Data Residency

Last updated: September 2026

ScentShield takes data residency seriously. This page documents where your data is stored, processed, and transmitted across our infrastructure.

🗄️

Database

Supabase (AWS eu-west-1, Ireland)

  • All formulas, compliance results, customer data, regulatory records
  • Encrypted at rest (AES-256)
  • Daily automated backups with 30-day retention
📁

File Storage

Supabase Storage (AWS eu-west-1, Ireland)

  • Generated documents (SDS, PCN, dossiers)
  • Supplier uploads
  • Encrypted at rest
🌐

Application Hosting

Vercel (AWS, global edge network)

  • Application code and static assets
  • No persistent user data stored on Vercel
🧠

AI Processing

Anthropic API (US-based)

  • Used for: regulatory search, copilot chat, document extraction
  • Data sent: formula compositions, ingredient names, regulatory queries
  • Anthropic does not train on your data (per their data policy)
  • No persistent storage of queries by Anthropic
📧

Email

Resend (US-based)

  • Used for: notifications, alerts, document distribution
  • Transactional emails only, no marketing lists
💳

Payments

Stripe (US-based, PCI DSS compliant)

  • Credit card data never touches ScentShield servers
  • All payment processing handled by Stripe

Data Transfer

  • EU-US data transfers covered by the EU-US Data Privacy Framework
  • Standard Contractual Clauses available on request

GDPR Compliance

  • You can export all your data at any time (Settings → Data & Privacy → Export)
  • You can delete your account and all data (Settings → Data & Privacy → Delete Account)
  • Data Processing Agreement available on request at privacy@scentshield.io

Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase & storageEU (Ireland)
VercelApplication hostingGlobal
AnthropicAI processingUS
ResendEmail deliveryUS
StripePayment processingUS
UpstashCache & job queueEU

For questions about data residency or to request a Data Processing Agreement, contact privacy@scentshield.io.