Home / Insights / Operations and security

Which country will your customer data sit in?

Verified 17 August 2026 · SaaS COMPASS · Updated 6 September 2026

All 4 vendors we checked put a sign-up from the United States in the United States, so on day one the answer to “where does our data sit?” is the same everywhere. What separates them is what happens the first time somebody asks for something else — a European client whose own policy names the EU, a health-care customer who wants a signed agreement, a state agency with its own approved-cloud list. HubSpot lets a paying customer move regions from the admin settings at no charge. Asana will move an existing organization, but only on the tiers that carry data residency. monday.com does not move an account at all once it has begun storing data. For Shopify we could not find a mechanism for the customer to choose a storage location stated on its own pages.

(Semrush and Squarespace are not covered here, because we could not find a mechanism for choosing a storage location stated on their own pages.)

Why does the storage location matter if you are buying from the United States?

One reason is the information-security questionnaire that clients send. A form of 100 to 200 questions will ask things like whether personal data is handled overseas and which countries are involved, and even 1 blank answer gets it sent back, delaying the start of trading by 2 to 4 weeks. As long as you can answer, an answer of “the United States” rarely stops a US deal. What stops it is being unable to answer.

The other is that the pressure on a US buyer almost never comes from a residency statute. The Department of Health and Human Services guidance on cloud computing states that the HIPAA Rules “do not include requirements specific to protection of electronic protected health information (ePHI) processed or stored by a CSP or any other business associate outside of the United States”, and answers the question of whether a covered entity may use a cloud provider that stores ePHI outside the country with “Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA) with the CSP”. What that rule asks for is a signed document, not a place. The requirements that do name a place come from contracts and procurement instead: a European client’s internal policy, a parent company’s standard, or a state government’s cloud authorization program.

SaaS COMPASS model — reading the storage location as a contract question rather than a statutory one is our own editorial view, not a legal opinion or a vendor position. It holds for ordinary commercial SaaS bought in the United States, and it stops holding the moment you sell to a public-sector buyer, where the state or federal authorization list is itself the requirement. The vendor statements each row rests on are in the table below.

Just 3 terms

SOC 2 / SOC 3 — an examination report by an external accounting auditor, and its summary version. What clients ask for is almost always SOC 2 Type 2 (an examination of whether the controls actually operated over a period of half a year to 1 year), released under a non-disclosure agreement. All 4 vendors can produce a Type 2, so product selection does not turn on this item.

Region / data residency — a region is the unit of geography in which data is placed; data residency is the name for the feature that lets the customer specify that geography.

BAA (business associate agreement) — the contract a HIPAA covered entity signs with a vendor that will handle protected health information on its behalf. It is a document, not a location, and a vendor either offers one or does not.

