How CauseCore protects nonprofit data
This page is maintained by CauseCore to answer common security and privacy questions from the nonprofits and teams we serve.
It describes the platform capabilities and practices we have in place today. It is not an independent certification, audit report, or legal agreement.
Access & authentication
- ✦Every workspace is a separate organization. Users can only see data from organizations they have been invited to.
- ✦Sign-in uses managed, industry-standard authentication with encrypted sessions. Google sign-in is available and password accounts require email verification.
- ✦Role-based access control lets owners, admins, managers and viewers see only the actions their role allows.
- ✦Database-level security rules scope every read and write to the user's organization, so a query from one nonprofit cannot reach another nonprofit's records.
Hosting & encryption
- ✦Data is stored in a managed cloud backend with encryption in transit and at rest.
- ✦The platform handles automated backups, patching, and infrastructure availability.
- ✦Application traffic is served over HTTPS with modern TLS.
Data collection & use
- ✦CauseCore stores the program, participant, volunteer, event, survey and report data you choose to upload or collect.
- ✦We do not sell nonprofit or beneficiary data to third parties.
- ✦AI features process your data only to generate the summaries, reports and insights you request inside the app.
Shared responsibility
Platform security is a shared effort. CauseCore provides the secure infrastructure, access controls and encryption described above. Each nonprofit is responsible for:
- ✦Inviting only the team members who need access, and removing people who leave.
- ✦Collecting only the data needed for delivery and reporting, and obtaining consent where required.
- ✦Keeping passwords and invite links private, and using strong authentication.
Privacy requests & contacts
Retention
Data is kept while your CauseCore workspace is active. You can delete records, surveys and stories at any time. Contact us to request workspace deletion.
Access & correction
Workspace owners and admins can view, edit or export most records directly from the app. For requests we cannot fulfil in-product, email us.
Security contact
To report a vulnerability or ask a security question, email security@causecore.app.
Note: This page reflects CauseCore's current practices and the capabilities of the managed platform it runs on. It does not guarantee compliance with any specific regulation or framework. If you need a Data Processing Agreement, custom security review, or compliance questionnaire completed, contact us at security@causecore.app.