Skip to content

Trust & Security Center

Connecting you to our latest security, compliance, privacy and legal information.

Privacy & Cookie Policies

This privacy policy applies to the websites of SmartSimple Software, Foundant Technologies, GivingData and Grant Toolbox, which together form an affiliated group of companies (collectively referred to as “Foundant”). When we refer to 'we,' 'us,' or 'our organization,' we mean the specific legal entity operating the website you are visiting, as detailed in Section 8.

We have developed our privacy statement to clearly demonstrate our firm commitment to the privacy of our visitors and users. The following discloses our information gathering and dissemination practices for this website. 

1. Introduction

1.1 We are committed to safeguarding the privacy of our websites visitors.

1.2 This policy applies where we are acting as a data controller with respect to the personal data of our websites and users; in other words, where we determine the purposes and means of the processing of that personal data.  For users accessing our services under a SaaS license agreement, data processing may also be governed by the terms of that agreement. This privacy policy describes our practices for data collected through the websites listed in Section 1.5.

1.3 We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website, we will ask you to consent to our use of cookies when you first visit our website.

1.4 Our website incorporates privacy controls which affect how we will process your personal data. By using the privacy controls, you can specify whether you would like to receive direct marketing communications and limit the publication of your information. You can access the privacy controls here.

1.5 The websites, including subdomains, covered by this policy are the following:

  • foundant.com
    • info.foundant.com
    • community.foundant.com
    • trust.foundant.com
  • smartsimple.com
    •  wiki.smartsimple.com
    • smart.smartsimple.com
  • givingdata.com
    • gdcentral.givingdata.com
    • solutions.givingdata.com

  • granttoolbox.com.au
    • support.granttoolbox.com.au

For more information about our legal entities, see Section 8.


2. How we use your personal data

2.1

In this Section 2 we have set out:

  1. general information on how we collect information on this website
  2. the general categories of personal data that we may process;
  3. in the case of personal data that we did not obtain directly from you, the source and specific categories of that data;
  4. the purposes for which we may process personal data; and
  5. the legal bases of the processing.

2.2 The personal information we collect can be divided into two main categories: information you give us, and information we collect automatically.

Information You Give Us:

We request to collect information from you when you are engaged in any of the following activities on our website or are otherwise engaged with us:

a.    Job Application
b.    Demo Request
c.    General Inquiry
d.    Event Sign-Up
e.    Newsletter Sign-Up
f.    Webinar Sign-Up
g.    Content Downloads
h.    Live Agent Chat
i.    GDPR Requests
j.    Filling out a web form
k.    Attendance at a live event or an event hosted by one of our affiliates

You can choose whether or not to disclose your personal data while engaging in these activities. However, if you do not provide the information we have deemed mandatory, you will not be able to take full advantage of the website and its functions or content.
When you submit data on our website, you will be consenting to us processing the categories of personal data that you have provided. The categories of personal data that we collect are as follows:

Contact Data

We may process your contact data ("contact data"). The contact data may include your first name, last name, email address, and phone number. The contact data may be processed for the purposes of communicating with you, operating our website, providing our services, processing requests, record-keeping, and marketing and sales purposes. The legal basis for this processing is consent OR our legitimate interests, namely the proper administration of our website and business.

Notification Data

We may process information that you provide to us for the purpose of subscribing to our email notifications and/or newsletters, and/or downloading content, confirmation of event or webinar registration, changes to any current or future registrations, notifications if you change your communication preferences, removing you from our mailing list upon your request, and adding you or deleting you from our marketing database. ("notification data"). The notification data may be processed for the purposes of sending you the relevant notifications and/or newsletters, and/or content. The legal basis for this processing is consent.

Correspondence Data

We may process information contained in or relating to any communication that you send to us ("correspondence data"). The correspondence data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms. The correspondence data may be processed for the purposes of communicating with you and record-keeping. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business and communications with users.

Inquiry Data

We may process information contained in any inquiry you submit to us regarding goods and/or services ("inquiry data"). The inquiry data may be processed for the purposes of offering, marketing and selling relevant goods and/or services to you. The legal basis for this processing is consent.

GDPR Request Data

We may process information contained in any GDPR Request you submit to us fulfilling your rights set out by the GDPR (“GDPR request data”). We will process this data for the purpose of fulfilling the request, communicating to you about the request, and sending you a validation once the request has been fulfilled. The legal basis for this processing is consent, OR if the processing is necessary to comply with our legal obligation as a controller.

Job Application Data

We may process data contained in any inquiry you make relating to job applications (“job application data”). This data may include address, city, country, province/state, postal/zip, work eligibility, employment status, level of education, work experience, desired annual salary, and anything you submit to us in your cover letter and/or resume. This data may be processed for human resources, hiring procedures, and record-keeping. To support these activities, job application data may be shared with Rippling (People Center, Inc.), our HR management platform, as set out in Section 3.2. The legal basis for this processing is consent OR the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.

