Roll Call holds resident records, incident notes, and house operations. This page describes the controls we have in place today and how we handle your data.
Updated August 18, 2026. Maintained by the Roll Call team as editable project content. It is not a third-party certification or independent audit.
The table below lists subprocessors already identified in our product and trust materials. For the current list in writing, email support.
| Vendor | Purpose | Data involved |
|---|---|---|
| Cloudflare | Application hosting and edge network | Application traffic and related operational metadata |
| Supabase | Database, authentication, and file storage | Account, house operations, and private file objects |
| Resend | Transactional email delivery | Email addresses and message metadata for product emails |
| Calendly | Walkthrough scheduling | Name, email, and scheduling details you submit when booking |
| Optional Google sign-in | Account email if you choose to sign in with Google | |
| Apple | Optional Apple sign-in | Account email if you choose to sign in with Apple |
| Lovable AI gateway | Optional relapse-risk screening prompt, Director opt-in | Operational notes and incident text only when an organization enables the feature |
Roll Call includes an optional relapse-risk screening prompt that a Director can enable for their organization. It is off by default and opt-in.
When enabled, the feature produces a screening prompt for trained staff. It is not medical advice and not a diagnosis. Staff clinical judgment decides any action.
We do not claim HIPAA, BAA coverage, SOC 2, ISO 27001, or other formal certifications on this page. If your organization needs a signed DPA, BAA, or vendor questionnaire, contact us.
Encrypted transport, managed database, managed auth, and private file storage provided by our hosting and backend providers.
Role-based access, row-level security policies, private buckets, audit logging, and least-privilege server functions.
Strong passwords, prompt removal of departing staff, and assigning each user the narrowest role they need to do their job.
To request a data export or deletion for your organization, email support@rollcallhm.com with the subject line "Data export or deletion request." See also our privacy policy.
To report a suspected security issue, request a data export or deletion, or ask for our current subprocessor list, contact the Roll Call team. We aim to acknowledge security reports within two business days.
Roll Call does not currently advertise SOC 2, HIPAA, ISO 27001, or other formal certifications. If your organization needs a signed DPA, BAA, or vendor questionnaire, reach out and we will work through it with you.