# RudderStack

> RudderStack collects events from websites, applications and servers, checks them against a stored tracking plan and delivers them to the company's own data warehouse and to connected destination systems.

- Vendor: RudderStack, Inc., San Francisco
- Canonical URL: https://www.convios.com/en/toolbox/rudderstack
- Language version: https://www.convios.com/de/werkzeugkasten/rudderstack
- Area: Go-to-market & sales · Cluster: customer data platform
- Role: Building block · Origin: Established, AI retrofitted
- As of: 2026-09-04 · Reviewed: 2026-09-04 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: What you buy is a delivery chain. Events go in at one point, get checked against a plan, and come out again in your own warehouse and in the destination systems. Without that chain, customer data can be neither analysed nor activated, and any AI application on customer data stands there without context. Having it puts you ahead of nobody. Twilio Segment and Hightouch take the same route, and the calls have converged far enough that a move stays open in both directions. Two things decide the value, and both stay in house. The first is the tracking plan. Without settling which events with which fields are allowed, the chain carries the same rubbish faster than before and the checking bites on nothing. The second is the warehouse. The vendor deliberately builds on top of it and, by its own account, persists nothing, which eases the exit and at the same time means storage, compute and modelling accrue alongside and appear on no invoice from the vendor. One point belongs before procurement. Section 3.2(f) of the terms forbids passing names or email addresses together with phone numbers or postal addresses to the service, other than the customer's own users, along with financial and health data. The security page in the same web presence advertises HIPAA and a signable agreement covering health data. Both statements stand side by side, checked on 4 September 2026, and for a customer data platform that is no side issue: those field combinations are the usual content.

## Suitability by company size

- Solo: suitable with caveats — Price is not the obstacle. The free plan takes 250,000 events a month, carries 16 connections for your own applications, more than 200 destinations and the route back out of the warehouse with ten connections. What is in the way is the warehouse itself. Without Snowflake, BigQuery or a comparable store and somebody who models tables, the chain delivers data to a place where nobody works with it. Warehouse sync runs every three hours on the free plan, which is enough for analysis.
- Mid-market: suitable — The fit is right here. Growth starts at USD 265 a month for one million events, tiered up to 25 million, with unlimited users, unlimited tracking plans, separate development and production environments and a sync every 30 minutes. There is no per-seat price and no minimum term, with 15 per cent off on annual billing. The work in house is the tracking plan and the question of which destination gets served under which consent state. Skip those two decisions and after six months you have a chain nobody can trace back.
- Enterprise: suitable with caveats — Four points sit in the dearest plan, and that plan has no published price. Sign-in through your own directory service, the access log, operation in a separated network environment and a negotiated master agreement all belong to Enterprise, as do the profiles and the scoring models. Then there is the storage location. The data processing agreement offers the choice between Amazon Web Services in the EU and in the United States, but leaves it to the order form and defaults to the United States where nothing is entered. A subscription taken through the website produces no order form. Anyone who needs the EU settles it in the contract, not in the settings.

## Vendor staying power

Funded: The company sits in San Francisco, is governed by Delaware law under Section 10.6 of the terms, and is venture funded according to the publicly available announcements. For a procurement review one point weighs more than the funding position: the vendor carries documents of different ages side by side. The data processing agreement in its February 2026 version offers Amazon Web Services in the EU and bases transfers on the EU-U.S. Data Privacy Framework. The transfer impact assessment on the same website is dated 12 January 2022, describes processing exclusively in United States availability zones, and does not know the framework, because it did not exist then. Anyone checking this point asks before signing which of the two documents describes their own contract.

