Security & data
Built to earn the community's trust
You hold caregivers' details in trust for your community. Here is how Carrier Stash keeps that data isolated, encrypted, and under your control.
Per-tenant data isolation
Every account's records sit behind PostgreSQL Row-Level Security enforced at the database layer, not just in the app. Each library within your organization is isolated from every other organization. One library can never read or write another organization's carriers, caregivers, or loans.
Encrypted in transit and at rest
All traffic to Carrier Stash is served over HTTPS (TLS), so data is encrypted on its way to and from your browser. Your records are stored in managed PostgreSQL encrypted at rest, and automated backups carry the same encryption.
Caregiver details and retention
We store only what a carrier library needs to run: caregiver names and contact details, waiver attestations, fit-check and follow-up notes, and any flags a user has set on a record, with the reason where one was given. That data is used to operate your library and nothing else. We do not sell it or build advertising profiles, and we keep it only while your account is active or you ask us to.
Data processing agreement
If your organization needs a Data Processing Agreement before it stores caregiver data, we make one available on request. Ask through our contact page and we will send the current version along with our subprocessor list.
Read the full privacy policy
The details on what we collect, how we use it, and the rights you have over your data.
Your data, your control
The records you create belong to your organization, not to us. You can take them with you or remove them whenever you need to.
- Export anytime
- Export your inventory and loan history to CSV whenever you want, for a grant report, a board meeting, or your own records.
- Delete on request
- A caregiver record can be deleted when someone asks to be removed, and we delete your organization's data when you close your account, except where we have to keep something by law.
- Role-based access
- Organization admins, library owners, and library users each get the permissions their role needs. Library users can create and edit caregiver records. Only library owners can manage flags, and only owners and admins can import data. If your organization runs in per-library mode, a user sees the caregivers tied to their library and the ones they created.
Subprocessors
We rely on a small set of trusted providers to run the service. Each one processes data only to deliver Carrier Stash to you.
- SupabaseDatabase, authentication, and file storage
- NetlifyWebsite and application hosting
- StripePayment processing for paid plans
- ResendTransactional email, such as account notices
Certifications and audits
Carrier Stash is not SOC 2 audited. We would rather tell you that outright than let silence answer for us. Here is what we do, and what the providers underneath us are audited against.
- What Carrier Stash does
- Per-tenant isolation enforced by PostgreSQL Row-Level Security, encryption in transit and at rest, and a Data Processing Agreement available on request. We hold no certification of our own and do not claim one.
- Supabase, our database and authentication
- SOC 2 Type 2 compliant, ISO 27001 certified, and HIPAA compliant.
- Netlify, our hosting
- Audited annually by independent third parties against SOC 2 Type 2, ISO 27001, ISO 27018, PCI DSS v4.0, and HIPAA.
- Stripe, our payment processor
- Card details go to Stripe directly at checkout. Carrier Stash never sees or stores a card number.
We checked each provider's published trust page on 9 July 2026. Ask us for a Data Processing Agreement and our current subprocessor list before you store caregiver records.
Have a security question? Get in touch
Ask us anything about how your data is handled, request a DPA before you add caregiver records, or report a security concern. We read every message and respond quickly.
Contact us
