Draft for legal review. This document is a working draft and has not been reviewed by counsel. Bracketed placeholders (for example [Legal Entity Name], [Contact Email], [Effective Date], [Governing Jurisdiction]) must be completed and the full text approved by your attorney before publication or reliance.

Privacy Policy

Privacy Policy

This Privacy Policy explains how [Legal Entity Name] (“Road,” “we,” “us”) collects, uses, discloses, and safeguards information in connection with the Road donor-management platform (the “Service”).

Last updated: [Effective Date]


1. The parties and their roles#

Road is a multi-tenant Software-as-a-Service platform that nonprofit organizations use to manage their donor relationships. Understanding who plays which role under privacy law is essential to this policy:

  • Road (us) — the platform provider. With respect to donor data that a customer uploads or syncs into the Service, Road acts as a processor (a “service provider” under the CCPA), processing that data only on the customer’s documented instructions.
  • The nonprofit customer — the organization that subscribes to the Service. The customer is the controller (a “business” under the CCPA) of the donor data it manages in Road. The customer decides what data to collect from its donors and why.
  • Donors and other contacts — the individuals whose information the customer stores in the Service. They are the data subjects.
For donor data, this policy describes Road’s practices as a processor. Donors with questions about how their information is used should contact the nonprofit organization that holds their record (the controller). Road’s processor obligations are set out in our Data Processing Addendum.

Separately, Road is the controller of the limited information it collects directly about the customer’s own administrators and end-users (account and usage data described below), because Road determines how that data is used to operate and secure the Service.


2. Information we collect#

Account information

When a user signs up for or is invited to a workspace, we collect name, email address, a hashed password (or federated identity), workspace name, role, and authentication metadata such as session records and IP address at login. We use Better Auth for authentication; passwords are stored only as salted hashes, never in plaintext.

Donor contact records and donor PII (customer content)

The core of the Service is the donor data our customers upload, import, enter, or sync. Depending on what the customer chooses to store, this may include donor and household names, postal and email addresses, phone numbers, donation and pledge history, recurring-giving schedules, communication and activity logs, tags, notes, and other relationship context. This is customer content; Road processes it solely to provide the Service and only on the customer’s instructions. Road does not sell customer content and does not use it for our own marketing.

Integration data

If a customer connects a third-party system (such as Virtuous, QuickBooks Online, or Fundraise Up), we process the data exchanged through that integration and store the credentials or tokens needed to maintain the connection. Integration credentials are encrypted at rest.

Usage and device data

We collect technical information generated as the Service is used: log data, feature and page usage, timestamps, browser and device type, and approximate location derived from IP address. We use this to operate, secure, debug, and improve the Service.

AI prompts and outputs

When a user invokes Road AI Agent or another agent feature, the relevant records and the user’s instruction are sent to the configured AI provider to generate a response or draft. AI actions draft only — they do not send communications or change records without a human approving them.

Support and communications

If you contact us for support, sales, or billing, we collect the information you provide and our correspondence with you.


3. How we use information#

  • To provide, maintain, secure, and support the Service.
  • To authenticate users and enforce tenant isolation between workspaces.
  • To process donor data on the customer’s behalf and to power requested features and integrations.
  • To generate AI drafts and assistant responses at the user’s request.
  • To monitor for abuse, fraud, and security incidents, and to enforce our Terms of Service.
  • To communicate with administrators about the Service, including service notices and, where applicable, billing.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CCPA.


4. Sub-processors and third parties#

We use a limited set of trusted sub-processors to deliver the Service. Each is bound by contractual confidentiality and data-protection obligations and may process data only to provide their service to us. The current sub-processors are:

Sub-processorPurposeData processed
Hosting / managed Postgres providerApplication hosting and the primary Postgres database that stores all workspace data.All account and donor records processed in the platform.
ResendTransactional and outbound email delivery (verification, acknowledgments, notifications).Recipient email addresses, names, and message content.
TwilioOutbound and inbound SMS messaging and delivery status callbacks.Recipient phone numbers and message content.
VirtuousDonor-platform integration — bidirectional sync of contacts, donations, pledges, and recurring schedules.Donor contact records, donation and pledge data (only for workspaces that enable the integration).
QuickBooks Online (Intuit)Accounting integration — one-way push of customers, classes, sales receipts, refund receipts, and invoices.Donor names, donation amounts, and related financial records (only for workspaces that enable the integration).
Fundraise UpDonation-platform integration — ingest of online donations and donor records.Donor contact records and donation data (only for workspaces that enable the integration).
AI / LLM providerPowers Road AI Agent. Configurable per deployment (a local model by default; optionally an OpenAI-compatible hosted provider).Only the data included in a given prompt — e.g. a contact record or message the assistant is asked to act on. Not used to train third-party models when a hosted provider is configured with that setting.
Integration providers (Virtuous, QuickBooks Online, Fundraise Up) receive data only for workspaces that explicitly enable the relevant integration. The AI provider is configurable per deployment; a self-hosted local model can be used so that prompt content never leaves the customer’s infrastructure.

5. Data retention#

We retain customer content for as long as the customer’s workspace is active. Records deleted within the Service are soft-deleted and excluded from normal use, then purged from backups on a rolling schedule. On termination of a customer’s subscription, we delete or return customer content in accordance with our Data Processing Addendum, subject to any retention required by law. Account and usage logs are retained only as long as needed for the purposes described above.


6. Security#

We apply administrative, technical, and organizational measures designed to protect personal information, including:

  • Tenant isolation enforced in the database. Every workspace’s data is segregated using PostgreSQL Row-Level Security, so one customer’s queries cannot reach another customer’s records.
  • Encryption. Data is encrypted in transit (TLS). Integration credentials and access tokens are encrypted at rest. Passwords are stored as salted hashes only.
  • Access controls. Role-based access within workspaces and least-privilege internal access.
  • Auditability. Mutations to records are written to an append-only audit log with actor attribution.
  • Monitoring. Logging and monitoring to detect and respond to suspicious activity.

No method of transmission or storage is perfectly secure. While we work to protect your information, we cannot guarantee absolute security.


7. Your privacy rights#

Depending on where you live, you may have rights to access, correct, export, restrict, or delete personal information, to object to certain processing, and to withdraw consent. These include rights under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

  1. If you are a donor or other data subject whose record is held by a nonprofit using Road, please direct your request to that organization (the controller). When a customer instructs us to assist with such a request, we will support them as their processor.
  2. If you are a customer administrator or end-user and want to exercise rights over the account data Road holds about you directly, contact us at [Contact Email].

Customers can access and export their data at any time through the Service, and can request deletion of a workspace by contacting us. We will not discriminate against you for exercising a privacy right.


8. Cookies and sessions#

Road uses strictly necessary cookies to keep you signed in and to secure your session. We do not use third-party advertising or cross-site tracking cookies in the application. Because authentication relies on these cookies, disabling them will prevent you from logging in.


9. International transfers#

Road and its sub-processors may process data in countries other than where you reside, including the United States. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) for cross-border transfers. Details of the data-protection terms are in our Data Processing Addendum.


10. Children’s data#

The Service is intended for use by nonprofit organizations and is not directed to children. We do not knowingly collect personal information directly from children under 13. Customers are responsible for the donor data they choose to store.


11. Changes to this policy#

We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide notice through the Service or by email to workspace administrators.


12. Contact us#

Questions about this Privacy Policy can be sent to [Legal Entity Name] at [Contact Email], [Mailing Address]. See also our Terms of Service and Data Processing Addendum.