How to read this disclosure

This page identifies the principal third parties that may process customer-account information when providing Roxby. A provider receives only the information needed for the service or integration in use. Optional providers do not receive information unless you choose or enable the related feature.

The public website and waitlist use a separate set of providers listed on the website service-provider page.

Core service providers

Cloudflare, Inc.

Purpose: Deliver and protect the web application and application programming interfaces; execute server requests; route database connections; store uploaded evidence; transport background work; enforce security controls; and send transactional service email.

Information: Network and request data, account and session identifiers, workspace and authorization context, customer records processed through server requests, uploaded evidence, background-work messages, and transactional-email addresses and content.

Processing locations: Cloudflare's global infrastructure. No single-country processing or residency commitment applies unless a separate written agreement says otherwise.

Provider information: Privacy Policy, Data Processing Addendum, and Cloudflare subprocessors.

Databricks, Inc. / Neon

Purpose: Provide the managed Neon PostgreSQL database used for accounts, workspaces, authorization, accounting records, audit history, accepted terms, and service state.

Information: Account identifiers, workspace and permission records, financial and rental records, accounting data, audit and security records, and other structured customer information stored by Roxby.

Processing locations: The configured U.S. cloud region and the locations used by the provider and its disclosed subprocessors. Branches for development, staging, and production do not create separate project-administration boundaries.

Provider information: Neon security, Data Processing Addendum, and subprocessors.

Optional connections and identity providers

Plaid Inc.

When used: You choose to connect a supported bank or card account.

Purpose: Present the connection flow, authenticate the connection with your financial institution, and provide the account and transaction information you authorize.

Information: Connection and device information, financial-institution and account metadata, balances, transaction history, and the permissions and connection tokens needed for the selected service. Plaid handles financial-institution credentials under its own end-user terms and privacy notice; Roxby does not receive your bank password from Plaid.

Provider information: Plaid privacy and legal policies and how Plaid handles financial data.

Apple Inc., Google LLC, and Microsoft Corporation

When used: You choose the applicable provider as a sign-in or account-linking method.

Purpose: Authenticate you and return the identity information and security result needed to link or sign in to your Roxby account.

Information: Provider account identifier, name or email address you authorize the provider to share, authentication result, and related security metadata. We do not receive the password used with the identity provider.

Provider information: Apple Privacy Policy, Google Privacy Policy, and Microsoft Privacy Statement.

Diagnostics and product measurement

Functional Software, Inc. d/b/a Sentry

When used: Diagnostic monitoring is enabled for the application environment.

Purpose: Receive bounded error and performance events so we can diagnose crashes, defects, and reliability problems.

Information: Pseudonymous application and trace identifiers, app and operating-system version, device class, route or operation label, timestamps, error classification, and approved diagnostic facts. Our diagnostic boundary excludes uploaded documents, bank transactions, journal contents, credentials, and unrestricted customer text.

Provider information: Privacy Policy, Data Processing Addendum, and subprocessors.

PostHog, Inc.

When used: Product measurement is enabled for the application environment under the applicable customer choice.

Purpose: Measure a closed set of product interactions and completed outcomes to improve usability and reliability.

Information: Pseudonymous product and installation identifiers, approved event names, app and operating-system version, coarse device properties, timestamps, and approved outcome fields. Our product-measurement boundary excludes uploaded documents, financial records, credentials, unrestricted customer text, session replay, and automatic screen capture.

Provider information: Privacy Policy, Data Processing Addendum, and subprocessors.

Customer support communications

Google LLC

Purpose: Provide the Gmail inboxes used to receive and answer messages sent to our support, privacy, and legal addresses.

Information: Your email address, message, attachments you choose to send, and standard email headers. Do not email passwords, passkey secrets, full bank credentials, or unrequested financial records.

Provider information: Google Privacy Policy and Terms.

Provider changes

We review providers before allowing them to process customer information. We update this page before a new principal provider begins processing customer information when the change affects this disclosure. Each approved version has a new permanent version URL and effective date.

Where a contract or applicable law gives a customer a separate notice or objection right, we follow that requirement. Removing a provider from this current list does not erase the permanent version that applied while the provider was in use.

Contact us

Email questions about providers or data handling to privacy@roxby.app.