Referral Rock Due Diligence
United States · referralrock.com · 11 vendors
Resilience scores
- Digital Sovereignty: 64
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Cloudflare, Inc. — Technology — United States
- Shopify Inc. — Other — Canada
- The Rocket Science Group LLC (Intuit Mailchimp) — Media & Marketing — United States
- and 8 more
Services catalogue
1 service in catalogue across 1 category; runs on 11 sub-vendors.
- Referral Rock
Insights
Last updated 2026-08-02 · revision 2
11 direct vendors, 225 subvendors
Direct vendors by controlling owner country (sample)
- India: 1
- Singapore: 1
- Canada: 1
Subvendors by controlling owner country (sample)
- Spain: 1
- Australia: 3
- Norway: 4
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Referral Rock exhibits medium to high migration readiness, largely attributable to its foundational use of Microsoft Azure, indicating a cloud-native or cloud-first approach. The tech stack includes modern elements like REST APIs and JavaScript, suggesting an architecture that is likely modular and adaptable. A significant advantage for migration is the absence of specified data residency requirements, offering flexibility in choosing new infrastructure locations. The existing compliance with GDPR & CCPA also means the company has established processes for handling sensitive data, which is crucial for any migration. However, several factors temper the readiness score. There is no explicit mention of advanced cloud-native practices such as containerization or microservices, which would further enhance migration agility. Financial stability data is unavailable, making it difficult to assess the company's capacity to fund a significant migration effort. Critically, while vendor geographic diversity is good, the 'Total Vendors: 0' data point is contradictory to the presence of vendor countries and services; assuming there are vendors, the 'Vendor Lock-in Risk' is unknown, which is a key determinant of migration complexity. High vendor lock-in could significantly impede migration efforts.
Compliance
9 in-scope frameworks identified; showing 3.
VCDPA — Assessment Required
Referral Rock is headquartered in Alexandria, Virginia (950 N Washington, Suite 404, Alexandria, VA 22314). The VCDPA (effective January 1, 2023) applies to businesses that control or process personal data of 100,000+ Virginia consumers annually, or 25,000+ Virginia consumers while deriving over 50% of gross revenue from the sale of personal data. As a SaaS platform serving 1,000+ businesses with their customer bases, Referral Rock likely processes data of Virginia consumers at scale. Risk is Medium because: (1) the company is domiciled in Virginia; (2) likely meets consumer data thresholds; (3) no VCDPA-specific compliance documentation is publicly available; (4) VCDPA enforcement by the Virginia Attorney General carries civil penalties up to $7,500 per violation.
Evidence: https://referralrock.com/privacy/, https://law.lis.virginia.gov/vacode/title59.1/chapter53/
GDPR (source) — Partially Compliant
Referral Rock is a US-based SaaS company (Alexandria, VA) that explicitly acknowledges GDPR applicability and has published a dedicated GDPR compliance page, a Data Processing Agreement (DPA), and privacy rights mechanisms (right to deletion, portability, modification). The company processes personal data of EU/EEA residents through its global customer base and referral programs. Risk is Medium rather than Low because: (1) compliance is self-declared without evidence of independent third-party GDPR audit or DPO appointment; (2) the privacy policy was last updated January 2024, and the security page was last updated March 2021, suggesting potential gaps in keeping pace with evolving GDPR guidance; (3) the company acknowledges international data transfers to the United States without explicitly referencing Standard Contractual Clauses (SCCs) or other GDPR-compliant transfer mechanisms post-Schrems II; (4) no EU representative appointment is publicly documented. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://referralrock.com/gdpr/, https://referralrock.com/privacy/, https://referralrock.com/dpa/, https://referralrock.com/security/
HIPAA (source) — Assessment Required
Referral Rock explicitly markets its platform to healthcare and wellness businesses ('clinics and healthcare' listed as a trusted industry on the homepage; dedicated healthcare industry page at referralrock.com/industries/healthcare/'). If healthcare customers use Referral Rock to manage referral programs that involve Protected Health Information (PHI) — such as patient referrals, patient names, or health-related data — Referral Rock could function as a Business Associate under HIPAA, requiring a Business Associate Agreement (BAA). Risk is Medium because: (1) the platform is actively marketed to healthcare providers; (2) referral programs in healthcare contexts may inherently involve PHI (patient names, contact details linked to health services); (3) no BAA template or HIPAA compliance documentation is publicly referenced on the website; (4) failure to execute BAAs with covered entity customers would constitute a HIPAA violation. The actual risk depends on whether healthcare customers are sharing PHI through the platform.
Evidence: https://referralrock.com/, https://referralrock.com/industries/healthcare/, https://referralrock.com/security/, https://referralrock.com/privacy/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Referral Rock is a bootstrapped, privately held US SaaS company that has operated independently for over 10 years without any outside funding. The founder has publicly emphasized profitability and self-sufficiency since 2015, which typically implies conservative burn and positive cash flow. The company has built a recurring SaaS revenue model with monthly and 6-month+ commitments, serves 1,000+ paying customers across diversified industries (home services, professional services, healthcare, financial services, e-commerce, SaaS, franchises, multi-location brands), and has notable enterprise logos including TripAdvisor, Penguin Random House, Culligan Water, Mitel, ActiveCampaign, Material Bank, Grover, and Flink. However, the resilience score is moderated by significant unknowns: no public financials (revenue, EBIT, equity) are disclosed, making external verification of financial health impossible. As a small bootstrapped company, it has less balance-sheet cushion than better-funded competitors like ReferralCandy, Friendbuy, Impact.com, PartnerStack, and Everflow. The referral/affiliate SaaS category is crowded and increasingly consolidated by larger partner-marketing suites. Key-person dependency on founder Josh Ho and SMB customer concentration (typically higher churn) further limit resilience. The company appears stable and likely profitable, but the lack of transparency and small scale warrant a mid-range score.
Key strengths: Bootstrapped with no outside funding or disclosed debt, 10+ years of continuous operation since 2015, 1,000+ paying customers with diversified industry base, Recurring SaaS revenue model with 6-month+ commitments, Marquee enterprise logos (TripAdvisor, Penguin Random House, Culligan, Mitel), Product breadth across referral, affiliate, and ambassador programs, 50+ integrations reducing single-platform dependency, Founder publicly emphasizes profitability and self-sufficiency
Risk factors: No public financial disclosures (revenue, EBIT, equity all undisclosed), Small bootstrapped scale with limited balance-sheet cushion vs. VC-funded competitors, Crowded competitive category with larger partner-marketing suites encroaching, Key-person dependency on founder Josh Ho, SMB customer concentration typically carries higher churn, External stakeholders cannot independently verify financial health
Workforce by country
- United States: 35
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.