The 4 vendors split into those you can move and those you cannot

Countries and regions where data is storedCan you choose at sign-up?Can you move it afterwards?Signs a HIPAA BAA?Own ISO 27001How to read this row
HubSpotUS East (Virginia) / US West (Oregon) / EU (Germany) / Canada (Montreal) / Australia (Sydney). On AWSNo. “New customers purchasing a subscription service will be assigned a hosting location based on the geo-location of their IP address at sign up.” Accounts that use only the free version are placed in the United States wherever they signed up fromYes, and at no charge. “Existing paid customers have the option to migrate their data to a new data center within your account settings. There is no charge for this”Yes, on Enterprise. Storing health data means turning on the sensitive-data feature, which is an Enterprise-only subscription, and identifying as a covered entity or business associate so that HubSpot “can track the application of the Business Associate Agreement (BAA)”. HubSpot describes using its products in compliance with HIPAA as being in public betaWe could not confirm a certification in its own name (what appears on the vendor’s own pages is the certification of its infrastructure provider)The cheapest route into the EU of the 4. You do not pick the region; you move it afterwards, free, once you are paying
monday.com3 regions: US / EU / APAC (Australia). On AWSOnly within limits. “Storing data in the EU Data Region is available for Enterprise plans, and for Standard and Pro plans created on or after January 23, 2023.” Accounts in North and South America are placed in the US regionNo. “Since data is physically stored in a predetermined location, once an account begins storing data it cannot be moved.” The route the vendor states is to have a partner or account manager create a new account in the region you want, going forwardListed on the Trust Center as available. The plan it requires is not stated thereISO 27001:2022. Also the only 1 of the 4 carrying a US state cloud authorization on its own pages (TX-RAMP)The one product where the door closes at the moment you first save data. The region has to be decided before the account exists
AsanaVirginia, US (default; backups in Ohio) / Frankfurt, Germany (Dublin) / Tokyo, Japan (Osaka) / Sydney, Australia (Melbourne)No. “By default, data will continue to reside in the United States for new workspaces and existing customer data”Yes, on the tiers that carry it. “Customers must contact our Sales team to opt-in for data residency to migrate their organization to their selected data region.” A paid add-on on Enterprise; included as standard on Enterprise+HIPAA is listed on the Trust page, alongside GLBA and the California, Colorado and Virginia state privacy laws. The plan it requires is not stated thereISO 27001:2022An existing organization can be moved, but only by buying up and going through sales. Authentication data stays in the United States either way
ShopifyA Canadian company. Merchants and users in the United States contract with Shopify Inc. in Ottawa, Canada, and the privacy policy states that Shopify “may send your Personal Data outside of your state, province, or country, including to the United States”We could not find this stated on the vendor’s own pagesWe could not find this stated on the vendor’s own pagesWe could not find this stated on the vendor’s own pagesWe could not confirm a certification in its own nameThis is not a product built around specifying where data is stored, and a US merchant’s counterparty is a Canadian entity

Scroll sideways to see every column

Checked on each vendor’s own pages, rechecked 6 September 2026. SOC 2 Type 2 and SOC 3 are available from all 4 vendors. Sources are at the end of this article.

A note on the ISO 27001 column alone. monday.com and Asana hold ISO 27001:2022 in their own name, while HubSpot and Shopify state no certification of their own. What HubSpot’s own pages carry is “HubSpot products are hosted with cloud infrastructure providers with SOC 2 Type 2 and ISO 27001 certifications, among others.”, and that is the certification of AWS, the provider renting them the infrastructure. For these 2 vendors, a company asked to submit an ISO 27001 certificate can only answer “the infrastructure provider’s certification”.

As a basis for taking personal data out of the EU and the UK — the direction a US buyer with European customers actually travels — all 4 vendors have the standard contractual clauses and the UK addendum in place, so this item separates none of them.

What “you can move it afterwards” actually covers

HubSpot’s move is the genuinely cheap one: it happens in the account settings, it costs nothing, and the only condition is that you are a paying customer. That last condition is the catch for anyone starting free, because a free-only account sits in the United States regardless of where it signed up, and the migration option arrives with the first paid subscription.

Asana’s move is real but priced. Data residency is a paid add-on on Enterprise and standard on Enterprise+, and neither Enterprise pricing nor the price of the add-on is published on the vendor’s own pages — sales inquiry only. It also comes with an exclusion set out explicitly in Asana’s own help pages.

Your user profile data, such as email address and passwords will continue to be stored in the US.

What moves to the region you chose is teams, projects, tasks, exports and attachments. What stays in the United States is authentication-related data such as email addresses, passwords, one-time keys, IP addresses and internal identifiers; measurement data on seat counts, usage and revenue; and data passed to external partners for AI features (customers in the EU excepted). For a US buyer moving to Frankfurt for a German client, that is the line to read carefully: business data in the region you chose, account data in the United States — so you cannot write “all of it sits in the EU” on a questionnaire.

monday.com states the position plainly.

Since data is physically stored in a predetermined location, once an account begins storing data it cannot be moved.

The vendor’s stated route is to ask a partner or an account manager to create a new account in the region you want, going forward — which leaves the existing boards to be exported and imported back in. We could not confirm on the vendor’s own pages whether comments, update history, automation settings and connected apps carry over. If there is even a small chance you will need the EU region, telling the sales team before you create your first account is the only low-cost route.

