Your data, your choice

Last updated 28 September 2026

A practical privacy information pack for organisations using Because of You. Choose the information you provide, understand where it goes, and know how to remove it.

Share this page with your team or keep a copy for your privacy review. You can also use your browser’s Print option to save a PDF.

Download the information pack (.md) · Privacy policy

1. Choose how much donor information to share

A shared experience needs no donor list. A personalised URL can include a first name, amount and date. Those parameters personalise the page without creating a stored donor record through that workflow. URLs can remain in browser history, forwarded messages and infrastructure logs; avoid email addresses and sensitive information in them.

Check your fundraising platform’s redirect settings before connecting it. Some platforms append additional donor information to the destination URL automatically. Ignoring a field in Because of You does not remove it from that URL. Choose an ID-only CSV when you want to control exactly which fields are shared.

For individual links with CRM matching, upload a CSV containing just your unique supporter or gift reference. Name, email, amount and date are optional. The browser reads the CSV; only the fields you map are sent to us. The original file and ignored columns are not uploaded. Email is excluded from automatic mapping. You can export the references alongside the generated links and match them in your own system.

A stable supporter reference connects records across experiences within your organisation, including Donor Wrapped, without an email or name. Gift references identify donations, not people. To connect older records or attach a reference to an existing email-based identity, the owner reviews the matches in Settings → Supporter matching. We keep existing identities and links and block conflicting matches. Adding a reference does not remove an email already stored; use donor deletion for a complete erasure review.

An ID-only record reduces the information shared with us, but is not necessarily anonymous: your organisation can match it to a person. References and emails are not displayed on donor pages. Name and gift details you choose to provide can appear on the experience. Engagement events can be linked to a stored donor record. Use stable, unique references and do not reuse one across different people.

2. Access and sharing

Staff sign in to access their workspace. Database access rules separate organisations, with owner, editor and viewer roles. Full donor deletion is restricted to the workspace owner and is available on every plan. Server credentials are kept on the server. Service operators have privileged access needed to support and run the application.

Donor experiences are unlisted links, marked no-index. Anyone with a link can open it; they are not password-protected donor accounts. HTTPS protects data in transit. A private source-report bucket prevents public file access; published images and extracted photos use public URLs. Only publish content suitable for that access model.

Replies contain the sender’s message and name and can also be emailed to the organisation’s owner. Ordinary experiences can disable replies; Wrapped recaps include them. A reply is not permission to publish a testimonial. Google Analytics is disabled across the website and app. First-party opens, shares and other donor experience events remain available to the organisation.

3. AI and automated processing

Donor CSV imports and donor-page personalisation do not send those fields to AI as part of those workflows. Website text, source reports, drafting requests, image-generation prompts and in-app AI help messages are different: they can be processed through OpenRouter and the model or OCR provider it routes to. Website reading can use Firecrawl.

For PDF extraction, we upload the source privately and provide the OCR service with a read URL valid for five minutes. Expiry stops further access through that URL; it does not erase a copy the OCR provider has already received or establish that provider’s retention period. Extracted text and photos may remain in the experience after the source is removed. Do not put donor lists or confidential personal records in source reports, prompts or help messages.

Our AI requests require OpenRouter’s provider data-collection restriction. This filters eligible model endpoints; it does not establish zero retention or cover the separate PDF/OCR service. Model routing and provider terms can vary. We do not promise a single AI-processing country or a blanket no-training guarantee across providers. Ask us to confirm the applicable routing and provider terms before supplying restricted material.

4. Providers and hosting

Supabase provides the database, authentication and file storage. The primary project is in Tokyo, Japan (ap-northeast-1). Vercel hosts the application; server processing is in the United States (iad1), with global edge delivery. These project settings were checked on 26 September 2026.

Resend delivers transactional emails, experience emails requested by staff, and reply notifications, processing recipient details and message content in the United States. Stripe handles account subscription payments; we do not store full card numbers.

OpenRouter and its model/OCR providers process the AI inputs described above. Firecrawl reads website content when needed. Cloudflare Turnstile provides anti-bot protection during signup using browser and network signals. Provider processing can involve countries outside Australia, including the United States. A provider’s headquarters is not a guarantee of its processing location.