- Legal entity and seat: RudderStack, Inc., 631 Howard Street, Floor 5, San Francisco, CA 94105; governed by the law of the State of Delaware, venue a federal court in the Northern District of California or a state court in San Francisco. The site carries no company disclosure page; the sitemap lists five legal pages (source: https://www.rudderstack.com/terms-of-service/, as of 2026-09-04)
- Funding: USD 56m in a round described as Series B, led by Insight Partners with Kleiner Perkins and S28 Capital; published on 2 February 2022 on the vendor's blog, which states total funding raised to that date as USD 82m. No later round has been published (source: https://www.rudderstack.com/blog/enabling-the-customer-data-stack-rudderstack-series-b-funding/, as of 2026-09-04)
- Security audit evidence: SOC 2 Type 2 announced on 5 April 2021; Section 9.1 of the data processing agreement obliges the vendor to make the report available subject to confidentiality. The certification body, the scope and the audit period appear on no publicly reachable page. The vendor claims no ISO/IEC 27001 certification for itself (source: https://www.rudderstack.com/blog/rudderstack-is-now-soc-2-certified-your-trust-is-our-treasure/, as of 2026-09-04)
- Transfer certification: Certification under the Data Privacy Framework announced on 24 November 2025, per the vendor covering the EU-U.S. framework, its UK extension and the Swiss framework; Section 6.1 of the data processing agreement names it as a transfer mechanism (source: https://www.rudderstack.com/blog/rudderstack-data-privacy-framework-certification/, as of 2026-09-04)
- Ongoing development: A post on governance driven by infrastructure-as-code for tracking plans published on 2 February 2026; the data processing agreement carries a February 2026 date (source: https://www.rudderstack.com/blog/new-iac-driven-governance-supports-trustworthy-customer-context/, as of 2026-09-04)
- Operational record: the status page carries separate components for ingestion and processing in the EU and reports 100 per cent and 99.99 per cent availability respectively over 90 days; no incident is reported between 20 August and 3 September 2026 (source: https://status.rudderstack.com/, as of 2026-09-04)

