Trust

Security & GDPR

Last updated 21 July 2026

Recharge holds leave data, coverage information, and connections into calendars and chat tools your team relies on. This page summarises how that data is hosted, secured, retained, and processed under UK/EU GDPR.

Hosting region

Primary customer data (leave records, organisation membership, and related Service data) is stored in the European Union on Neon PostgreSQL. Application compute and edge delivery run on Vercel. Some subprocessors process data in the US or other regions; where UK/EU law requires a transfer mechanism, we rely on appropriate safeguards (for example adequacy decisions or Standard Contractual Clauses), as described in our DPA.

Encryption

All traffic to and from Recharge is encrypted in transit with TLS. Data at rest, including integration credentials and leave records, is encrypted in our database. OAuth and webhook credentials are encrypted with an application-level key before storage.

Backup policy

The primary PostgreSQL database is backed up continuously by Neon, with point-in-time recovery available within the provider’s configured history window. Backup copies are encrypted at rest by the provider. We restore from backups only for disaster recovery or to correct confirmed data-loss incidents — not for routine access to deleted records after the retention periods below.

Data retention

We retain account and leave data while your account or organisation workspace is active. After you delete an account, or after an organisation subscription ends and deletion is requested, we delete or anonymise personal data within 30 days, except where UK or EU law requires longer retention (for example billing and tax records). Organisation admins can export workspace data as CSV while the subscription is active. See also our Privacy Policy.

Authentication & access

Sign-in, sessions, and organization membership are handled through Clerk. Every organization’s data is scoped to that organization: members and admins only see their own workspace, and personal accounts are never visible to an organization unless you explicitly join one.

Integration security

  • Google Calendar, Outlook, Slack, Discord, Microsoft Teams, and Notion connect via OAuth — Recharge only requests the scopes needed to sync leave and send notifications.
  • Outbound webhooks are signed with HMAC so receivers can verify events came from Recharge.
  • You choose which integrations connect, at the personal or organization level, and can disconnect them at any time.
  • Integration deliveries are logged with retry, so failures are visible rather than silent.

AI & data minimization

AI suggestions are generated from structured context — allowance, work pattern, public holidays, and coverage signals — not a full mirror of your personal or connected calendars. Suggestions are ranked and filtered using only the fields relevant to leave planning and team coverage.

Infrastructure

Recharge runs on Vercel with Neon PostgreSQL, with monitoring for uptime and performance. Card payments are handled by Clerk and Stripe; we do not store full card numbers.

Subprocessors

We use the following subprocessors to deliver the Service. This list is the live source of truth referenced by our DPA (Schedule 2). Last updated 21 July 2026. Organisation customers receive at least 30 days’ notice of material additions or replacements.

SubprocessorPurposeTypical location
ClerkAuthentication, organisations, session management, and billing identityUSA / EEA (SCCs / adequacy as applicable)
StripePayment processing (via Clerk Billing)USA / EEA
VercelApplication hosting, edge infrastructure, and AI GatewayUSA / EEA
NeonPrimary PostgreSQL datastore for Service dataEuropean Union
ResendTransactional email (invites, approvals, digests, notifications)USA / EEA (SCCs / adequacy as applicable)
OpenAI (via Vercel AI Gateway)Generation of leave suggestions from structured contextUSA (SCCs / adequacy as applicable)
Customer-enabled integrationsCalendar sync and chat notifications Customer authorises (e.g. Google, Microsoft, Slack, Discord, Notion, webhooks)Per integration provider

GDPR roles & Data Processing Agreement

For organisation workspaces, the customer organisation is the data controller for workspace leave data and Recharge is the processor. Our GDPR Article 28 / UK GDPR DPA template is available to download for legal review, with a countersigned copy on request.

View and download the DPA · Download PDF

Reporting a vulnerability

If you believe you’ve found a security issue in Recharge, please report it to support@recharge.app. We ask that you give us a reasonable window to investigate and fix an issue before disclosing it publicly.