Privacy Policy

Effective April 9, 2026

1. Who We Are

DonorShepherd is a donor stewardship platform for small nonprofit organizations. This policy describes how we collect, use, and protect information when you use our service.

2. Information We Collect

Account information: When you sign up, we collect your name, work email address, and organization name.

Donor data you upload: Any donor contact information, gift records, and notes you enter or import into the Service. This data belongs to you and is processed solely to provide the Service.

Usage data: We use PostHog to count page views and understand how the product is used. On this public website it runs without storing anything on your device unless you tell us otherwise; inside the application it always runs that way. It is never tied to individual donor records — see our Cookie Policy.

Payment information: Billing is handled by Stripe. We do not store credit card numbers. We store your Stripe customer ID to manage your subscription.

3. How We Use Information

  • To provide, operate, and improve the Service
  • To send transactional emails (magic links, action notifications)
  • To process billing and subscription management
  • To respond to support requests
  • To detect and prevent fraudulent or abusive activity

We do not sell your data. We do not use your donor records for advertising or share them with third parties outside of what is necessary to operate the Service.

4. Third-Party Services

We use the following sub-processors to deliver the Service:

  • Neon — database hosting (PostgreSQL)
  • Stytch — authentication (magic links, session management)
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Google Cloud Storage — file uploads (CSV imports, images)
  • Railway — application hosting
  • PostHog — product analytics

Each of these providers has their own privacy policy and data processing agreements.

5. Data Retention

Your data is retained for as long as your account is active. If you cancel your subscription, your data is retained for 30 days and then permanently deleted from our systems. You may request earlier deletion by contacting us.

6. Security

We use industry-standard security practices including encryption in transit (TLS) and at rest. Access to production data is restricted to authorized personnel. We do not store passwords — authentication is handled via one-time magic links.

7. Your Rights

You have the right to access, correct, or delete your data at any time. Most data can be managed directly within the application. To request complete account deletion or a data export, contact us at the email below.

8. Cookies

We keep a small number of cookies to sign you in and remember your preferences, and we use PostHog to count page views. The complete list — every cookie and browser-storage key, what sets it, and how long it lasts — is on our Cookie Policy, which is generated from the configuration the site actually runs on rather than written by hand.

Within the signed-in application, where you work with donor records, analytics runs in a cookieless mode and nothing more: no session recording, no click-text capture, and no donor information is ever sent to an analytics provider.

9. Changes to This Policy

We may update this policy from time to time. We will notify active users by email before material changes take effect. The effective date at the top of this page will always reflect the current version.

10. Contact

Questions or requests about your data? Email us at [email protected].