## Cost of leaving

Moderate: The data is already out. The vendor builds on the customer's warehouse and, by its own account, persists nothing, so the events sit in your own store from the start. What is missing after an exit is everything above that: the transformations in JavaScript or Python, the destination settings, the tracking plans with their violation rules, and the profiles and scoring models from the dearest plan. The calls in the SDKs follow the same specification as the older competitor's, which eases the path in both directions. The contract allows time: Section 6.3 of the terms makes customer data available for 30 days after the end, and Section 1.6 keeps the configurations of a paused account for a year. The work on switching day sits in the applications, not in the contract.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | publicly available in full text, in its February 2026 version, and incorporated through the terms without a request and without a plan attached — The agreement sits openly available at a stable address and is expressly part of the agreement under Section 10 of the terms. It names the roles clearly: the customer is controller or processor, the vendor solely processor or sub-processor, processing only on documented instructions under Article 28(3) GDPR. Section 2.2 additionally forbids the vendor to sell personal data, process it for its own marketing or analytics purposes, or determine its own purposes. A different order applies to the operating data of the account, set out in Section 2.4 of the terms. | evidenced | 2026-09-04 |
| Storage location | Amazon Web Services in the EU or in the United States, with the order form making the choice; absent an entry the United States applies — Section 5.3 of the data processing agreement offers both regions and says in the same paragraph that absent an entry on the order form, Amazon Web Services in the United States is the default provider. The EU region exists, then, but does not arrive by itself, and a subscription taken through the website produces no order form. That the region carries in operation is shown by the status page, which lists ingestion and processing in the EU as separate components. The transfer impact assessment on the same website describes processing exclusively in United States availability zones and is dated 12 January 2022. | partially evidenced | 2026-09-04 |
| Subprocessors | public list inside the data processing agreement, two entries with purpose and country, plus 30 days' notice before any change — There is no dedicated sub-processor page; the sitemap carries five legal pages in total. The list sits in Section 5.3 of the data processing agreement and names two entries with purpose and country: Amazon Web Services in the EU and Amazon Web Services in the United States, both as cloud service provider. Section 5.4 promises notice at least 30 days before a new sub-processor, by email to the signatory or via the website, and allows 20 days for a reasoned objection. Where an objection reaches no agreement, the customer may suspend the affected part of the service. | evidenced | 2026-09-04 |
| Third-country transfer | transfer to the United States possible; the agreement names the EU-U.S. Data Privacy Framework as the basis, plus the 2021 standard contractual clauses, modules two and three — Section 6 of the data processing agreement assigns the mechanisms one by one. For the United States the certification under the Data Privacy Framework applies, announced on 24 November 2025; the standard contractual clauses under Implementing Decision 2021/914 are incorporated alongside, with module two for controller to processor, module three for the processor chain, the docking clause enabled and Irish governing law. For the United Kingdom the addendum to the clauses is deemed executed, and for Switzerland the clauses apply with the modifications required there. Anyone storing in the EU settles the question on the order form and needs the mechanism only for peripheral processing. | evidenced | 2026-09-04 |
| Training on customer data | own purposes on customer content contractually excluded; the word training appears in neither agreement, and an extension to model providers is missing — Two places carry the statement. Section 2.2 of the data processing agreement forbids the vendor to sell personal data, process it for its own marketing or analytics purposes, or determine its own purposes. Section 2.4 of the terms draws the line to the second kind of data: product telemetry, meaning the volume and type of events, the destinations configured, the features used, team size, login frequency and session duration, is expressly not customer data, contains no event content, and may not be combined with it. That telemetry is used, per the same section, for product analytics, security, customer retention and sales. A sentence on model training appears in neither document, and since the vendor offers scoring models as a feature, what commitment covers the model providers used there stays open. | partially evidenced | 2026-09-04 |
| Retention and deletion | deletion or return within 30 days of a request, backups at most 90 days, deletion certificate on request — Section 10 of the data processing agreement quantifies both periods: 30 days after the customer's request for deletion or return, and for backups the standard backup cycle, not exceeding 90 days. A deletion certificate is available on request. The terms add two further periods: under Section 6.3 customer data stays available for 30 days after the agreement ends, and under Section 1.6 the configurations of a paused account are kept for a year and may be deleted thereafter. The security page states that the vendor does not store the data. The periods in the contract show that it does hold it in operation, if briefly. | evidenced | 2026-09-04 |
| Certifications | SOC 2 Type 2 per the vendor, report on request under confidentiality; Data Privacy Framework certification since 24 November 2025; HIPAA only on the dearest plan — Three pieces of evidence are named, and each carries a condition. The announcement of the SOC 2 Type 2 audit dates from 5 April 2021; which body audited, which scope is covered and which period underlies it appears on no publicly reachable page, and under Section 9.1 of the agreement the report comes only subject to confidentiality. The vendor announced its Data Privacy Framework certification on 24 November 2025 and relies on it in the agreement. Compliance with the requirements for health data, including a signable agreement, appears on the pricing page under Enterprise alone. The vendor claims no ISO/IEC 27001 certification for itself; the standard appears on its pages only in explanatory articles. Audit rights are set in Section 9.2: once a year, remote only, because the vendor keeps no physical location. | partially evidenced | 2026-09-04 |
| EU AI Act, Article 50 | self-applied label as an agentic and AI-native platform, with no mention of Regulation (EU) 2024/1689 on any page checked — The vendor presents itself on its home page as an agentic customer data platform and offers identity resolution, audience building and scoring models on the dearest plan. Checked on 4 September 2026 were all five legal pages, the security page, the pricing page and around 200 further pages from the learning centre and the blog, including the whole data security section. Regulation (EU) 2024/1689 appears at none of those places, nor does a statement on the transparency duties in Article 50 or a certification to ISO/IEC 42001. In practice that is bearable, because the scoring models compute in your own warehouse and face nobody: the deployer sets the disclosure themselves as soon as they approach customers off the back of a score. A decision written into your own process replaces the missing commitment. | partially evidenced | 2026-09-04 |
| Audit logging | access log only on the dearest plan; the scope is described, the retention period and the export path are not — The documentation states plainly that the log belongs to the Enterprise plan alone, and describes its scope: user, action, target, entity type and timestamp are recorded, across sources, destinations, transformations, team changes, second-factor settings and the workspace. How long the entries are kept and whether they can be exported into your own system does not appear there, and the pricing page does not list the point in its plan comparison at all. Checked were the pricing page with its full comparison, the security page, the documentation on the log and the data processing agreement. Anyone planning for evidentiary duties settles the period and the export before signing. | partially evidenced | 2026-09-04 |

