Privacy notice
Last updated September 22, 2026
Draft. Written to the shape these documents normally take, and not yet reviewed by a lawyer.
DonorLedger holds sensitive information: who gives to an organization, and how much. This notice explains what we hold, why, and what you can ask us to do about it. ReVu Doc LLC operates DonorLedger and is responsible for the choices described here.
Who is responsible for what
Your organization decides what donor records to keep and what to do with them; we hold and process those records on your instructions so that the service can run. In the language of data protection law, your organization is the controller of its donor records and we are its processor. For your staff’s own accounts, and for the technical records below, we decide the purposes and are the controller. Organizations that need a written data processing agreement should write to [email protected].
What we hold
Donor records your organization enters: names, contact details, household groupings, envelope numbers, and the contributions recorded against them, with the statements produced from them.
Your staff: name, email address, role, and sign-in details. Passwords are stored only as one-way hashes and cannot be read back, by us or by anyone else. Second-factor secrets are encrypted at rest.
Technical records: an activity log of account-level actions, and server logs holding IP address, browser type, and timestamps. These exist so an organization can see who changed what, and so we can find and fix faults.
We do not ask for, and have no use for, government identifiers, health information, or card numbers. Card details go directly to our payment processor and never reach us.
Why we hold it
To provide the service your organization signed up for, to keep it secure, to meet our legal obligations, and to bill for it. Where the law requires a legal basis, ours is the performance of our contract with your organization and our legitimate interest in running and protecting the service.
What we do not do
We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use donor records to advertise to donors, and we do not use them to train machine learning models.
Who can see it
Only people your organization invites, and only as much as their role allows — a volunteer recorder, for example, can enter the week’s gifts but cannot see anyone’s giving history. Each organization’s records are isolated at the database level, not merely in the application.
Our own staff cannot open your records at will. Support access has to be granted by your organization, expires on its own, and everything done during such a session is written to your activity log with the staff member’s name against it.
Donors
If your organization turns on the donor portal, a donor signs in with a link sent to the address the organization holds and sees only their own household’s statements and giving. A donor who wants a record corrected or removed should ask the organization they give to, which controls it; if they write to us, we will pass the request on.
Companies that help us run the service
Hosting and database, transactional and statement email delivery, object storage for generated statement PDFs, subscription payments, and error reporting. Each is bound to protect the information and to use it only to provide its service to us. A current list is available from [email protected], and we will give notice before adding one that materially changes where or how records are held.
Where records are held
Records are stored in the United States. Where information is transferred across borders we rely on the safeguards the law provides for such transfers.
How we protect it
Encryption in transit; access separated per organization and enforced by the database rather than only by the application; passwords stored as one-way hashes; optional second factors with their secrets encrypted; giving history that re-locks on an idle session, because the office computer is often shared; regular backups with restores rehearsed rather than assumed. No system is perfectly secure and we do not claim otherwise.
If something goes wrong
If personal information is exposed in a way that creates a real risk to the people it describes, we will tell the affected organizations without undue delay and within any period the law sets, describe what happened and what we are doing about it, and notify regulators where required.
How long we keep it
Donor and contribution records are kept while the account is open. After cancellation they are kept for 365 days so you can export them, then permanently deleted, leaving only a record that the account existed, which we keep for our own accounting. You can ask us to delete sooner. Backups age out on their own schedule, so a deleted record may persist in a backup briefly before it is overwritten.
Your rights
Depending on where you live you may have the right to ask for a copy of your personal information, to have it corrected or deleted, to object to or restrict how it is used, and to receive it in a portable form. Exercising a right costs nothing and will not lead to worse treatment. Write to [email protected]; we will verify the request and respond within the period the law allows. Where we hold the information for an organization, we will refer you to that organization, which decides.
Children
DonorLedger is for the staff of churches and charities and is not directed at children. An organization may record a gift from a minor as part of its own records; we do not knowingly collect information directly from children.
Changes
We will update this notice as the service changes, and will give notice by email before a material change takes effect. The date at the top shows when it last changed.
Contact
ReVu Doc LLC, 6041 S Brightwater Trl, Springfield, MO 65810. Privacy questions and requests: [email protected].