1. Scope and Our Role
This Privacy Policy applies to MemberSwift websites, applications, public pages, demos, organization workspaces, member portals, hosted email, and related services (the “Services”).
MemberSwift acts in two different roles. We decide how to use information needed to create accounts, operate subscriptions, secure the platform, provide support, and improve our Services. When an organization enters or collects member, donor, volunteer, event, reservation, website, or email information, that organization generally decides why the information is used. In that situation, MemberSwift processes the information for the organization.
Questions or privacy requests may be sent to info@memberswift.com. If your request concerns records held by a particular organization, contact that organization as well because it controls those records.
2. Information We Collect
Account and organization information
- Name, email address, password hash, role, login session, two-factor authentication settings, and account recovery information.
- Organization name, contact details, staff invitations, permissions, connected domains, plan, storage assignment, support tickets, referral information, and configuration choices.
Member and organization content
- Member contact details, addresses, membership numbers and types, status, expiration dates, household relationships, photos, custom fields, flags, notes, attendance, volunteer activity, rewards, directory choices, and communication preferences.
- Forms, applications, agreements, documents, images, website pages, mailing-list entries, event registrations, tickets, donations, reservations, polls, announcements, accounting records, dues, and payment history.
- Hosted mailbox addresses, contacts, message metadata, message content, attachments, folders, forwarding settings, aliases, and sender rules.
Billing and transaction information
We receive subscription, invoice, payment-status, Stripe account, checkout, refund, dispute, and transaction identifiers. Payment card numbers and bank credentials are collected and processed by Stripe rather than stored by MemberSwift.
Technical and security information
We collect device and browser information, timestamps, requested pages, session and security events, rate-limit activity, error details, and limited network information needed to prevent abuse, diagnose problems, and maintain reliable service. We may hash or shorten security signals where full values are unnecessary.
Information from others
Organizations may import member records or receive information from their staff, members, website visitors, Stripe, connected services, or public forms. The organization is responsible for having authority to provide that information to MemberSwift.
3. How We Use Information
- Provide accounts, organization workspaces, public websites, hosted email, member portals, forms, payments, events, communications, and other requested features.
- Authenticate users, support two-factor authentication, prevent fraud and abuse, enforce permissions, protect organizations from cross-account access, and investigate security events.
- Process subscriptions, apply storage and email limits, confirm transactions, send billing and service notices, and provide customer support.
- Route messages and payments according to an organization’s settings.
- Maintain backups, audit history, operational records, and legally required records.
- Understand feature use and service health using operational or aggregated information.
- Comply with law, protect rights and safety, and enforce our Terms of Use.
Where applicable law requires a legal basis, processing may be necessary to perform a contract, comply with legal obligations, protect legitimate interests in operating and securing the Services, or carry out choices made with consent.
4. Cookies and Similar Technology
MemberSwift uses essential cookies and browser storage for login sessions, security, organization routing, demo isolation, interface preferences such as dark mode, and application reliability. We do not use this information to sell personal data or serve behaviorally targeted advertising. Blocking essential storage may prevent sign-in or other features from working.
5. How Information Is Shared
- With the organization: its authorized owners, administrators, and staff may access information according to their role. Members may see information the organization chooses to place in a portal or private directory.
- With service providers: Cloudflare provides hosting, databases, file storage, routing, security, and email infrastructure. Stripe processes subscriptions and organization payment transactions. These providers handle information under their own terms and privacy practices.
- At your direction: information may be published on an organization website, sent to selected recipients, forwarded to a configured address, or shared with an integration when an authorized user requests it.
- For legal and safety reasons: we may disclose information when reasonably necessary to comply with law, respond to lawful process, prevent fraud or abuse, protect safety, or defend legal rights.
- Business changes: information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice obligations.
MemberSwift does not sell personal information or share it for cross-context behavioral advertising.
6. Payments and Connected Accounts
Stripe processes MemberSwift subscriptions and may process dues, donations, tickets, rentals, and other organization payments through connected Stripe accounts. Organizations select where their funds are routed. MemberSwift receives transaction status and identifiers needed to update records, but Stripe controls its own collection and use of financial information.
7. Email and Communications
Organizations choose their recipients and are responsible for the content and legal basis of messages they send. Members may change optional communication preferences and unsubscribe from marketing communications. Required security, account, transaction, and billing notices may still be sent. Hosted mailbox forwarding may send a copy to a personal address selected by the organization; replies made from that personal account may occur outside MemberSwift.
8. Retention and Deletion
We retain information while an account is active and as needed to provide the Services. Retention may continue for backups, fraud prevention, payment records, legal obligations, dispute resolution, audit history, or enforcement. Different records have different retention periods. Temporary sessions, login codes, demo changes, and rate-limit records expire on shorter schedules.
Organizations should export needed information before closing an account. A verified deletion request may be delayed or limited where retention is legally required, a legal hold applies, a transaction is disputed, or deletion would affect another person’s rights. Backup copies may remain until the backup cycle expires.
9. Security
We use measures designed to protect information, including encrypted connections, password hashing, role-based permissions, two-factor authentication options, private file storage, database separation, request-local organization routing, rate limits, audit records, and restricted support access. No online service can guarantee absolute security. Account owners are responsible for strong credentials, appropriate staff access, and promptly reporting suspected misuse.
10. Your Choices and Rights
Depending on your location and relationship with MemberSwift, you may ask to access, correct, export, or delete information; object to or restrict certain processing; withdraw consent; or appeal a privacy-request decision. You may also manage email preferences, directory visibility, and account security settings where those controls are available.
Send a request to info@memberswift.com. We may need to verify your identity and authority. If an organization controls the requested record, we may direct the request to that organization or assist it in responding. You may also complain to the privacy regulator or attorney general that has authority where you live.
11. Children
MemberSwift is designed for organizations and is not directed to children under 13. Organizations using the Services for youth programs are responsible for obtaining any required parent or guardian permission, limiting collection, configuring appropriate access, and complying with laws that apply to children’s information. Do not create a direct MemberSwift account for a child where parental consent is required and has not been obtained.
12. International Use
MemberSwift and its providers may process information in the United States and other locations where infrastructure operates. Users outside the United States understand that privacy laws may differ. Where required, we use appropriate safeguards for cross-border processing.
13. Changes to This Policy
We may update this policy as the Services or legal requirements change. We will post the revised version with a new effective date and provide additional notice when a material change requires it. Continued use after the effective date means the updated policy applies, subject to rights provided by law.
14. Contact
For privacy questions, rights requests, or concerns, email info@memberswift.com.