## Cost

- Entry: Free costs nothing and takes 250,000 events a month, with ten members, one production environment, a warehouse sync every three hours, ten connections back out of the warehouse and five transformations. Growth starts at USD 265 a month for one million events and tiers across three, five, seven, ten and 25 million; above that the vendor points to sales. The plan brings unlimited members, unlimited tracking plans, separate development and production environments, a sync every 30 minutes and 25 connections back out of the warehouse; annual billing carries 15 per cent off and 30 days to try it. Enterprise has no published price. (as of 2026-09-04)
- Where it gets expensive: The bill hangs on a single quantity, and it grows with the business. Billing is per event, and an event under Section 5.1(b) of the terms is a single call, measured at the ingestion endpoint, with the vendor's billing systems treated as the authoritative record. Retries after destination-side errors and the vendor's own diagnostic calls are not counted. Collecting page views unfiltered means paying for data nobody analyses, and the tracking plan is exactly what guards against that. The second step is a jump rather than a climb. Directory sign-in, the access log, the separated network environment, a negotiated master agreement, health data and the profiles all sit in Enterprise, and that plan has no price you can read in advance. Then there are the costs outside the invoice: storage and compute in your own warehouse accrue as soon as the chain runs.

## Three routes compared

### Buy Twilio Segment, the market standard

Segment belongs to Twilio and is the established counterpart; the calls track, identify, page, screen, group and alias come from that specification and are rebuilt by the other vendors. In large corporates it usually stays because it runs under an existing master agreement with a counterparty already vetted, and because the developers know the calls anyway. Price is the difference you see before the conversation: the pricing page names no figure for the customer data platform, lists volume and throughput as custom and points to sales, checked on 4 September 2026. For the pipeline alone there are 14 days to try it. Anyone wanting to compare therefore has a conversation first.

### Take Hightouch and buy the decisioning with it

Hightouch starts a layer higher and sells the transport and, alongside it, the decision about who receives which outreach and when; the advertising and lifecycle building blocks with machine decisioning sit in the same tool. The free entry covers two active syncs back out of the warehouse, unlimited destinations and unlimited users. Billing is by usage, and no figure appears on the pricing page, checked on 4 September 2026. What you give up is the same as with the market standard: the chance to read the price before negotiating. On top of that, the logic of who gets approached moves out of your own warehouse into somebody else's tool.

### Build the chain yourself, or run the core yourself

Two routes are open, and the second looks cheaper than it is. The first is a genuine self-build: the ingestion endpoint for events runs on Cloudflare Pages and Workers, identities and interim state sit in Supabase, n8n handles distribution to the destinations, the keys for it live in Infisical, PostHog covers product analytics, and the whole thing is written with Claude Code. Costed at EUR 900 a day and 20 to 30 person-days for a version that serves three to five destinations reliably, a workable first version lands between EUR 18,000 and 27,000, plus ongoing operation; that calculation is an estimate. The second route is running the vendor's own code. The core is available under the Elastic License 2.0 and runs on Kubernetes, but the control plane stays with the vendor: the self-hostable version is deprecated and no longer works with core releases after 1.2. The open version additionally lacks the route back out of the warehouse, data quality controls, the access log, directory sign-in, alerting and multi-node operation. Both routes break at the same place, the destination integrations. Every destination has its own field names, its own rate limits, its own retry behaviour, and changes all of it without warning. The vendor maintains more than 200 of them for all customers at once; in a self-build one person maintains the five you have, and that work never ends. Add the question of who maintains the chain once the person who built it leaves, and who can show that a withdrawn consent arrived at every destination.

Recommendation by size:

- Solo: Start on Free, but only once a warehouse is in place and somebody maintains the tables.
- Mid-market: Take Growth and settle the tracking plan in the same move, before the first destination is connected.
- Enterprise: Before signing, write the EU region into the order form and hold the field restriction in Section 3.2(f) against your own data requirements.

## Context

- Implements method: [GTM Stack Signal Routing](https://www.convios.com/en/methods/gtm-stack-signal-routing) — The method needs one place where the signals converge before a score decides the next step, and that place is exactly what the customer data platform is.
- Implements method: [Lead Scoring: Best Leads to Best Closers](https://www.convios.com/en/methods/lead-scoring-and-routing) — A score is only as good as the fields it computes from, and the enforced tracking plan decides whether those fields arrive complete in the first place.
- Implements method: [Data Monetization: Improve, Wrap, Sell](https://www.convios.com/en/methods/data-monetization-improve-wrap-sell) — The method demands a named proof of value before any data initiative, and this tool belongs solely on the first route, improving your own operation.
- Implements method: [AI-GTM Maturity (4 Levels)](https://www.convios.com/en/methods/ai-gtm-maturity-levels) — Without reliable customer context every level above the first stays out of reach, because the models would otherwise decide on incomplete data.
- Alternative: [PostHog](https://www.convios.com/en/toolbox/posthog)
- Alternative: n8n
- Displaces: Home-grown scripts that rebuild events for each destination separately, Tracking pixels maintained separately in every application, Nightly exports from the database into individual sales tools

