Skip to content

Legal

Privacy Policy

What Aurora collects, from whom, who else touches it, and what gets deleted. Written from what the software actually does, which is why it is shorter than the ones assembled from a template and specific where those are vague.

Effective 4 August 2026 · Version 2026-08-04

1Who we are, and what we are not

Aurora is software that nonprofit organizations use to show supporters the specific things they need and to accept donations toward them. We are not a charity, we do not solicit donations, and we are not a party to any gift. The donation is between the supporter and the organization; that organization receives the money into its own payment account and issues any receipt.

This page describes how Aurora handles personal information. It does not describe how any individual nonprofit handles the information it collects through Aurora — for that, ask them.

2Two different sets of people

The distinction runs through everything below, because our relationship with the two groups is different.

  • Nonprofit users — the people who hold an account with us. They gave us their information directly, to use our software.
  • Donors and requesters — people whose information reaches us because a nonprofit uses our software. We hold it on that organization's behalf, and they are the ones who decide what to do with it.

3What we collect from a donor

Name, email address, the amount, which need was filled, and when. That is what a completed payment tells us and what the organization needs in order to thank you and keep its records.

If you answer the optional question about why you gave, we keep that answer too — both the reason you picked and anything you typed. It goes to the organization you gave to, the way the rest of your record does. It is optional, it is never a condition of giving, and it is not published anywhere without your permission being asked for separately.

Not card details. Payment happens on Stripe's or PayPal's own checkout, hosted by them, and we receive back a reference to a completed payment. There is no card number in our database.

4What we collect through a public form

An organization can publish two forms that anyone can reach without an account. Both ask for a name, an email address and — optionally — a phone number, alongside the substance of what is being sent in.

A need request adds what is needed, the team or location it relates to, and optionally an estimated cost and a quantity.

A story submission adds what happened, the story itself, the team or location, and the name of the person the story is about. That last field is the one to be careful with: it is somebody else's name, submitted by somebody else, and the person it names has not filled anything in. It is never copied onto the published story, and section 6 says when it is erased.

5Who else is involved

These are the third parties that process data on our behalf. Each one is verifiable in the product itself rather than being a list of vendors we might one day use.

  • Supabase — the database and the file storage behind Aurora.
  • Stripe — payment processing and payouts, for organizations that connect it.
  • PayPal — payment processing and payouts, for organizations that connect it.
  • Resend — transactional email (receipts, alerts, decisions on a request).
  • Vercel — hosting.
  • Double the Donation — employer matching lookups, and only for organizations that have connected their own account with them.

6How long we keep it, stated precisely

Thirty days after a request sent through one of those public forms reaches a closed state — fulfilled or published, declined, or expired — a nightly job erases the contact details on it. The email address and the phone number go, and on a story submission so does the name of the person the story is about. Nobody at the organization has to remember; it happens whether or not anyone opens the queue again.

That job finds a submission by its email address, and every submission made through Aurora carries one: both forms mark the field required and the endpoints behind them reject anything without a valid address. So there is no anonymous request sitting outside the sweep.

It erases contact details and nothing else. The name of the person who sent the request in, the team they named and the text of what they wrote are not erased on a schedule. Donation and donor records are kept for as long as the organization has an account, because they are the organization's financial records.

7Uploaded photographs are publicly readable

Images uploaded to a need or a story are stored in a bucket that anyone holding the URL can read. This is deliberate and necessary: the widget renders on other people's websites and email clients fetch images without signing in, so an access-controlled bucket would leave a broken image everywhere the need appears.

It means an image is only as private as its URL. If a photograph shows a person your organization serves, treat publishing it here the same way you would treat publishing it on your own public website — because that is what it is.

8What we do not do

We do not sell personal information, and we do not share it for advertising. There is no advertising pixel, no analytics tracker and no third-party script on this marketing site — the typefaces are served from our own domain rather than fetched from a font host, so your browser does not talk to anyone else to render this page. If that ever changes, this section changes first and before the script ships.

We do not email an organization's donors or subscribers on our own initiative, and we have no access to any mailing list you keep elsewhere.

9Email choices

Anything optional or repeating — summaries, digests, alerts you asked for — carries a real one-click unsubscribe, and an unsubscribe is recorded against one organization, so muting one does not silence another.

Transactional email cannot be switched off: a receipt for a payment, or the decision on a request somebody submitted, is the answer to something that person did, and suppressing it would leave them with a charge or a pending request and no word about either.

10Your rights, and who to ask

If you are a donor or someone who sent in a request, the organization you dealt with holds your information and is the right first contact. They can look your record up and tell you what it says.

Deletion is the part we will not pretend about. There is no control on their dashboard today that removes a donor record or a submission, so nobody there can do it for you however willing they are. Write to the address below and we will do it — or ask them to, and it reaches us the same way. We would rather write that down than point you at a screen with no such button on it.

If you hold an Aurora account, write to us directly. You can export your organization's full donor and donation history to CSV from the dashboard at any time without asking us.

11Contact

Questions about this policy, or a request about your own information, go to support@auroradonate.com. If you gave to a nonprofit through Aurora and are not sure who holds what, this page explains it.