This site is currently invite-only. Enter the access password to continue.
© 2024 Squish. All rights reserved.
How we protect customer data, who we share it with, and how long we keep it. Updated October 5, 2026.
Squish is a multi-service platform. The customer-facing site (squish.co) and the internal CRM (work.squish.co) run on Cloudflare Workers / Pages. Five Node.js backends — squish-backend, squish-crm-backend, squish-provisioning, squish-email, and squish-hosting — run on Railway in the US-East region. Customer records live in Salesforce; transactional state, audit logs, and provisioning metadata live in Google Firestore (US region). Payment data is held by Stripe — Squish is out-of-PCI-scope by design.
Domain registration is brokered through NameSilo. Shared web hosting runs on Plesk nodes hosted on DigitalOcean droplets; Managed Cloud VPS defaults to CyberPanel on its own droplet. Hosted sites are fronted by Bunny's CDN and WAF. Microsoft 365 licensing is brokered through Pax8 (CSP).
Every privileged action lands in one of these append-only Firestore collections:
Security controls aren't only described in this page — load-bearing ones are asserted in code so that the next deploy can't silently weaken them.
Operational data is held for short defensible windows; financial records are kept for the 7 years US tax law expects. Customer-deletion requests are honored within 30 days for non-financial data.
| Data type | Retention window | Backing store |
|---|---|---|
| Operational logs (debug, heartbeats) | 30 days | Firestore TTL on cron_runs |
| Email send log | 90 days | Firestore TTL on email_log |
| Webhook events (Stripe, etc.) | 90 days | Firestore TTL on webhook_events |
| Abandoned carts | 90 days | Firestore TTL on carts (status=draft|abandoned) |
| Failed-charge records | 1 year after last activity | Firestore TTL on failed_charges |
| Security events (auth fail, RBAC deny) | 1 year | Firestore TTL on security_events |
| Impersonation audit (staff-as-customer) | Indefinitely | Firestore impersonation_sessions |
| Domain renewal records (financial) | 7 years | Firestore domain_renewals + Salesforce Order |
| Refunds, billing actions | 7 years | Firestore billing_actions + Salesforce |
| Successful charges, invoices, orders | 7 years | Stripe + Salesforce Order (mirrored) |
| Customer account data (active) | Lifetime of account + 30 days | Salesforce Account / Contact |
| AI assistant transcripts | Indefinitely | Salesforce Chat_Conversation__c + Chat_Message__c |
| Website builder projects (Faber) | Indefinitely | Firestore faberProjects |
| Customer data after deletion request | 30 days, except what we cannot delete on request: billing records (7 years), security and abuse records (1 year), and AI assistant transcripts, staff access records and website builder projects (indefinitely). Billing records include your customer record at Stripe, with saved cards removed | Salesforce + Firestore purge job |
Vendors that process customer data on our behalf. Each operates under their own compliance program — links go to their public trust pages.
| Vendor | Purpose | Region | Compliance |
|---|---|---|---|
| Stripe | Payment processing, card storage (PCI scope) | US | SOC 1, SOC 2, PCI DSS L1 |
| Salesforce | Customer records, orders, support cases | US | SOC 1, SOC 2, ISO 27001, ISO 27018 |
| Google Firebase | Authentication, Firestore database, hosting | US | SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018 |
| Cloudflare | CDN, DDoS protection, WAF, staff access (Zero Trust) | Global edge | SOC 2, ISO 27001, PCI DSS |
| NameSilo | Domain registration + DNS | US/CA | ICANN-accredited registrar |
| Pax8 | Microsoft 365 license provisioning (CSP) | US | SOC 2 |
| Microsoft | Microsoft 365 mailbox + tenant hosting (managed via delegated admin) | US (customer-chosen) | SOC 1, SOC 2, ISO 27001, ISO 27018, HIPAA |
| Resend | Transactional email delivery | US | SOC 2 |
| Railway | Backend container hosting (US-East) | US | SOC 2 |
| DigitalOcean | Plesk shared-hosting droplets | US | SOC 2, SOC 3, ISO 27001, PCI DSS |
| Amazon Web Services | Managed AWS hosting engagements | US | SOC 1, SOC 2, ISO 27001, PCI DSS |
| Bunny.net | CDN + WAF for hosted customer sites, parked domains, and redirects | Global edge | GDPR (DPA available) |
| Anthropic | AI assistant (chat support, prompt routing); AI Visibility answer checks | US | SOC 2 |
| Perplexity | AI Visibility answer checks | US | SOC 2 |
Today: Squish operates a self-attested security program backed by the controls described above. Most of the SOC 2 Type 1 control set (access control, encryption, audit logging, vendor management, change management) is already in place; formal audit is on the roadmap.
SOC 2 Type 1: not yet engaged with an auditor. The control set is largely built; attestation is the next step.
SOC 2 Type 2: begins observation period after Type 1 attestation lands.
For procurement teams: we'll happily complete a security questionnaire (CAIQ-Lite, SIG-Lite, or your own format). Reach out at security@squish.co.
Data Processing Agreement (DPA): our standard DPA, aligned to GDPR Article 28 and including the EU Standard Contractual Clauses, is published at squish.co/dpa and is incorporated into our Terms of Service automatically.