This box is the notice we give you at or before we collect personal information on this website or when you create an account (California Civil Code section 1798.100 and 11 C.C.R. section 7012). The rest of this page is the full policy.
We collect: identifiers (name, email, phone, account IDs); commercial information (plan and billing status); internet activity (pages, device, IP); professional information (role, organization); and, if you write to us, the content of that message. If you use the product, your organization may also store financial and contact data in its books. That books data is handled as described in “Two roles” below.
Why: to run this website, answer you, provide the service, bill, secure the systems, and meet the law.
We do not sell personal information. We do not share it for cross-context behavioral advertising unless you turn on marketing cookies. See Sale and sharing.
How long: see the table under How long we keep it. We keep each category only as long as reasonably needed for the purposes listed, plus legal holds.
1. Who we are
Tutelium is US software for treasurers at churches, charities, and similar organizations. It is offered by Tutelium Corp., a Delaware corporation. EIN 42-4484663. Delaware registered office: 8 The Green, Suite B, Dover, Delaware 19901.
This policy covers the marketing website, waitlist and contact forms, customer accounts, and how we act when your organization uses the product.
2. Two roles (this matters)
We are the business
For website visitors, leads, and your user account (name, email, login, billing contact), Tutelium Corp. decides how that information is used. In privacy-law language we are the “business” (and, if GDPR ever applies to that slice, the controller).
Your organization is the business
For data in your books and portals (donors, members, volunteers, claimants, officers, gifts, receipts, Form 990 pack fields), your organization decides. We process only to provide the service. We are a “service provider” / processor. The Data Processing Agreement applies. People in that data should contact your organization first. We help you respond.
3. What we collect
Sources: you; your users; your donors or volunteers when they use a public giving page or portal you enabled; automatic logs; and service providers (for example Stripe for subscription billing, or a bank-connection provider if you connect a bank).
| Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Name, email, phone, account ID, IP address, cookie ID | No sale. Share only if you consent to marketing cookies. |
| Customer records | Organization name, role, billing contact, plan | No |
| Commercial information | Subscription status, invoices we issue to you | No |
| Internet activity | Pages viewed, device and browser, approximate location from IP, in-app actions for security | No sale. Analytics/marketing only with consent. |
| Professional information | Job title or treasurer role you give us | No |
| Financial information (service provider) | Bank transactions, receipts, gift amounts, payee account identifiers in claims, Stripe gift IDs. We do not store full card numbers when Stripe Payment Element is used as designed. | No. Processed for your organization. |
| Sensitive personal information (limited) | Account login credentials (stored hashed/encrypted); bank account numbers in books or claims if you enter them; government IDs only if you put them in a pack (for example an EIN, which identifies an organization). We do not seek Social Security numbers for the product. | No. We do not use sensitive information to infer characteristics about a consumer. |
| Inferences | We do not build marketing profiles of donors. Product matching suggestions stay in your organization environment. | No |
We do not collect biometric identifiers, precise geolocation, or education records as a product feature. Audio or image files appear only if you or a claimant uploads a receipt or similar file.
Form 990 pack prep (as service provider): EIN and organization identifiers you enter; principal officer name and address you enter; mapped money lines from your books; other parts you complete. We do not claim donor-level Schedule B processing.
Custom domain: the hostname you connect, certificate status, and a change log (who changed it, when). Actor IDs in logs can be personal information. We never ask for private keys.
People care SMS and login codes (as service provider): mobile numbers, message body you compose, delivery status, consent records. Login OTP uses the number the person provides in that flow.
Live giving (as service provider): donor name and contact collected at checkout, amount, fund, Stripe object IDs, webhook metadata needed to post the gift. Card primary account numbers stay with Stripe under your Stripe agreement.
4. Why we use it
- Provide, secure, and support the service (contract with your organization).
- Bill subscription fees and prevent fraud (contract and our legitimate business need).
- Answer website and waitlist requests (your request). Service emails to account holders. Optional marketing email only if you ask for it, with unsubscribe.
- Meet the law (tax and bookkeeping retention, legal claims, lawful requests).
- Improve the product using de-identified usage that does not include names, account numbers, or amounts from the books.
We do not use customer books data to train public AI models. See AI.
5. Sale, sharing, and ads
We do not sell personal information for money. We do not sell it as California law defines “sale.”
Sharing for cross-context behavioral advertising. Our cookie banner can allow marketing cookies. Until a live Google Tag Manager container is configured, those third-party ads tags are not loaded. If we later enable them, they run only after you consent. That consent-based ads measurement may be "sharing" under the CCPA. You can say no in cookie settings, or use the Do Not Sell or Share link in the website footer. If your browser sends a Global Privacy Control (GPC) signal, we treat that as an opt-out of sale and sharing: marketing cookies stay off. A generic Do Not Track header is not a recognized opt-out under California law; we honor GPC instead.
