VolunteerFlow
HomeFeaturesHow it worksPricingAboutOrganizations
Start free

Privacy Policy

Effective Date: April 9, 2026 · Last Updated: September 24, 2026 · Version 1.2

The short version: We collect only what we need to run VolunteerFlow. We don't sell your data. You can export or delete your data at any time. VolunteerFlow acts as a data processor on behalf of your organization, which is the data controller.

Contents

1. Introduction2. Information We Collect3. How We Use Your Information4. Multi-Tenant Data Structure5. Internal Employee Access6. Sharing with Third Parties7. Cookies & Tracking8. Data Retention9. Security10. Children's Privacy11. Your Privacy Rights12. GDPR Compliance13. California Rights (CCPA/CPRA)14. Other State Privacy Laws15. Contact Information16. Changes to This Policy17. Additional Notices

1. Introduction

VolunteerFlow is a multi-tenant Software-as-a-Service (SaaS) platform designed to help nonprofits, educational institutions, and other organizations manage volunteer programs, track volunteer hours, schedule events, and coordinate volunteer activities.

This Privacy Policy describes how PowerHouseTech LLC, a New York limited liability company doing business as VolunteerFlow ("VolunteerFlow," "we," "us," "our"), collects, uses, discloses, and otherwise processes personal information through our platform, website, and services (collectively, the "Services"). This Privacy Policy is intended for:

  • Organization representatives (owners, administrators, managers, coordinators, and leaders) who manage volunteer programs
  • Volunteers who participate in volunteer activities coordinated through the platform
  • Internal staff members and employees who use the platform for support, administrative, or operational purposes

As a SaaS platform, VolunteerFlow operates on a multi-tenant architecture. Organizations (nonprofits and other eligible entities) are data controllers responsible for the volunteers in their programs, while VolunteerFlow acts as a data processor. This means that organizations determine what personal information is collected from volunteers, while VolunteerFlow provides the infrastructure and tools to manage that information.

Please read this Privacy Policy carefully. By accessing or using VolunteerFlow, you agree to the practices described in this policy. If you do not agree with our privacy practices, please do not use the Services.

2. Information We Collect

2.1 Volunteer Information

When volunteers register for or use the platform, either directly or through their organization's instance, we may collect:

  • Name (first and last name), email address, phone number, physical location or address
  • Skills and volunteer interests; volunteer hours and activity logs
  • Emergency contact information (name, phone number, relationship)
  • Profile avatar or photograph; custom tags or categories assigned by the organization
  • Volunteer status (active, inactive, suspended, etc.); share tokens for secure portal access
  • Application and onboarding records; training completions and certifications; orientation attendance
  • Reference check information; waiver signatures and consent records; badge or achievement records

2.2 Organization Information

When organizations sign up for VolunteerFlow, we collect:

  • Organization name, email address, phone number, physical address, website URL, Tax ID or EIN
  • Organization logo and branding colors; timezone preference; portal settings and customization preferences
  • Checkr API key (for background check integration); billing and subscription information

2.3 Staff and Administrator Information

For users with staff or administrative roles, we collect: full name, email address, job title and department, user role and permissions level, last login timestamp, login attempt records, user creation date and creator ID.

2.4 Event and Activity Information

Information related to volunteer events includes: event title, description, location, dates/times, contact information, images and media, volunteer applications and registrations, hours logged, attendance records and check-ins.

2.5 Message and Communication Data

When using our messaging features, we collect: full message content and attachments, sender and recipient information, message timestamps, read/unread status.

2.6 Technical and Session Data

We automatically collect: IP address, user agent and browser information, device type and operating system, session timestamps, session duration, pages visited and features used, click and interaction data, referring URL, crash and error logs, performance metrics.

2.7 Billing and Payment Information

For organizations on paid plans, we collect Stripe customer ID, Stripe subscription ID, current subscription plan and tier, billing cycle dates, and invoice records. We do not directly collect credit card numbers, expiration dates, or CVV codes — these are handled exclusively by Stripe.

2.8 File Upload Information

When files are uploaded, we collect: file name, file type and MIME type, file size, uploading user, upload timestamp, and storage path.

2.9 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. See Section 7 and our Cookie Policy for detailed information.

