Data Residency
Last updated: September 2026
ScentShield takes data residency seriously. This page documents where your data is stored, processed, and transmitted across our infrastructure.
🗄️
Database
Supabase (AWS eu-west-1, Ireland)
- All formulas, compliance results, customer data, regulatory records
- Encrypted at rest (AES-256)
- Daily automated backups with 30-day retention
📁
File Storage
Supabase Storage (AWS eu-west-1, Ireland)
- Generated documents (SDS, PCN, dossiers)
- Supplier uploads
- Encrypted at rest
🌐
Application Hosting
Vercel (AWS, global edge network)
- Application code and static assets
- No persistent user data stored on Vercel
🧠
AI Processing
Anthropic API (US-based)
- Used for: regulatory search, copilot chat, document extraction
- Data sent: formula compositions, ingredient names, regulatory queries
- Anthropic does not train on your data (per their data policy)
- No persistent storage of queries by Anthropic
📧Email
Resend (US-based)
- Used for: notifications, alerts, document distribution
- Transactional emails only, no marketing lists
💳
Payments
Stripe (US-based, PCI DSS compliant)
- Credit card data never touches ScentShield servers
- All payment processing handled by Stripe
Data Transfer
- EU-US data transfers covered by the EU-US Data Privacy Framework
- Standard Contractual Clauses available on request
GDPR Compliance
- You can export all your data at any time (Settings → Data & Privacy → Export)
- You can delete your account and all data (Settings → Data & Privacy → Delete Account)
- Data Processing Agreement available on request at privacy@scentshield.io
Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & storage | EU (Ireland) |
| Vercel | Application hosting | Global |
| Anthropic | AI processing | US |
| Resend | Email delivery | US |
| Stripe | Payment processing | US |
| Upstash | Cache & job queue | EU |
For questions about data residency or to request a Data Processing Agreement, contact privacy@scentshield.io.