Health Data

We may process “health data”. We may collect this data when you are signing to attend an in-person event with us . This data may include food allergies, diet restrictions, and if you require special assistance. This data may be processed for the purposes of providing you appropriate accommodations at our event(s), should you require it. The legal basis for this processing is consent OR if processing is necessary in order to protect the vital interests of the data subject or of another natural person.

Information We Collect Automatically:

We request and/or request to collect information from you when you are engaged in any of the following activities on our website:


Usage Data

We may process data about your use of our website and services ("usage data"). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is Google Analytics. This usage data may be processed for the purposes of analyzing the use of the website and services. The legal basis for this processing is consent OR our legitimate interests, namely monitoring and improving our website and services.

Security and Fraud Prevention Data

We use Google reCAPTCHA to protect our website and services from automated abuse, spam, and fraudulent activity. reCAPTCHA analyzes user interactions to distinguish legitimate users from bots. This processing may include IP address, browser characteristics, device information, mouse movements, click patterns, keystroke dynamics, and cookies. We act as the data controller for this processing, and Google processes this data on our behalf as a data processor under the Google Cloud Data Processing Addendum. Data may be transferred to Google's servers in the United States, protected by Standard Contractual Clauses.


The legal basis for this processing is our legitimate interests, namely protecting our website and services from fraudulent activity, automated abuse, and spam, and ensuring the security and integrity of our systems. 

More Information

We do not purchase marketing lists from third-parties.

 

We may process any of your personal data identified in this policy where necessary for the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is our legitimate interests, namely the protection and assertion of our legal rights, your legal rights and the legal rights of others.


In addition to the specific purposes for which we may process your personal data set out in this Section 2, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.


You must not provide us with personal data relating to any third party unless specifically requested to do so by us or where such disclosure is necessary for the purposes outlined in this policy.

3. Providing your personal data to others

3.1 We may disclose your personal data to any member of our group of companies (this means our subsidiaries, our ultimate holding company and all its subsidiaries) insofar as reasonably necessary for the purposes, and on the legal bases, set out in this policy. Information about our group of companies can be found in section 8.  Additionally, in the event we, or substantially all of our assets, are acquired by one or more third parties as a result of an acquisition, merger, sale, reorganization, consolidation, or liquidation, in which case information may be one of the transferred assets.  We require that all members of our group of companies implement appropriate security measures to protect usage data.  

3.2 We use the following sub-processors to process the data categories listed below: 
 (last updated: June 1, 2026)

 

Sub-processor

Data Categories Processed

Purpose

Zoom/Teams

Contact Data, Correspondence Data

Video conferencing/meetings

Unbounce

Contact Data, Inquiry Data

Landing pages/lead generation

Rippling (People Center, Inc.) 

Job Application Data, Contact Data, Employee HR Data (including payroll, benefits, and performance data) 

HR management, payroll administration, and applicant tracking 

Emma

Contact Data, Notification Data

Email marketing/campaigns

Google Analytics

Usage data

Website analytics/visitor tracking

WordPress

Contact Data, Usage Data, Content Data

Website hosting and content management

WPRocket

Usage Data

Website performance optimization

WPML

Content Data

Website multilingual functionality

Google Ads

Contact Data, Usage Data

Online advertising/remarketing

Google reCAPTCHA

Contact Data, Usage Data

Bot detection and fraud prevention

Marketo

Contact Data, Usage Data, Notification Data

Marketing automation/campaign management

Marketo Measure (Bizible)

Contact Data, Usage Data

Marketing attribution/analytics

ClickCease

Usage Data

Click fraud protection

PathFactory

Contact Data, Usage Data

Content engagement tracking

Microsoft Clarity

Usage Data

Website behavior analytics

VWO

Usage Data, Contact Data

A/B testing/website optimization

OneTrust

Contact Data, Consent Data

Cookie consent management

Vanilla Forums

Contact Data, User-Generated Content

Community forum hosting

Zendesk

Contact Data, Inquiry Data, Correspondence Data

Customer support/ticketing

ChiliPiper

Contact Data, Scheduling Data

Meeting scheduling/routing

Captivate

Usage Data

Content engagement/learning management

Oktopost

Contact Data, Usage Data

Social media management

Vimeo

Usage Data

Video hosting

ZoomInfo

Contact Data

Sales intelligence/lead enrichment

HubSpot

Contact Data, Usage Data, Notification Data

CRM/marketing automation

Calendly

Contact Data, Scheduling Data

Meeting scheduling

LinkedIn

Contact Data, Usage Data

Social media advertising/analytics

Microsoft Ads

Contact Data, Usage Data

Online advertising

YouTube

Usage Data

Video hosting/embedding

Salesforce

Contact Data, Inquiry Data, Usage Data

CRM/sales management

All processing is limited to the purposes specified in Section 2. Health Data are not shared with or processed by our sub-processors.