3. How We Use Your Information

3.1 Providing and Improving Services

We use personal information to create and manage user accounts, provide core platform functionality, customize your experience, send transactional emails, diagnose technical issues, and develop and improve our Services.

3.2 Communication and Support

We use your information to respond to inquiries and support requests, send customer support updates, provide onboarding assistance, send administrative announcements, and facilitate communication between volunteers and organization coordinators.

3.3 Security and Fraud Prevention

We use personal information to monitor for unauthorized access, prevent fraud and abuse, enforce our Terms of Service, protect the safety of VolunteerFlow and our users, and comply with law enforcement requests and legal obligations.

3.4 Background Checks and Volunteer Screening

When an organization integrates VolunteerFlow with Checkr, we use volunteer personal information (name, email, phone, address) to facilitate background check candidate creation. Organizations are responsible for obtaining proper consent from volunteers before initiating background checks.

3.5 Analytics and Business Intelligence

We use aggregated and anonymized usage data to analyze trends, measure platform performance, identify popular features, and prepare internal business reports.

3.6 Billing and Account Management

We use billing information to process subscription payments and renewals, track subscription status, generate invoices and billing statements, monitor payment failures, and enforce billing terms.

3.7 Legal and Compliance

We use personal information to comply with applicable laws and regulations, respond to government and law enforcement requests, establish or defend legal claims, and comply with data protection regulations (GDPR, CCPA, etc.).

4. Multi-Tenant Data Structure and Data Roles

4.1 Data Controller vs. Data Processor

VolunteerFlow operates as a multi-tenant platform where each organization has its own isolated instance. Under data protection laws (including GDPR and CCPA): Organizations using VolunteerFlow are data controllers — they determine the purposes and means by which volunteer personal information is collected and processed. VolunteerFlow is a data processor — we process personal information on behalf of organizations, according to their instructions, and only for purposes necessary to provide the Services.

4.2 Data Isolation and Segregation

Each organization's data is logically isolated within our multi-tenant architecture. Organization administrators can only access their own organization's volunteer data. Volunteers can only view and manage their profile within their associated organization.

4.3 Volunteer Data Ownership

Volunteers' personal information is managed by the organization that recruited them. The organization determines what information is collected, how it is used, who has access, how long it is retained, and whether information is shared with background check providers. Volunteers should review the privacy policy of their specific organization.

4.4 Data Processing Agreements

Organizations that fall under GDPR, CCPA, or other data protection regulations enter into Data Processing Agreements (DPAs) with VolunteerFlow. See our Data Processing Agreement for full details.

5. Internal Employee Access and Support Operations

Important Disclosure: Authorized VolunteerFlow staff may access your organization's data for support, troubleshooting, onboarding, and compliance purposes. All access is logged, and organizations may request audit logs of staff access to their data.

5.1 Authorized Access by VolunteerFlow Staff

To provide customer support, troubleshoot technical issues, onboard new organizations, and maintain the platform, authorized VolunteerFlow employees may access organization data. Staff roles include: Owner, Super Admin, Admin, Manager, Senior Support, Support Agent, Onboarding Specialist, Billing Specialist, and Read Only. Access is limited to what is necessary for each employee's job responsibilities.

5.2 Support and Troubleshooting Access

When an organization contacts support, our team may need to view organization settings and configuration, review volunteer data to diagnose issues, check logs and system records, and test functionality to replicate and resolve issues. Support staff do not access personal information for any other purpose.

5.3 Support Impersonation Mode

VolunteerFlow provides a "support impersonation mode" that allows authorized support staff to view the platform as if they were an organization administrator, for legitimate support and troubleshooting purposes. This feature is strictly limited to authorized personnel. Each support session is logged, and organization administrators can review support access to their account.

5.4 Comprehensive Audit Logging

All access to organization data by VolunteerFlow staff is logged in our audit system. Every staff action generates a record containing: staff member ID and name, organization ID, action category and type, resource type and ID, field-level changes (before and after values), reason for access, IP address, session ID, and precise timestamp. Organizations can request audit logs of staff access to their data.

5.5 Data Security During Support Access

All access occurs over encrypted HTTPS connections. Sessions are authenticated and session activities are logged. Sensitive data (passwords, payment information) is masked and not displayed. Support access is rate-limited to prevent abuse.