We measure our public marketing pages, resource hub and published articles using first-party daily counts: page views, broad referral-source categories and selected clicks. These analytics events do not contain full URLs, query values, raw referrers, names, emails or visitor identifiers. They do not use analytics cookies or persistent browser storage, and are not collected on donor experiences or signed-in app pages. Browser Do Not Track and Global Privacy Control signals stop this collection. The counts show activity, not unique visitors or individual journeys; ordinary hosting and security logs are separate.

Google Analytics previously measured the marketing website and signed-in application. It is disabled in this release. This does not erase previously collected data or old analytics cookies; existing provider-held data remains subject to the property’s retention and any separate deletion request.

5. Retention and temporary files

Source PDFs: removal is attempted after processing, including a failed extraction. A daily cleanup at 03:30 UTC discovers abandoned private uploads older than 24 hours and retries failures. With successful runs and no backlog, abandoned sources are usually removed within 24–48 hours. Failures and backlogs can extend this; owners can see pending work and the latest run in Settings → Data & privacy. Historical PDFs uploaded to the public bucket before private storage was introduced require a separate review; this job does not silently remove published assets.

Donor records, supporter identities, pages, replies and related analytics remain while needed to provide the service or until removed. Ordinary experience deletion removes its donors, pages and events, but may leave supporter identities and reply snapshots. Re-uploading a CSV without email does not erase a previously created supporter identity. Use the dedicated donor deletion workflow for a complete review of linked live records.

Cleanup audit records and donor-deletion receipts expire after 90 days through the daily maintenance job. Deletion receipts keep counts and opaque internal record IDs for audit and recovery review, without donor names, emails, CRM references, message text or link slugs.

The public website’s aggregate traffic counters are also removed after 90 days by daily maintenance. There is no individual visitor record to look up in those counters. Operational security logs and earlier Google Analytics data have separate retention settings.

Database backups: seven completed daily backups were visible when checked on 26 September 2026; point-in-time recovery was disabled. Deletion changes live records immediately, not existing backup snapshots. Backup copies age out through the provider’s retention. Database backups do not contain Storage file bytes. Before restoring a database, operators must preserve and reapply later deletions and reconcile the original requests before reopening access. Receipt IDs alone can miss older records that an import replaced.

Provider email, security logs and analytics have their own retention settings. The Resend account was checked on 28 September 2026 and is on Pro. Resend publishes 30-day email/log retention for Pro and seven-day backups; earlier message removal requires its support process. These are provider retention terms, not an independent deletion test. The Vercel account is on Pro and returned no configured drains when checked on 26 September 2026; runtime log retention depends on observability options, which are not fully verified. Contact us for a request-specific assessment. Downloaded exports, forwarded emails and saved browser copies remain with their recipients. Billing and legally required records may need separate retention.

6. How donor deletion works

The workspace owner opens Settings → Data & privacy and searches by an exact supporter reference, email, gift reference, donor record ID or reply ID. The preview follows linked identities across that workspace and shows donor records, supporter identities, individual and Wrapped links, replies, page events and related client-error records. It does not match people by name. Reused identifiers can connect multiple records: review every match before confirming.

Replies created while linked retain private matching keys, so they can be found after their original page is removed. Some older replies were already detached before this feature existed. The owner must review those separately and explicitly select verified matches. Replies on shared links may also need manual identification through the Replies inbox. Personal information typed into campaign stories, images or other free-form content requires a separate content review.

After the owner types the confirmation, matched live records are removed together and affected personal links stop working. The scope is checked again before deletion; changes to the matching records require a fresh preview. Campaign content and other donors are preserved. A receipt records the result. Separate-copy review remains pending until the owner explicitly marks it complete.

To finish a request, review your CRM, downloaded CSVs, saved pages, email inboxes and open browser tabs. Contact us for relevant provider copies, logs and backup retention. The app cannot recall emails or erase someone else’s device. Account deletion and requests involving report content or old public files also need support review.

7. Questions, procurement and privacy requests

Because of You is operated by Kyle Behrend Pty Ltd (ABN 88 699 700 000). Contact hello@because-of-you.com. Donors should contact the organisation that sent their experience; we help that organisation respond. Avoid sending a full donor list with an initial enquiry.

This guide describes the product and verified settings as of the date above. It is not a signed data-processing agreement, security certification or legal advice. If your organisation requires a DPA, specific processing locations, agreed deletion deadlines or additional controls, contact us to review and agree those requirements before supplying restricted information. Provider links help with due diligence; they do not confirm that a separate contract has been executed.