## Evidence

- Legal entity, address, governing law and venue, the definition of an event and billing in Section 5.1(b), product telemetry in Section 2.4, the field restriction in Section 3.2(f), customer data available 30 days after the end in Section 6.3, configurations kept for a year in Section 1.6 — https://www.rudderstack.com/terms-of-service/ (as of 2026-09-04)
- February 2026 version, role allocation under Article 28 GDPR, the ban on own purposes in Section 2.2, the sub-processor list with two entries and the United States default in Section 5.3, notice and objection periods in Section 5.4, transfer mechanisms in Section 6, audit rights in Section 9, deletion periods of 30 and 90 days in Section 10 — https://www.rudderstack.com/data-privacy-addendum/ (as of 2026-09-04)
- Plans Free, Growth from USD 265 for one million events and Enterprise on request, volume tiers, sync intervals, the number of connections and transformations, and the assignment of directory sign-in, health data, separated network environment and profiles to Enterprise — https://www.rudderstack.com/pricing/ (as of 2026-09-04)
- The statement that the vendor does not store the data, the naming of directory sign-in, an encrypted tunnel, permissions management and audit logs, and of SOC 2 Type 2 and compliance with the requirements for health data including a signable agreement — https://www.rudderstack.com/security/ (as of 2026-09-04)
- Audit logs on the Enterprise plan alone, recording user, action, target, entity type and timestamp across sources, destinations, transformations, team, second factor and workspace; no statement on retention period or export — https://www.rudderstack.com/docs/dashboard-guides/audit-logs/ (as of 2026-09-04)
- The open version lacks the route back out of the warehouse, data quality controls, event metrics, audit logs, directory sign-in, operation in a separated network environment, alerting, team invitations and multi-node operation; the self-hostable control plane is deprecated and no longer works with core releases after 1.2 — https://www.rudderstack.com/docs/get-started/rudderstack-open-source/hosted-vs-open-source/ (as of 2026-09-04)
- The rudder-server core is released under the Elastic License 2.0 and can be run via Docker and Kubernetes, with the vendor recommending Kubernetes for production — https://github.com/rudderlabs/rudder-server (as of 2026-09-04)
- Funding of USD 56m led by Insight Partners with Kleiner Perkins and S28 Capital, published on 2 February 2022, total raised to that date USD 82m per the same announcement — https://www.rudderstack.com/blog/enabling-the-customer-data-stack-rudderstack-series-b-funding/ (as of 2026-09-04)
- Data Privacy Framework certification announced on 24 November 2025, per the vendor covering the EU-U.S. framework, its UK extension and the Swiss framework — https://www.rudderstack.com/blog/rudderstack-data-privacy-framework-certification/ (as of 2026-09-04)
- SOC 2 Type 2 announced on 5 April 2021 — https://www.rudderstack.com/blog/rudderstack-is-now-soc-2-certified-your-trust-is-our-treasure/ (as of 2026-09-04)
- The transfer impact assessment is dated 12 January 2022 and describes processing exclusively in United States availability zones — https://www.rudderstack.com/data-transfer-impact-assessment/ (as of 2026-09-04)
- Separate components for ingestion and processing in the EU with 100 per cent and 99.99 per cent availability over 90 days, and no incident between 20 August and 3 September 2026 — https://status.rudderstack.com/ (as of 2026-09-04)
- Twilio Segment names no price for the customer data platform, lists volume and throughput as custom and points to sales; for the pipeline there is a 14-day trial — https://www.twilio.com/en-us/pricing/customer-data (as of 2026-09-04)
- Hightouch bills by usage and publishes no figure; the free entry covers two active syncs back out of the warehouse, with unlimited destinations and users — https://hightouch.com/pricing (as of 2026-09-04)