5.6 Limitations on Internal Access

VolunteerFlow staff do not access personal information for marketing purposes, do not share personal information with unauthorized parties, do not use personal information for research unless anonymized, and are subject to disciplinary action for unauthorized access. See our Employee Access & Audit Policy for full details.

6. Sharing with Third Parties

VolunteerFlow shares personal information with third-party service providers to operate the platform. We only share the minimum information necessary and require third parties to protect that information.

6.1 Hosting and Storage — Supabase, Railway, Vercel

All data collected through VolunteerFlow is stored in Supabase (database and file storage, United States region). Our backend application runs on Railway and our website on Vercel, both in the United States. Data is encrypted in transit and at rest.

6.2 Payments — Stripe and Square

We use Stripe to bill organizations for VolunteerFlow subscriptions. Data shared: organization name, billing contact email, billing address, invoice amounts, and subscription details. Where an organization takes donations, store orders, or kiosk payments, those payments are processed by Square on the organization's behalf. Data shared: payer name, email, amount, and order details. Card numbers are entered directly with the payment processor and never reach VolunteerFlow.

6.3 Email — Resend

We use Resend to deliver account, notification, and announcement emails. Data shared: recipient name and email address, and message content.

6.4 SMS — Telnyx

If an organization enables SMS messaging features, we send messages through Telnyx. Data shared: volunteer phone numbers, message content, and message timestamps. Organizations are responsible for obtaining volunteer consent before sending SMS messages.

6.5 Push Notifications — Google Firebase Cloud Messaging

Our mobile apps receive push notifications through Firebase Cloud Messaging. Data shared: a device push token and the notification content.

6.6 Background Checks — Checkr and Sterling

When an organization connects Checkr or Sterling, we facilitate background check submissions to the provider the organization selects. Data shared: volunteer name, email address, phone number, and physical address. Organizations must obtain explicit written consent from volunteers before submitting background checks.

6.7 AI Features — Anthropic and OpenAI

AI features included in the Impact plan (such as message and report drafting and scheduling suggestions), and photo-based animal record import, send the relevant text or image to Anthropic or OpenAI to generate a result. Under these providers' commercial API terms, this data is not used to train their models. If an organization connects its own AI provider account, data sent to that provider is governed by the organization's agreement with it.

6.8 No Selling of Personal Information

VolunteerFlow does not sell, rent, or trade personal information for money or other valuable consideration. We do not share personal information with data brokers or marketing networks.

6.9 Legal Requirements and Law Enforcement

We may disclose personal information without further notice if required by law or legal process, necessary to enforce our Terms of Service, or necessary to protect the safety, rights, or property of VolunteerFlow, our users, or the public.

6.10 Business Transfers

If VolunteerFlow is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice of such change and any choices you may have.

7. Cookies and Tracking Technologies

For full details on cookies and tracking technologies we use, please see our dedicated Cookie and Tracking Policy.

7.1 Authentication Cookies

We use JWT authentication cookies (HTTP-only, Secure) to maintain your login session. These cookies are essential for the platform to function and expire 7 days from login.

7.2 Performance Measurement

We use Vercel Web Analytics and Speed Insights to measure page views and website performance. They do not set cookies and do not identify individual visitors.

7.3 Session Recording

We do not record user sessions. No session replay or screen recording tool is enabled.

7.4 Managing Cookies

You can control cookies through your browser settings. Authentication cookies cannot be disabled without preventing login.

7.5 Do Not Track

We do not currently respond to Do Not Track (DNT) signals, but you can use cookie controls in your browser to limit tracking.

8. Data Retention

8.1 Default Data Retention

By default, VolunteerFlow retains personal information for as long as your account is active or as long as needed to provide the Services.

8.2 Organization-Configurable Retention

Organizations can delete volunteer records, hours, events, and other data at any time, and can close their account. VolunteerFlow does not currently offer automatic deletion schedules.