Who should not choose these 4 vendors

SaaS COMPASS model — the 4 exclusions below are our reading of the vendor statements in the table, not vendor guidance. Each one assumes the requirement arrives after you have signed, which is the ordinary case; a company that already knows its region, its BAA and its authorization list on day one can buy the matching tier and none of the 4 exclusions applies.

monday.com — companies where there is even a small chance that the storage location becomes a requirement. A sign-up from the United States is placed in the US region, and once data has been stored the account cannot be moved. It is the only product here where the way back closes at the moment of signing.

Asana — companies that need the move to be cheap or quick. Moving an existing organization means an Enterprise add-on or Enterprise+, neither priced on the vendor’s own pages, plus a conversation with sales. And a company required to keep credentials in one region cannot meet that requirement at all, because authentication data remains in the United States whichever region you pick.

HubSpot — companies asked to submit an ISO 27001 certificate in the vendor’s own name; what appears on the vendor’s own pages is the certification of its infrastructure provider. Companies handling health data need care too: the sensitive-data feature that carries the BAA is Enterprise-only, and HubSpot describes HIPAA compliance support as being in public beta.

Shopify — companies that need to specify where data is stored, or that need a counterparty inside the United States. We could not find a mechanism for the customer to choose stated on the vendor’s own pages, and a US merchant’s contracting entity is Shopify Inc. in Canada.

Which of these applies to you?

Q1: Does a client, a parent company or an industry rule name a specific region?
YesHubSpot moves free of charge once you are paying; Asana moves an existing organization on Enterprise+ or the Enterprise add-on; monday.com does not move an existing account at all. At Asana, authentication data stays in the United States whichever region you choose
NoGo to Q2
Q2: Do you handle protected health information?
YesWhat the rule asks for is a signed BAA, not a US location. HubSpot carries one on Enterprise with the sensitive-data feature enabled; monday.com and Asana list HIPAA on their trust pages without naming a plan. Ask which plan before you buy, not after
NoGo to Q3
Q3: Are you selling to a state or local government agency?
YesCheck that state’s own authorization list before the product shortlist. Of these 4, only monday.com states a US state authorization on its own pages (TX-RAMP), and none of the 4 states FedRAMP
NoGo to Q4
Q4: Has a client asked you to submit a questionnaire or a SOC 2 report?
YesLeave the storage location as it is and answer with SOC 3, the DPA URL and the region shown in the admin settings. All 4 vendors can produce a SOC 2 Type 2
NoDeciding whether to move the storage location can wait until you receive a concrete request

Source: each vendor’s own pages (rechecked 6 September 2026)

If the personal data you handle is only your own staff roster and the business cards of your clients, if you hold no data entrusted to you by another company, and if you have no plans to work on public-sector, financial or health-care accounts, then buying up a tier to move the storage location should not be worth the cost. A DPA (data processing agreement) is built into the terms of service automatically at all 4 vendors, so a minimum contractual relationship is in place without you doing anything. How to produce the documents, and what to put in place before you are asked, are set out in a separate piece, “What do you show a client who asks how you manage information?”.

Buying from Japan? See the Japanese edition for the Act on the Protection of Personal Information, the Tokyo region and what a Japanese client’s questionnaire asks →

Sources (rechecked 6 September 2026)

This article is not legal advice. For obligations under HIPAA, the GLBA, state privacy laws or a state authorization program, and for judgments about the standard required by a contract with a client, please consult a lawyer or another specialist. We could not find the following stated on the vendors’ own pages: whether the storage location can be chosen at Shopify and whether Shopify signs a BAA, how a SOC 2 Type 2 report is obtained from Asana and the pricing of its Enterprise tiers, which plans carry the HIPAA business associate agreement at monday.com and Asana, the scope of data that carries over if a monday.com account is recreated, and ISO 27001 certification in the names of HubSpot and Shopify. Vendor terms, certifications and data center configurations change. Please check the latest information on each vendor’s own pages before signing.

← Back to the comparison

What changed on this page

Every recorded change to this site is in the change log.

HubSpot Free plan available
Visit