We do not use or disclose sensitive personal information for purposes that trigger the “limit the use” right, other than to provide the service you asked for.
We do not have actual knowledge that we sell or share the personal information of consumers under 16.
6. Who we share with
We share with service providers who must use the data only for us, including:
- Supabase (authentication, database, storage) on US country projects
- Application hosting and TLS (including certificates for a custom domain you connect)
- Stripe: (A) Tutelium subscription billing; (B) your organization’s Stripe account for gifts, where you are merchant of record
- OpenAI, for minimized assistant prompts and receipt OCR on files you upload (no training on your data under our business API terms)
- Twilio, for care SMS and login one-time codes when those channels are on
- Microsoft mailbox path for transactional login email, when that path is configured
- Plaid or a similar bank-connection provider, only if you choose to connect a bank
- Analytics or ads vendors, only if you consent and a live tag container is configured
The current list lives in the Data Processing Agreement. We may also disclose information if the law requires it, to protect rights and safety, or in a merger or sale of the company (the buyer must keep protecting it).
If you connect Planning Center or another integration, that provider’s terms apply to data that flows through the connection. We process the copy in Tutelium as your service provider.
7. AI
Solon helps inside your organization. External language models do not get a live connection to your books. For chat we send a minimized summary without names, account numbers, or donor identifiers where we can avoid them. Matching-rule and categorise paths do not send payee names, bank memos, IBANs, or amounts to a language model. If a suggestion cannot be made without those fields, the product does not call the model. Receipt OCR sends only the file you (or a claimant) upload. A person in your organization reviews matching suggestions before a rule is saved or a line is booked. We do not use this AI to make significant decisions about a consumer on our own behalf (hiring, lending, housing, or similar). Details: Responsible AI Use.
8. How long we keep it
| Category | Typical period |
|---|---|
| Website leads and contact messages | Until you ask us to delete, or after a documented idle period if you never become a customer |
| User account | For the life of the account, then deleted or anonymized after offboarding |
| Books, invoices, bank imports, gift rows that support the books, Form 990 pack evidence | Seven years (US organizations should keep at least as long as IRS and state rules require; we do not go shorter than that baseline without a written compliance decision) |
| Officer or contact details not required for the books | Only while needed for the purpose, then delete or anonymize |
| SMS message bodies | Up to 12 months |
| Security and audit logs, custom-domain change logs | 12 to 24 months, unless a legal hold applies |
| Backups | Rolling window. A backup is not a substitute for erasure. |
Soft-delete in the product is not erasure. Frozen board packs may be blocked from deletion on purpose. That is not a completed deletion request.
9. Security and storage
We use encryption in transit and at rest, role-based access, separation of customer environments, and logging. Data for the US product is hosted in the United States. Read more on how we secure your data. No method is perfect. You must also protect logins and who you invite.
10. Your privacy rights
If you are a California resident and the CCPA applies to Tutelium Corp. as a “business,” you may request: to know / access; delete; correct; portability; opt out of sale or sharing; and limit use of sensitive personal information where that right applies. We will not discriminate against you for exercising those rights. You may use an authorized agent as the regulations allow. We will verify you before we fulfill a request.
If the request is about data your church or charity stored in Tutelium, send it to that organization. We assist them as service provider. We cannot treat a donor request as if we were the charity.
Other US state laws (for example Virginia, Colorado, Connecticut, Texas, and others) may give similar rights if we meet their thresholds. We will honor a request in line with the law that actually applies. You may appeal a denial by replying to our decision and asking for a review.
To make a request, use our contact page and write “privacy request.” We may need to confirm your identity. California “Shine the Light” (Civil Code section 1798.83): we do not disclose personal information to third parties for their direct marketing in the way that statute covers.
If European data protection law applies to a particular activity, the people concerned also have GDPR rights (access, correction, deletion, restriction, portability, objection). The Data Processing Agreement explains how we help your organization with those requests for books data.
11. Children
Tutelium is for organizations, not for children under 13. We do not knowingly collect personal information from children under 13 on this website. If you believe we have, contact us and we will delete it. Volunteer or member records about minors in your books are your organization’s responsibility as the business.
12. Cookies
Necessary cookies run the site and remember your cookie choice. Analytics and marketing cookies wait for consent. Details and settings: Cookie Policy.
13. Changes
We may update this policy when the product or the law changes. We will change the date at the top. If a change is material, we will give extra notice (email or in-product) where the law requires it. We review this policy at least once every 12 months.
14. Contact
Privacy questions and CCPA requests: contact page (mark the message as a privacy request).
Tutelium Corp., a Delaware corporation. EIN 42-4484663. Delaware registered office: 8 The Green, Suite B, Dover, Delaware 19901.
You may also complain to a data protection authority that has power over the activity (for California residents, the California Privacy Protection Agency and the California Attorney General).