EU-hosted & your data

Where your data lives, and who can see it

A plain-language account of where MentPass stores your data, which connections are read-only, and the subprocessors involved. No legal gloss — just what is true today.

Where your data lives

MentPass stores application data in Supabase PostgreSQL hosted in the European Union. Client records, session summaries, action items, uploaded files, and imported analytics snapshots are kept inside the MentPass workspace.

The web application is hosted on Vercel and delivered over HTTPS. Connected services such as Google, Meta, Fathom, Stripe, and email delivery process data only when a workspace enables or uses that feature.

What analytics access is read-only

When you connect a client's marketing accounts, MentPass requests read-only reporting access. We can read the numbers below; we cannot change settings, spend, or campaigns.

Google Analytics 4

Read-only

Reporting data only — sessions, users, sources, pages, and conversions. MentPass cannot change GA4 settings or view other Google services.

Google Search Console

Read-only

Search performance only — clicks, impressions, CTR, average position, top queries, and top pages.

Google Ads

Read-only

Reporting only — spend, impressions, clicks, conversions, and campaign performance. No campaign edits.

Meta Ads

Read-only

Reporting only — spend, reach, impressions, clicks, CTR, CPC, and actions. No campaign edits.

Subprocessors

MentPass relies on a small number of third-party services to run. Some are core infrastructure providers; others are optional integrations enabled by the mentor or client.

Supabase

EU-hosted PostgreSQL database and file storage for MentPass application data.

Data involved: Client records, workspace data, OAuth tokens, analytics snapshots, resources, and uploaded files.

Vercel

Application hosting, HTTPS delivery, deployments, and platform logs.

Data involved: Request metadata and operational logs needed to serve and secure the application.

Resend

Transactional email delivery for notifications and account messages.

Data involved: Recipient email addresses, message content, and delivery metadata.

Google APIs

Optional read-only integrations for GA4, Search Console, Google Ads, and Google Calendar.

Data involved: Connected-account reporting data, selected properties, ad account metrics, and calendar event metadata.

Meta Marketing API

Optional read-only Meta Ads reporting integration.

Data involved: Selected ad account identifiers, OAuth tokens, and aggregate advertising performance metrics.

Fathom

Optional meeting recording source connected through the mentor's own Fathom account.

Data involved: Meeting recordings, transcripts, summaries, and action items synced into MentPass.

Stripe

Workspace billing, checkout, subscription, and invoice handling.

Data involved: Billing details, subscription status, checkout events, and payment metadata.