The short version
Your organization's records belong to your organization, not to us. We do not sell your data or your donors' data. Card and bank numbers never reach our servers. You can export everything, any time, and take it with you.
1. Overview
ugivv is community management software for nonprofits. Organizations use it to keep records of their people, run groups and events, accept donations, and communicate with their community.
This policy explains what we collect, why, and what you can do about it. It covers ugivv.com and the ugivv application. Where an organization uses ugivv to manage its own community, that organization decides what to collect and how to use it, and we handle that data on its behalf. See Your organization's data.
2. Information we collect
Account information
When you create an account we collect your email address and name. ugivv uses passwordless sign-in, so we send a short-lived code to your email instead of storing a password.
Workspace records
Information your organization enters or imports: people and households, groups and teams, events and signups, care records, funds and campaigns, donation history, and recurring plans. Organizations choose what to record here, including how much detail to keep.
Donor and giving information
When a gift is made, we record the amount, date, fund or campaign, and the giver's identity where they provide it. Guest gifts create a visitor record so the organization can issue a receipt.
Payment information
Card numbers and bank account numbers are collected directly by our payment processor and are tokenized before they reach us. We store a token and limited details such as the last four digits and card brand. We never see or store full card or bank numbers. See Payments.
Usage information
Standard technical data such as IP address, browser type, pages viewed, and timestamps, used to operate the service, diagnose problems, and detect abuse.
3. How we use it
- To provide the service: authenticate you, load your workspace, process donations, send receipts and notifications.
- To support you: answer questions, investigate issues, and restore data when something goes wrong.
- To keep the service safe: detect fraud, abuse, and unauthorized access.
- To improve the product: understand which features are used and where people get stuck, using aggregated and de-identified information wherever it will do the job.
- To meet legal obligations, including financial and tax recordkeeping.
We do not sell personal information, and we do not share it with advertisers.
4. Your organization's data
Your organization owns its records. The people, giving history, groups, and communications in a workspace belong to that organization. We process them on the organization's instructions in order to run the service.
If you are a member, donor, or volunteer of an organization that uses ugivv and you want your information corrected or removed, contact that organization first. They control their own records. We will help them act on your request, and we will act directly where the law requires it.
Organizations can export their full records at any time, in one click.
5. Payments
Donations are processed by PaidYET, our payment partner. Card and bank details are entered into PaidYET's hosted fields and tokenized at the moment of entry. ugivv stores the resulting token, never the number itself. PCI DSS compliance is handled at the processor level.
Because a token is stored rather than a number, saved payment methods can be charged again for recurring gifts without ugivv ever holding the underlying credentials.
PaidYET processes payment data under its own terms and privacy practices, and may collect information directly from givers in order to complete a transaction and meet its own legal obligations.
6. AI features
ugivv includes AI features such as connection scoring, giving insights, drafted messages, self-updating audiences, and forecasts. These operate on your workspace's own data in order to produce results for your workspace.
- AI features run inside your workspace and respect the same role permissions as the person using them.
- Your data is never used to train outside models.
- Any AI action that changes something requires your confirmation before it takes effect.
7. Sharing and disclosure
We share information only in these cases:
- Service providers. Vendors who run parts of the service on our behalf, such as hosting, email delivery, and payment processing. They may use the information only to perform that work.
- Public pages. Content an organization chooses to publish, such as its public giving page, campaign progress, or open events, is visible to anyone with the link.
- Legal requirements. Where we are required by law, or where disclosure is necessary to protect the rights, safety, or property of ugivv, our users, or the public.
- Business transfers. If ugivv is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
8. Data retention
We keep workspace data for as long as the account is active. When an account is closed, we delete its data within 90 days, except where we are required to keep records longer for financial, tax, or legal reasons. Residual copies may persist in encrypted backups for up to 12 months before being overwritten.
9. Security
Data is encrypted in transit. Access to production systems is restricted to the people who need it, and administrative actions are logged. Roles inside a workspace limit what each person can see: managers can serve people without seeing settings, plans, funds, or the team.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you promptly and describe what happened and what we are doing about it.
10. Cookies
We use only what the service needs:
- Essential. Keeping you signed in and maintaining your session.
- Preference. Remembering choices such as the screen you were last on.
- Analytics. Aggregate usage measurement so we can see which features earn their place.
We do not use advertising cookies or third-party tracking pixels.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing. To exercise any of these, contact us through ugivv.com. We respond within 30 days.
Organizations can exercise most of these directly in the app: records are editable, and full exports are available at any time.
Every notification email includes a one-click unsubscribe link that works without signing in.
12. Children
ugivv is not directed at children under 13, and we do not knowingly collect their personal information for our own purposes. Organizations may keep records about minors as part of their community, such as children in a household or youth in a program. Those records are controlled by the organization, which is responsible for obtaining any consent its programs require.
13. Changes to this policy
We may update this policy. If a change is material, we will give notice by email or in the app at least 14 days before it takes effect. The "Last updated" date above always reflects the current version.