8.3 Specific Retention Periods

  • Volunteer profiles: Retained while active; deleted upon removal or account closure
  • Hours and activity logs: Retained while the account is active, unless the organization deletes them
  • Staff audit logs: Minimum 1 year for security and compliance
  • Sign-in session records and IP addresses: Deleted 35 days after they are created
  • Backup data: Up to 30 days
  • Billing records and invoices: Minimum 7 years for tax and accounting
  • Authentication cookies: 7 days, or 30 days if you choose to stay signed in

8.4 Deletion of Account Data

When an organization closes its account, its data can be exported for 30 days, is deleted from active systems within the following 60 days, and expires from backups within 30 days after that. Billing records may be retained longer for legal purposes.

8.5 Right to Request Deletion

Volunteers and organization representatives can request deletion of personal information. Deletion is subject to legal retention requirements, ongoing legal disputes, and the organization's data retention policies.

9. Security

9.1 Security Measures

  • Encryption: HTTPS (TLS/SSL) for all data in transit; passwords hashed with bcrypt; all data encrypted at rest by our hosting provider, with health and medical records, government identification references, and locked case notes additionally encrypted by VolunteerFlow
  • Authentication: HTTP-only Secure cookies; role-based access control (RBAC); multi-factor authentication available to every staff account; IP allowlisting on the Impact plan
  • Session Security: Sessions are unique per login and expire after 7 days, or 30 days if you choose to stay signed in; sign-ins are logged
  • Rate Limiting: Login attempts rate-limited; API endpoints rate-limited; brute force protection
  • Audit Logging: sign-ins, administrative changes, and every VolunteerFlow support session are logged with the user, the action, and the time

The complete list of the security measures we commit to is Annex A of our Data Processing Agreement. A plain-language summary is at volunteerflow.us/security.

9.2 Security Limitations

While we implement strong security measures, no system is completely secure. We cannot guarantee absolute protection against sophisticated cyberattacks, insider threats, or compromised credentials.

9.3 Data Breach Notification

If we become aware of a security breach affecting personal information, we will notify affected users and organizations without unreasonable delay, provide information about the breach and recommended actions, and comply with notification requirements under applicable laws (GDPR, CCPA, state laws). Organizations are notified no later than 72 hours after we discover a breach affecting their data, as set out in the Data Processing Agreement.

10. Children's Privacy

10.1 No Intentional Collection from Children

VolunteerFlow is not designed for children under the age of 13 and we do not intentionally collect personal information from children.

10.2 No Age Verification

Important: VolunteerFlow does not currently implement age verification mechanisms. Organizations are responsible for obtaining appropriate parental or guardian consent before collecting information from volunteers under 13 years old.

10.3 Teens and Young Adults

Volunteers aged 13–17 may use VolunteerFlow if their parent or guardian has consented to their participation and the organization complies with applicable laws protecting minors.

10.4 If We Learn a Minor's Information Was Collected

If VolunteerFlow becomes aware that a minor under 13 has created an account without proper parental consent, we will notify the parent or guardian, provide ability to access and review the minor's information, and delete the account and personal information upon request.

11. Your Privacy Rights

11.1 General Rights

  • Right to Access: Request a copy of the personal information we hold about you
  • Right to Correction: Correct or update inaccurate or incomplete information
  • Right to Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Right to Data Portability: Receive your personal information in a portable, machine-readable format
  • Right to Object: Object to processing for marketing purposes or automated decision-making
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

11.2 How to Exercise Your Rights

To exercise any of these rights, contact us at legal@volunteerflow.us. Include your name, organization, and specific request. We will respond within 30 days or as required by law.

11.3 Right to Lodge a Complaint

If you believe your privacy rights have been violated, you have the right to lodge a complaint with your supervisory authority or data protection regulator (EU: your national data protection authority; California: California Attorney General).

12. GDPR Compliance (European Union)

12.1 Legal Basis for Processing

VolunteerFlow processes personal information based on the following legal bases under GDPR: contract performance (to provide Services), legal obligation (required by law), legitimate interests (fraud prevention, security), and consent where required.

12.2 Data Processing Agreements

Every organization's use of VolunteerFlow is covered by our Data Processing Agreement (DPA), which forms part of the Terms of Service and applies automatically. It includes our security measures, sub-processor disclosures, data subject rights mechanisms, and audit rights. See our Data Processing Agreement or contact legal@volunteerflow.us.

12.3 Data Subject Rights Under GDPR

EU residents have the right to access, rectify, erase, restrict processing, data portability, and object to processing. To exercise these rights, contact your organization administrator or VolunteerFlow support.

