages (app.gorefer.io/webinar/). The marketing Pixel honors DNT/GPC; the separate webinar Pixel currently does not. Not loaded inside the signed-in application. | Meta click identifiers (_fbp, _fbc) IP address and browser user agent Hashed email, phone and first/last name (SHA-256) — webinar registrations only Public marketing and webinar page URLs and event names | United States / Global |
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Amazon Web Services (SES) | Medium | Transactional email delivery (notifications, invitations, receipts, dunning emails) | Email addresses Email content (notification messages) Delivery metadata | United States (us-west-2) | SOC 1/2/3 ISO 27001/17/18 PCI DSS Level 1 HIPAA-eligible |
| Beehiiv | Low | Marketing newsletter and waitlist subscriptions from the public website | Email addresses Signup source / UTM metadata | United States |
Identity / Auth
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Medium | OAuth 2.0 sign-in (optional), Google Calendar integration for appointment scheduling | OAuth tokens Calendar event metadata (when integration enabled) | Global | SOC 1 / 2 / 3 ISO 27001 |
Error Tracking
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Sentry | Low | Real-time application error tracking, performance monitoring, and sampled session replay (all text masked, all media blocked) | Stack traces Request metadata User ID (anonymized) Browser/OS metadata Masked session replay (DOM structure and interactions; text and media redacted in the browser) | United States | SOC 2 Type II GDPR compliant |
Storage
| Vendor | Data Sensitivity | Purpose | Data Processed | Region | Certifications |
|---|---|---|---|---|---|
| Sanity | Low | Headless CMS storing and serving public blog content | Published blog content Author names (published bylines) | United States / Global |
Data Processing Agreements
Updated April 2026
GoRefer DPA available on request
All customers can request a Data Processing Agreement (DPA) from GoRefer. Enterprise customers receive a custom DPA reviewed with their legal team. Growth and Scale plans use our standard DPA. Request via the Trust Portal or by emailing privacy@gorefer.io.