ugivv
Legal

Privacy Policy

Effective: August 10, 2026 Last updated: August 10, 2026

The short version

Your organization's records belong to your organization, not to us. We do not sell your data or your donors' data. Card and bank numbers never reach our servers. You can export everything, any time, and take it with you.

1. Overview

ugivv is community management software for nonprofits. Organizations use it to keep records of their people, run groups and events, accept donations, and communicate with their community.

This policy explains what we collect, why, and what you can do about it. It covers ugivv.com and the ugivv application. Where an organization uses ugivv to manage its own community, that organization decides what to collect and how to use it, and we handle that data on its behalf. See Your organization's data.

2. Information we collect

Account information

When you create an account we collect your email address and name. ugivv uses passwordless sign-in, so we send a short-lived code to your email instead of storing a password.

Workspace records

Information your organization enters or imports: people and households, groups and teams, events and signups, care records, funds and campaigns, donation history, and recurring plans. Organizations choose what to record here, including how much detail to keep.

Donor and giving information

When a gift is made, we record the amount, date, fund or campaign, and the giver's identity where they provide it. Guest gifts create a visitor record so the organization can issue a receipt.

Payment information

Card numbers and bank account numbers are collected directly by our payment processor and are tokenized before they reach us. We store a token and limited details such as the last four digits and card brand. We never see or store full card or bank numbers. See Payments.

Usage information

Standard technical data such as IP address, browser type, pages viewed, and timestamps, used to operate the service, diagnose problems, and detect abuse.

3. How we use it

We do not sell personal information, and we do not share it with advertisers.

4. Your organization's data

Your organization owns its records. The people, giving history, groups, and communications in a workspace belong to that organization. We process them on the organization's instructions in order to run the service.

If you are a member, donor, or volunteer of an organization that uses ugivv and you want your information corrected or removed, contact that organization first. They control their own records. We will help them act on your request, and we will act directly where the law requires it.

Organizations can export their full records at any time, in one click.

5. Payments

Donations are processed by PaidYET, our payment partner. Card and bank details are entered into PaidYET's hosted fields and tokenized at the moment of entry. ugivv stores the resulting token, never the number itself. PCI DSS compliance is handled at the processor level.

Because a token is stored rather than a number, saved payment methods can be charged again for recurring gifts without ugivv ever holding the underlying credentials.

PaidYET processes payment data under its own terms and privacy practices, and may collect information directly from givers in order to complete a transaction and meet its own legal obligations.

6. AI features

ugivv includes AI features such as connection scoring, giving insights, drafted messages, self-updating audiences, and forecasts. These operate on your workspace's own data in order to produce results for your workspace.

7. Sharing and disclosure

We share information only in these cases:

8. Data retention

We keep workspace data for as long as the account is active. When an account is closed, we delete its data within 90 days, except where we are required to keep records longer for financial, tax, or legal reasons. Residual copies may persist in encrypted backups for up to 12 months before being overwritten.

9. Security

Data is encrypted in transit. Access to production systems is restricted to the people who need it, and administrative actions are logged. Roles inside a workspace limit what each person can see: managers can serve people without seeing settings, plans, funds, or the team.

No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you promptly and describe what happened and what we are doing about it.

10. Cookies

We use only what the service needs:

We do not use advertising cookies or third-party tracking pixels.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing. To exercise any of these, contact us through ugivv.com. We respond within 30 days.

Organizations can exercise most of these directly in the app: records are editable, and full exports are available at any time.

Every notification email includes a one-click unsubscribe link that works without signing in.

12. Children

ugivv is not directed at children under 13, and we do not knowingly collect their personal information for our own purposes. Organizations may keep records about minors as part of their community, such as children in a household or youth in a program. Those records are controlled by the organization, which is responsible for obtaining any consent its programs require.

13. Changes to this policy

We may update this policy. If a change is material, we will give notice by email or in the app at least 14 days before it takes effect. The "Last updated" date above always reflects the current version.