12.4 International Data Transfers

VolunteerFlow is headquartered in the United States. For EU personal information transferred outside the EU, transfers are authorized under Standard Contractual Clauses (SCCs) approved by the European Commission.

12.5 Special Categories of Data

Where an organization enables the relevant features, VolunteerFlow stores special or sensitive categories of personal data on the organization's behalf: health and medical records, race and ethnicity, gender, household income, military and veteran status, criminal history disclosures, and government identification references. The organization decides whether to collect this information and is responsible for having a lawful basis and any required consent. Health records and government identification references are stored encrypted and are visible only to users the organization grants access. VolunteerFlow does not collect biometric data.

13. California Privacy Rights (CCPA/CPRA)

13.1 Categories of Personal Information Collected

In the past 12 months, VolunteerFlow has collected: identifiers (name, email, phone, IP), personal information (address, emergency contacts), commercial information (billing, subscription), internet activity (pages visited, sessions), geolocation data, professional information (role, hours), education information (training records), and inferences (volunteer history, preferences).

13.2 California Consumer Rights

  • Right to Know: What personal information we collect, sources, and how we use it
  • Right to Delete: Request deletion of personal information we have collected
  • Right to Correct: Correct inaccurate personal information
  • Right to Opt-Out: Opt out of sale or sharing of personal information (we do not sell or share personal information)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

13.3 Do Not Sell or Share My Personal Information

VolunteerFlow does not sell or share personal information for cross-context behavioral advertising or in exchange for money. To submit a request, contact legal@volunteerflow.us. We will respond within 45 calendar days.

14. Other State Privacy Laws

Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Delaware, Oregon, Texas, Utah, and Virginia, may have rights similar to California residents. The New York SHIELD Act also governs how we safeguard personal information and notify about breaches. If you are a resident of a state with a privacy law, you generally have the right to know what personal information is collected, to access, delete, and correct it, and to opt out of sales or targeted advertising.

To exercise rights under state privacy laws, contact legal@volunteerflow.us. We will respond within timeframes specified by your state's law, typically 30–45 days.

15. Contact Information

15.1 Privacy Questions and Requests

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact:
Email: legal@volunteerflow.us

15.2 Support and Troubleshooting

For technical support or account-related issues, visit our support portal or contact your organization administrator.

15.3 Report a Data Breach

If you believe your personal information has been compromised or accessed without authorization, contact legal@volunteerflow.us immediately.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last Updated" date, notify users by email or through the platform dashboard, and provide a notice period (typically 30 days) before changes take effect. By continuing to use VolunteerFlow after changes become effective, you accept the updated Privacy Policy.

Previous versions of this Privacy Policy are available upon request at legal@volunteerflow.us.

17. Additional Notices

17.1 Third-Party Links

VolunteerFlow may contain links to third-party websites or services. This Privacy Policy applies only to VolunteerFlow. We are not responsible for the privacy practices of third-party providers.

17.2 Data Ownership

Organizations that use VolunteerFlow own the personal information they provide to the platform. VolunteerFlow does not claim ownership of this data and acts as a data processor on behalf of organizations.

17.3 Organizational Responsibility

Organizations using VolunteerFlow remain responsible for collecting personal information lawfully, providing their own privacy notices to volunteers, complying with data protection laws, responding to volunteer data requests, and ensuring appropriate consent for background checks.

17.4 Governing Law

This Privacy Policy is governed by the laws of the State of New York, United States, without regard to conflict of law provisions. Privacy rights under GDPR, CCPA, and other state privacy laws will be applied according to their respective jurisdictions.

17.5 Entire Agreement

This Privacy Policy, together with our Terms of Service and any Data Processing Agreement, constitutes the entire agreement regarding privacy and data protection. If any provision is found to be unenforceable, the remaining provisions will continue in effect.

VolunteerFlow

The volunteer management platform built for organizations that want to make a bigger impact.

Disabled Military Veteran-Owned Business
Product
How it worksFeaturesPricing
Company
AboutCareersContact
Legal
Privacy PolicyTerms of ServiceAcceptable UseCookie PolicyBilling & RefundsData ProcessingSecurity

© 2026 VolunteerFlow. All rights reserved.

Status