Customer Data Terms · Exhibit B
Your records stay
your evidence.
The customer owns its records. Sofrito uses the information the customer chooses to share to deliver, secure, and support the accepted service.
Information covered
Application and signer identity, business context, agreement and payment status, sample and agreed operating records, review notes, delivery records, and outcome follow-ups are covered. Sofrito does not receive card numbers from Checkout.
Providers
- Cloudflare hosts the application and protects public access.
- Supabase hosted Postgres and Storage hold restricted application and customer records.
- Stripe-hosted Checkout handles card details and returns signed payment events.
- Resend carries access and service email when enabled.
Boundaries and choices
- De-identified research use and testimonial contact are required conditions of Founding Access, acknowledged separately in the agreement alongside the required service and data consents.
- De-identified research use covers themes, categories of finding, and aggregate observations only — never raw records, business identity, or figures. Customer records are not used to train a general model.
- Testimonial contact is permission to ask whether you would give a testimonial. It does not permit publication of a name, an identifiable quote, a business identity, or results; identifiable publication needs separate written permission given at the time, and a request may be declined at any time with no effect on service.
- Automated preparation cannot approve a finding, change a financial value, or replace human review.
- Export, correction, or deletion requests go to hello@trysofrito.com. Legal and protective records may be retained when required and will be identified.
- Access is scoped to the verified customer or assigned staff account. Unrelated customer records are not part of that scope.