Privacy Policy

Last updated: June 30, 2026

DatoVero LLC (“DatoVero,” “we,” “us,” or “our”) provides a software platform that helps nonprofit organizations manage volunteers, donors, the people they serve, grants, finances, and related operations (the “Service”). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.

This Policy is written for the United States. The Service is intended for nonprofit organizations and their staff located in the United States and is not directed to individuals outside the United States.

Two roles, one important distinction. DatoVero plays two different roles:

  • For information about account holders (the nonprofit’s staff who sign in, and visitors to datovero.com), DatoVero is the controller — this Policy governs that information.
  • For the information a nonprofit enters into the Service about its own donors, clients/beneficiaries, and volunteers (“Customer Data”), the nonprofit organization is the controller and DatoVero is a processor acting on that organization’s instructions. If you are a donor, client, or volunteer of a nonprofit that uses DatoVero, please direct privacy requests to that organization; our handling of Customer Data is governed by our Data Processing Addendum.

1. Information we collect

a. Information you provide when you create or use an account

  • Identity and contact details: name, email address, organization name, and (if you choose to provide it) phone number, mailing address, and profile photo.
  • Authentication data: a password (stored only as a secure hash by our authentication provider) and, if you enable it, two-factor authentication settings and recovery codes.
  • Billing details: your subscription plan and selected modules. Payment card numbers are collected and stored by our payment processor (Stripe), not by DatoVero. We receive limited billing metadata (e.g., status, last four digits, plan) but never full card numbers.
  • Communications: messages you send us (support requests, contact-form submissions, feedback).

b. Customer Data you enter about the people your organization serves
When you use the Service, you may enter information about your donors, clients/beneficiaries, and volunteers. Depending on the modules you use, this can include names, contact details, donation history, volunteer hours and dates of birth, and sensitive demographic information about clients/beneficiaries (such as age, race/ethnicity, veteran status, disability status, income, and education). You control this information and are responsible for having a lawful basis and any required consents to collect it (see Section 7 and our DPA).

c. Information collected automatically

  • Usage and device data: pages viewed, actions taken, browser/device type, and approximate activity timestamps.
  • IP addresses: we hash visitor IP addresses for privacy when used for analytics, and we log IP address and browser user-agent for security and fraud-prevention purposes (e.g., detecting suspicious sign-ins).
  • Cookies and similar technologies: see our Cookie Policy.

d. Information from connected services
If your organization connects a third-party account (for example, QuickBooks Online), we access only the data needed to provide the feature you enabled (such as accounting transactions and account names), with your authorization, and you may disconnect at any time.

We do not knowingly collect information directly from children. The Service is intended for use by adults (18+) acting on behalf of an organization. See Section 7.

2. How we use information

We use personal information to:

  • Provide, operate, secure, and improve the Service;
  • Authenticate users, maintain sessions, and protect accounts (including 2FA, rate limiting, fraud detection, and security monitoring);
  • Process subscriptions and billing;
  • Provide optional AI-assisted features (see Section 4);
  • Respond to support requests and send service-related communications (e.g., account, security, and billing notices);
  • Send product updates or marketing where permitted — you can opt out of marketing at any time; and
  • Comply with law and enforce our agreements.

We rely on the following legal bases as applicable: performing our contract with you, our legitimate business interests (such as securing and improving the Service), your consent (where required), and compliance with legal obligations.

3. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:

  • Service providers (“subprocessors”). We use trusted vendors to run the Service (hosting, database, payments, email, AI, error tracking, and rate limiting). They may process personal information only to provide services to us and under contractual confidentiality and security obligations. Our current subprocessors are listed in the Subprocessor List.
  • Your organization. Customer Data is accessible to the authorized users of the nonprofit organization that controls it, according to that organization’s own permission settings.
  • Legal and safety. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of DatoVero, our users, or the public.
  • Business transfers. If DatoVero is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

4. AI-assisted features

Certain optional features use artificial intelligence (for example, drafting assistance and summaries). When you use them, relevant information is sent to our AI provider (Anthropic) to generate a response. We design these features to send aggregated or de-identified information where practical and not to send raw sensitive beneficiary records. We do not permit our AI provider to use your information to train its models. AI features are optional and degrade gracefully if disabled.

5. Data retention

We retain account information for as long as your account is active. After your account is terminated or your subscription ends, we retain Customer Data for 60 days to allow for reactivation and export, after which we delete or de-identify it, except where we must retain certain records to comply with law, resolve disputes, or enforce our agreements. Backups are cycled out on a rolling basis. You or your organization may request earlier deletion as described below.

6. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including: per-organization data isolation enforced at the database level (row-level security), encryption in transit (HTTPS/TLS) and at rest, hashed passwords, optional two-factor authentication, least-privilege access controls, rate limiting, append-only security audit logs, and ongoing security monitoring. No method of transmission or storage is 100% secure, but we work to protect your information and to notify affected parties of incidents as required by law.

7. Children’s privacy

The Service is not directed to children, and account holders must be at least 18. We do not knowingly collect personal information directly from children. A nonprofit customer may, through its own programs, enter information about minors (for example, youth volunteers or program participants) as Customer Data. In that case, the customer is solely responsible for providing any legally required notices and obtaining any required parental/guardian consent (including under the Children’s Online Privacy Protection Act, where applicable), and for handling that data lawfully. If you believe a child’s information has been provided to us without proper authorization, contact us and we will work with the relevant organization to address it.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of marketing.

  • Account data (DatoVero as controller): contact us at hudson@datovero.com to exercise these rights. We will verify your request and respond as required by law.
  • Customer Data (your nonprofit as controller): please contact the nonprofit organization that holds your information. We will assist that organization in responding to your request.

California residents (CCPA/CPRA). We have not sold or “shared” (as defined under the CPRA) personal information in the preceding 12 months. California residents may request to know, delete, and correct personal information. We use sensitive personal information only as necessary to provide the Service, a purpose for which the CPRA’s right to limit use of sensitive personal information does not apply; we do not use or disclose it for other purposes. Requests are subject to verification. We will not discriminate against you for exercising these rights. To make a request, email hudson@datovero.com.

9. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice where required.

10. Contact us

DatoVero LLC
536 W 11th St Apt 306, Fayetteville, AR 72701
Privacy: hudson@datovero.com · General: hudson@datovero.com

Questions about this document? Email hudson@datovero.com.