This Privacy Policy explains how DonorFoundry processes information when nonprofit organizations and their team members visit the site, request a demo, create a workspace, subscribe to an annual plan, or use DonorFoundry services.
1. Information you provide
We process information you submit directly, including your name, work email, phone number, job title, organization name, EIN, nonprofit classification, website, address, mission statement, cause areas, service geography, campaign goals, prospect preferences, target gift ranges, CRM information, notes, demo preferences, and team-member invitation details.
Account passwords are stored only as one-way password hashes. DonorFoundry does not store full payment-card numbers; payment collection and billing management are handled through Stripe.
2. Account, billing, and transaction information
For paid accounts we receive billing and subscription metadata from Stripe, such as Stripe customer and subscription identifiers, subscription status, invoice identifiers, amounts, currency, invoice links, and payment state. We use this information to activate accounts, provide billing history, send payment notices, and manage subscription access.
3. Email and communications information
Transactional emails are sent through Amazon Simple Email Service (Amazon SES). We may receive technical delivery events such as delivery, bounce, complaint, delay, or rendering-failure notifications. We use these events to maintain delivery logs and local suppression records so we do not repeatedly send to addresses that have permanently bounced or generated complaints.
4. Technical and security information
We may process limited technical information such as browser user agent, session identifiers, timestamps, and a cryptographic hash derived from the requesting IP address for rate limiting, security, fraud prevention, and consent records. The application is designed not to store raw IP addresses for these purposes.
5. Prospect and donor-intelligence data
DonorFoundry may make available prospect intelligence derived from public, licensed, partner, organization-provided, and inferred data sources. Customers may also import their own prospect research by CSV or enter records manually. Depending on the connected data sources and geography, prospect information may include professional, organizational, philanthropic, business, foundation, geographic, relationship, and campaign-relevance signals. Provider-supplied facts, customer-supplied notes, and AI-generated analysis are stored separately where practical. Inferred scores or suggestions should be treated as research assistance rather than verified facts.
6. How we use information
We use information to provide and secure the service; create nonprofit workspaces; personalize prospect discovery and research; process subscriptions; send transactional communications; provide customer support; measure product activity; prevent abuse; maintain suppression preferences; improve models and workflows; comply with law; and protect DonorFoundry, customers, and other people.
7. Service providers
We use third-party service providers where needed to operate the platform. Current application integrations include Stripe for payment and subscription services and Amazon Web Services, including Amazon SES and Amazon SNS, for transactional email and delivery-event processing. When AI scoring or outreach drafting is enabled, relevant nonprofit, campaign, and prospect context may be sent to the configured AI service provider, such as OpenAI, for the requested generation. When a donor-intelligence provider is connected, search criteria and nonprofit/campaign context may be sent to that provider and matching records may be returned to the workspace. Hosting, analytics, data, CRM, and other providers may be added as the service develops. Providers process information under their own terms and privacy practices as applicable.
8. Retention
We retain account, organization, consent, billing, security, and communication records for as long as reasonably necessary to operate the service, maintain transaction history, resolve disputes, enforce agreements, and meet legal or contractual obligations. Retention periods can vary by record type. Local email suppression records may be retained to honor non-delivery or complaint signals.
9. Your choices and requests
Authenticated users can download an account-data export from the Privacy & Data area. Users can submit correction requests, and workspace owners can submit organization deletion requests. EIN and organization-identity changes require human review. Additional privacy rights may apply based on your location and applicable law.
10. Security
We use administrative, technical, and application safeguards designed to protect account information, including password hashing, session controls, CSRF protection, rate limiting, signed Stripe webhook verification, signed Amazon SNS message validation, and access controls. No online service can guarantee absolute security.
11. International use and children
DonorFoundry is intended for organizations and professional fundraising users, not children. If information is transferred across borders, it may be processed in jurisdictions with different data-protection laws, subject to applicable legal requirements.
12. Changes to this policy
We may update this policy as DonorFoundry, its data sources, or legal requirements change. The “Last updated” date identifies the current published version. Material changes may also be communicated through the service or by email where appropriate.
13. Contact
For privacy questions or requests, contact hello@donorfoundry.com. Authenticated customers can also use the Privacy & Data area in their account.