Trust
Every vendor that processes your data
What each one does, what it sees, where the data lives, and whether it is connected today. Customers are told by email before we add one.
Where your corporation's data actually sits
The database for Canadian corporations is a Supabase Postgres project in the Canadian region, ca-central-1. Object storage for Canadian corporations is a Google Cloud bucket in northamerica-northeast1, Montreal. Application functions run in Montreal.
There is no United States region yet. It is created with our first United States tenant, and we would rather say that than list a region that does not exist.
The two places data leaves your country, stated plainly
Identity records held by our authentication provider are global rather than regional. That covers an email address, a display name and a second factor enrolment, and no corporation records.
Meeting transcription, document extraction and drafting are processed by model providers whose processing region is not confined to your country. Virtual meeting capture is processed in the United States.
Our residency promise is that your corporation's records and financial data are stored in your country. It is not that no byte ever leaves it.
18 vendors, 11 connected today
Vercel
- What it does
- Application hosting and serverless functions for the product, the owner portal and this website.
- What it sees
- Everything that passes through a request: it is the layer the application runs on. Nothing is stored at rest by Vercel.
- Where
- Functions run in Montreal (yul1). Edge caches worldwide hold static assets only. A United States function region is enabled with the first United States tenant.
- Status
- Connected
- Added
Supabase
- What it does
- The managed Postgres database that holds the corporation's record: ledger, roster, documents metadata, decisions, obligations and the audit chain.
- What it sees
- All structured customer data, including owner names, contact details, balances and the audit chain.
- Where
- Canada, ca-central-1, in the project boardbutler-ca. A United States region is not yet provisioned; the second project is created in us-east-1 with the first United States tenant, and until then no United States region exists to name.
- Status
- Connected
- Added
Google Cloud, Firebase Authentication
- What it does
- Sign-in, multi-factor enrolment and session identity for every person who uses the product.
- What it sees
- Email address, display name, the identity provider used, and the second-factor enrolment record. No corporation records.
- Where
- Firebase Authentication identity records are held globally by Google and are not confined to one country. We state that plainly rather than implying otherwise, because the residency promise in the product covers the corporation's records and financial data, not every byte of identity metadata.
- Status
- Connected
- Added
Google Cloud, Firebase Storage
- What it does
- Object storage for documents, generated PDFs, meeting recordings and exports.
- What it sees
- Every uploaded and generated document. Each object is encrypted by Board Butler with the regional key before it reaches the bucket.
- Where
- Canada, northamerica-northeast1 (Montreal), bucket boardbutler-prod. A United States bucket in us-east1 is created with the first United States tenant.
- Status
- Connected
- Added
Google, Gemini
- What it does
- Meeting transcription, speaker labelling and captions.
- What it sees
- Meeting audio and the transcript produced from it. Board Butler sends no ledger data and no owner roster to it.
- Where
- Processing region per Google's data-processing terms. It is not confined to the corporation's country, which is why transcription is a stated exception to the residency promise rather than a silent one.
- Status
- Connected
- Added
Anthropic
- What it does
- Document extraction, drafting and classification. Every output is a draft a human approves; nothing it produces is published on its own.
- What it sees
- The document or transcript passed to it for the task in hand. Under the API terms, inputs are not used to train models.
- Where
- Processing region per Anthropic's terms. It is not confined to the corporation's country, and is a stated exception to the residency promise for the same reason transcription is.
- Status
- Connected
- Added
Stripe
- What it does
- Subscription billing for Board Butler, and owner payments settled into the corporation's own connected account.
- What it sees
- Payer name, email, the amount and the payment method. Card numbers reach Stripe directly and never reach Board Butler.
- Where
- Stripe processes in the United States and in the regions named in its data-processing agreement.
- Status
- Connected
- Added
Plaid
- What it does
- Read-only bank account connections for reconciliation and for the treasury view.
- What it sees
- The corporation's bank account and transaction data. Board Butler never receives online banking credentials.
- Where
- Plaid processes in the United States and in Canada per its data-processing agreement.
- Status
- Connected
- Added
Resend
- What it does
- Transactional and notice email: meeting notices, statements, records-request responses and account mail.
- What it sees
- Recipient email address, the message and any attachment on it.
- Where
- Resend processes in the United States.
- Status
- Connected
- Added
PostGrid
- What it does
- Print and physical mail for owners who receive notices on paper.
- What it sees
- Recipient name, mailing address and the document printed.
- Where
- PostGrid is a Canadian company and prints in Canada for Canadian corporations and in the United States for United States associations.
- Status
- Connected
- Added
Recall.ai
- What it does
- Joining a virtual board meeting to capture audio for the minute drafting flow.
- What it sees
- Meeting audio and the participant list of the meeting it joins.
- Where
- United States, us-west-2. This is confirmed from the account rather than assumed, and it means virtual meeting capture leaves Canada even for a Canadian corporation. A board that does not want that does not enable meeting capture.
- Status
- Connected
- Added
Twilio
- What it does
- SMS reminders and second-factor codes where a person chooses SMS.
- What it sees
- Mobile number and the message text.
- Where
- Twilio processes in the United States and in the regions named in its data-processing agreement.
- Status
- Not connected yet
- Added
PostHog
- What it does
- Product analytics. Board Butler runs its own PostHog instance rather than sending product events to a vendor-run one, and lists it here so the list is complete rather than convenient.
- What it sees
- Pseudonymous product events with a hashed tenant and corporation identifier. No owner names, no balances.
- Where
- The Board Butler instance is not yet provisioned. Its region is recorded here once it is, before any event is sent.
- Status
- Not connected yet
- Added
Sentry
- What it does
- Error reporting from the application.
- What it sees
- Stack traces and request metadata with identifiers scrubbed.
- Where
- Sentry processes in the region of the organisation, which is chosen when the organisation is created.
- Status
- Not connected yet
- Added
HubSpot
- What it does
- Demo requests, marketing email and the contact record behind them. This website only; it holds no corporation records.
- What it sees
- Name, email, phone, corporation name, jurisdiction, unit count and the marketing attribution of the visit.
- Where
- HubSpot processes in the United States and in the European Union per its data-processing agreement.
- Status
- Not connected yet
- Added
Better Stack
- What it does
- The public status page and uptime monitoring.
- What it sees
- Availability of public endpoints. No customer data.
- Where
- Better Stack processes in the European Union and the United States per its terms.
- Status
- Not connected yet
- Added
Intuit QuickBooks
- What it does
- Accounting sync, and only when the corporation connects it.
- What it sees
- Chart of accounts, journal entries and vendor records, in the direction the corporation chooses.
- Where
- Intuit processes in the United States.
- Status
- Not connected yet
- Added
Xero
- What it does
- Accounting sync, and only when the corporation connects it.
- What it sees
- Chart of accounts, journal entries and vendor records, in the direction the corporation chooses.
- Where
- Xero processes in the United States and in the regions named in its terms.
- Status
- Not connected yet
- Added
Customers receive notice of an addition to this list by email at the address on the account.
What we do with it, and what you can take back
The privacy policy says what each of these vendors is used for. The portability page says how to take everything back at any time.