Skip to content

Legal

Compliance

Who verifies whom, where the money actually sits, and what happens when something looks wrong. Written for the person at your organization who has to sign off on this.

Last reviewed 4 August 2026

We never hold your donations

This is the most important fact on the page, and everything else follows from it. Every donation is charged directly to the nonprofit's own account with Stripe or PayPal — Aurora is named on the charge as the platform, but the nonprofit is the merchant and the money settles into the bank account they verified with their processor.

Aurora has no pooled account, no client-money account, and no balance of your donations at any point. We cannot pay ourselves out of your gifts, we cannot delay your payouts, and we cannot refund a donation on your behalf — your processor does that, on your instruction.

It also means that if Aurora disappeared tomorrow, your donations would not be caught up in it.

Every organization is verified before it can take a penny

An organization cannot accept a single donation through Aurora until it has completed Stripe's own onboarding, which verifies the legal entity, its tax identification number, its representative's identity, its beneficial owners, and its bank account.

That is not a policy we apply — it is how the software is built. The widget's ability to create a charge is derived from the capability status Stripe reports back, so an organization Stripe has not cleared has a widget that cannot create a charge at all. There is no code path around it.

Donations can only ever reach the organization that asked for them

The account a donation is paid into is resolved on our servers from the organization that published the need. Nothing the donor's browser sends can name a destination, because no part of our API accepts one.

Connected accounts are organizations, never individuals — Aurora has no personal fundraisers and no way to create one. So the pattern these controls usually exist to catch, where the person collecting is not the person benefiting, cannot be constructed here.

Sanctions

Aurora is a US company and is subject to OFAC sanctions regulations. We onboard organizations registered in the United States, with US bank accounts, in US dollars only — there are no international payouts and no cross-border settlement.

Stripe screens every connected account, its representative and its beneficial owners against sanctions lists as part of onboarding, and screens transactions. Our checkout endpoints additionally refuse requests that appear to originate in a comprehensively sanctioned jurisdiction.

We also screen independently. Every organization on Aurora is checked daily against the sanctions lists the US Treasury publishes — around twenty thousand designated parties and their known aliases, refreshed every morning. A possible match is reviewed by a person; it never automatically stops anyone's donations, because a name resembling another name is a question, not a finding.

All of our infrastructure is hosted in the United States.

We check that your EIN is really yours

When an organization tells us its EIN, we check it against the IRS record of exempt organizations and compare the registered name to the name on the account. A mismatch is reviewed by a person.

That data reaches us through ProPublica's Nonprofit Explorer, which republishes the IRS Business Master File — we send them an EIN and nothing else, and an EIN is public information printed on the receipts you already issue. If their service is unavailable we record that we could not check, which is deliberately not the same as recording that your EIN is invalid.

We watch for donations that do not look ordinary

Every donation is checked against bounds before it is taken: nothing under a dollar, nothing over a hundred thousand. Beyond that we review unusually large single gifts and unusually heavy days for an organization — including days built from many small donations that individually look like nothing, which is what deliberate structuring is designed to look like.

These are review thresholds, not limits. Nothing here refuses a donation, because a platform that never holds your money cannot claw it back either way — so blocking a real gift on suspicion would cost a real charity something and buy nobody anything.

Every need declares what it is for

Organizations choose a cause for each need they publish from a fixed list, rather than typing whatever they like. It is a short list on purpose. Its value is not that a need labelled food is about food — it is that a need labelled food whose text is about something else entirely becomes a question somebody can ask, which is not possible without the field.

What is published, and what binds you

Our Acceptable Use Policy sets out who may use Aurora, what may not be funded through it, and the standards for what an organization publishes. It incorporates Stripe's Restricted Businesses list in full, and it is a binding term rather than a notice — organizations accept it, we record the acceptance, and a change re-prompts everyone.

We maintain written Know Your Customer, Anti-Money Laundering and Sanctions Compliance policies. We do not publish their text, because they name the specific patterns we treat as red flags and publishing those tells anyone minded to work around them exactly where the lines are. We send them to payment partners and to organizations that need them for their own governance — just ask.

Read the Acceptable Use Policy, or write to support@auroradonate.com for the others.

What we are still building

Aurora is a young company, and we would rather list these than let you assume they are already in place. Each is committed in one of our written policies:

  • Aggregation of donation patterns across different organizations. Today each organization is reviewed on its own, so a pattern spread thinly across several would not stand out.
  • Review of a new organization's first published need before it goes live. Today the cause category is recorded but nothing gates publication on it.
  • A dedicated review queue. Flags are recorded and emailed to us today, which works at our size and will not at ten times it.
  • An independent periodic review of our sanctions compliance. We have no employees, so there is currently no independent function to perform one.

If one of these matters to your decision, tell us — it moves it up the list, and knowing which ones people actually ask about is genuinely useful to us.

Reporting something

If you believe an organization is using Aurora for something it should not be, or you have appeared in a need or story without agreeing to it, write to support@auroradonate.com. You do not need an Aurora account, and every report is read by a person.

How we handle personal information is set out in our Privacy Policy, and what we do and do not store is described on our security page.