Data security

How your donors' data is kept safe

Plain answers for your executive director, your treasurer and your board. No jargon, no hedging.

The one thing that matters most

Card numbers never touch your website. When a donor types their card in, it goes straight from their browser to the payment processor. Your site never sees it, never stores it, and could not leak it. That is not a policy, it is how the system is built.

Your data is yours alone

Most donor systems put every nonprofit's data in one shared database. If that system is breached, every organisation on it is exposed at once.

DonorFix does not work that way. Your donors live in your database, on your hosting account, in your name. There is no shared system. Another organisation's problem cannot become yours, because there is no connection between you.

Who can see what

Four levels of staff access, from full administrator to view-only for board members. Set per person, enforced by the system rather than by the menu they see. Sensitive notes can be marked administrator-only.

Coming as volunteer and membership tools arrive: access will move to a simple set of tick boxes, so an administrator can switch each area on or off for each person. A volunteer coordinator sees volunteers; a bookkeeper sees gifts; nobody sees more than their job needs.

Every change to a gift is logged with who made it and when. Gifts are never deleted, only corrected, with the original preserved. That matters for your auditor as much as for security.

Two-factor authentication is available on staff accounts, which most systems in this price range do not offer.

Can DonorFix see our data?

Yes, when we need to, and only then. Updates, fixes and anything you have asked us to help with mean signing in to your system. We do it through a DonorFix account in your system, so our actions appear in your audit log like anyone else's. You control that account: switch it off, and we can no longer sign in.

We never copy, export, sell or share your donor data, and we never use it for anything but looking after your system.

The hosting account and the database are in your organisation's name. You decide who has access, including us, and you can remove ours at any time. Your system and your data stay exactly where they are.

Encryption

Every page, form and sign-in travels over an encrypted connection, so nothing a donor or your staff types can be read on the way.

Card details are handled entirely by the payment provider and never reach your system. Staff passwords are stored in a form that cannot be turned back into the password, so not even we can read them.

Your donor records are protected by who can reach them: they sit in your own database, behind your hosting account, with every access checked. We don't scramble names and addresses inside the database itself, because that would stop search and reports from working, and the key to unscramble them would have to sit on the same server anyway.

Built in from the first day

  • Every page checks who you are. Each screen confirms your access level before it shows anything. Changing a number in the web address does not open someone else's record.
  • Sign-in is protected. Repeated wrong passwords slow down, without locking your own team out. A forgotten password is reset by a single-use link that expires in an hour, and passwords are never sent by email.
  • Sessions time out. A signed-in screen left open on a shared office laptop closes itself after a period of inactivity.
  • Forms can't be faked. Every form that changes your data carries a check that stops it being submitted from another website.
  • Donations are checked on our side. The amount is confirmed by the system, not taken from the donor's browser, and each payment is verified with the payment provider and recorded exactly once.
  • Imports are safe. An imported file is checked before it is saved, a full backup is taken before anything is written, and every import can be undone.
  • Everything is logged. Gift changes, merges, deletions and sign-ins are recorded in an audit log, so "who changed this?" always has an answer.

Backups

Your hosting takes nightly backups. You can also export your entire donor list to a spreadsheet at any time and keep your own copy. That second one matters: it means you are never locked in, and never dependent on anyone else's backup working.

Kept up to date, and looked after

Every DonorFix system receives its updates from a single release, including security fixes. Each release is tested against real data and a fresh installation before it goes out, and your system then collects it. A fix made once reaches every organisation, while your data stays in your own separate database.

That is what Care is for: keeping your system current, watching that it runs every night, and being reachable when something needs attention. It is part of every DonorFix installation, because a system that handles your donations every night should never be left unattended.

What we would do if something went wrong

We would tell you the same day, in plain language. We would establish what was reached and what was not, and the audit log means that is a question with an answer rather than a guess. And because your system is yours alone, the question stays about your organisation and no one else's.

Questions your board wants answered?

Bring them to the call. We will walk through exactly where your data lives and who can reach it.

Book a Demo