Last updated: June 30, 2026
DatoVero LLC (“DatoVero,” “we,” “us,” or “our”) provides a software platform that helps nonprofit organizations manage volunteers, donors, the people they serve, grants, finances, and related operations (the “Service”). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.
This Policy is written for the United States. The Service is intended for nonprofit organizations and their staff located in the United States and is not directed to individuals outside the United States.
Two roles, one important distinction. DatoVero plays two different roles:
a. Information you provide when you create or use an account
b. Customer Data you enter about the people your organization serves
When you use the Service, you may enter information about your donors, clients/beneficiaries, and volunteers. Depending on the modules you use, this can include names, contact details, donation history, volunteer hours and dates of birth, and sensitive demographic information about clients/beneficiaries (such as age, race/ethnicity, veteran status, disability status, income, and education). You control this information and are responsible for having a lawful basis and any required consents to collect it (see Section 7 and our DPA).
c. Information collected automatically
d. Information from connected services
If your organization connects a third-party account (for example, QuickBooks Online), we access only the data needed to provide the feature you enabled (such as accounting transactions and account names), with your authorization, and you may disconnect at any time.
We do not knowingly collect information directly from children. The Service is intended for use by adults (18+) acting on behalf of an organization. See Section 7.
We use personal information to:
We rely on the following legal bases as applicable: performing our contract with you, our legitimate business interests (such as securing and improving the Service), your consent (where required), and compliance with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
Certain optional features use artificial intelligence (for example, drafting assistance and summaries). When you use them, relevant information is sent to our AI provider (Anthropic) to generate a response. We design these features to send aggregated or de-identified information where practical and not to send raw sensitive beneficiary records. We do not permit our AI provider to use your information to train its models. AI features are optional and degrade gracefully if disabled.
We retain account information for as long as your account is active. After your account is terminated or your subscription ends, we retain Customer Data for 60 days to allow for reactivation and export, after which we delete or de-identify it, except where we must retain certain records to comply with law, resolve disputes, or enforce our agreements. Backups are cycled out on a rolling basis. You or your organization may request earlier deletion as described below.
We use administrative, technical, and physical safeguards designed to protect personal information, including: per-organization data isolation enforced at the database level (row-level security), encryption in transit (HTTPS/TLS) and at rest, hashed passwords, optional two-factor authentication, least-privilege access controls, rate limiting, append-only security audit logs, and ongoing security monitoring. No method of transmission or storage is 100% secure, but we work to protect your information and to notify affected parties of incidents as required by law.
The Service is not directed to children, and account holders must be at least 18. We do not knowingly collect personal information directly from children. A nonprofit customer may, through its own programs, enter information about minors (for example, youth volunteers or program participants) as Customer Data. In that case, the customer is solely responsible for providing any legally required notices and obtaining any required parental/guardian consent (including under the Children’s Online Privacy Protection Act, where applicable), and for handling that data lawfully. If you believe a child’s information has been provided to us without proper authorization, contact us and we will work with the relevant organization to address it.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of marketing.
California residents (CCPA/CPRA). We have not sold or “shared” (as defined under the CPRA) personal information in the preceding 12 months. California residents may request to know, delete, and correct personal information. We use sensitive personal information only as necessary to provide the Service, a purpose for which the CPRA’s right to limit use of sensitive personal information does not apply; we do not use or disclose it for other purposes. Requests are subject to verification. We will not discriminate against you for exercising these rights. To make a request, email hudson@datovero.com.
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice where required.
DatoVero LLC
536 W 11th St Apt 306, Fayetteville, AR 72701
Privacy: hudson@datovero.com · General: hudson@datovero.com
Questions about this document? Email hudson@datovero.com.