 

These sub-processors are situated in the United States. Transfers to the United States are protected by Standard Contractual Clauses (SCCs) adopted by the European Commission. We have entered into a Data Processing Agreement with each sub-processor that incorporates these SCCs.

 

3.3 In addition to the specific disclosures of personal data set out in this Section 3, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your personal data where such disclosure is necessary for the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.  We may also use, disclose, and/or sell anonymized, aggregate data based on usage data, provided that such data cannot be combined with any other data to re-identify any individuals.

4. International transfers of your personal data

In this Section 4, we provide information about the circumstances in which your personal data may be transferred to countries outside of the region in which you are located, including outside of the European Economic Area (EEA)

 

4.1 We have offices in the United States, Canada , United Kingdom, Ireland and Australia.  The hosting facilities for our websites are located in the United States and Canada. The European Commission has made an "adequacy decision" with respect to the data protection laws of each of these countries. According to the European Commission, Canada offers adequate protections for the transfer of data. Data transferred to Canada will be covered by the adequacy decision. Transfers to the United States will be protected by appropriate safeguards, namely the use of standard data protection clauses adopted or approved by the European Commission.

 

4.2 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.

5. Retaining and deleting personal data

5.1 This Section 5 sets out our data retention policies and procedure, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data. 

Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

 

5.2 We will retain your personal data as follows: 
Usage data will be retained for a maximum period of 26 months following the date of collection.
Contact Data will be retained for a maximum period of 5 years following the date of collection.
Notification Data will be retained for a maximum period of 5 years following the date of collection.
Correspondence Data will be retained for a maximum period of 5 years following the date of collection.
Inquiry Data will be retained for a maximum period of 5 years following the date of collection.
GDPR Request Data will be retained for a maximum period of one (1) day after the request has been fulfilled.
Job Application Data will be retained for a minimum period of the job application process following the application date, and for a maximum period of 5 years following application rejection date. If the job applicant is successful, the data will be subject to our Human Resources Policy.
Health Data will be retained for a minimum period of (1) day post event date, and for a maximum period of 6 months following the date of collection.

Notwithstanding the other provisions of this Section 5, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.

6. Amendment

6.1 We may update this policy from time to time by publishing a new version on our website.

 

6.2 You should check this page occasionally to ensure you are happy with any changes to this policy.

 

6.3 We may notify you of changes to this policy by email or through a notification on this website.

 

7. Your rights

In this Section 7, we have summarized the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.

7.1 Your principal rights under data protection law are:

  • the right to access;

  • the right to rectification;

  • the right to erasure;

  • the right to restrict processing;

  • the right to object to processing;

  • the right to data portability;

  • the right to complain to a supervisory authority; and

  • the right to withdraw consent

 

7.1 Your principal rights under data protection law are:

  1. the right to access;
  2. the right to rectification;
  3. the right to erasure;
  4. the right to restrict processing;
  5. the right to object to processing;
  6. the right to data portability;
  7. the right to complain to a supervisory authority; and
  8. the right to withdraw consent

7.2 The Right of Access. You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.

 

7.3 The Right to Rectification. You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.

7.4 The Right to Erasure. In some circumstances you have the right to the erasure of your personal data without undue delay. Those circumstances include: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defense of legal claims.

 

7.5  The Right to Restriction of Processing. In some circumstances you have the right to restrict the processing of your personal data. Those circumstances are: you contest the accuracy of the personal data; processing is unlawful but you oppose erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise or defense of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise or defense of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.

 

7.6 The Right to Object to Processing.

You have the right to object to our processing of your personal data on grounds relating to your particular situation. This right applies in two contexts:

 

General Objection: You may object to processing where the legal basis is that processing is necessary for the performance of a task carried out in the public interest or in the exercise of any official authority vested in us, or for the purposes of legitimate interests pursued by us or by a third party. If you make such an objection, we will cease to process the personal information unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defense of legal claims.

 

Marketing Objection: You also have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.

 

7.7 

The Right to Data Portability. To the extent that the legal basis for our processing of your personal data is:

  1. consent; or
  2. that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.

7.8 The Right to Complain to a Supervisory Authority. If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.

 

7.9 The Right to Withdraw Consent. To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal. 


How to Exercise Your Rights. You may exercise any of your rights in relation to your personal data by written notice to us OR by emailing us. Contact info provided under 8.2.

8. Our details

8.1 

We are legally organized or incorporated in:

    1. United States as Foundant Technologies, A Montana Corporation, located at 143 Willow Peak Drive, Bozeman MT 59718
    2. United States as SmartSimple Software Ltd., A Delaware Corporation, located at 143 Willow Peak Drive, Bozeman MT 59718
    3. United States as GivingData LLC, A Massachusetts Limited Liability Company, located at 143 Willow Peak Drive, Bozeman MT 59718
    4. Canada as SmartSimple Software Inc., A Federally Incorporated Corporation, located at 501 - 56 The Esplanade, Toronto, ON, Canada. M5E 1A6;
    5. Ireland as SmartSimple Software Ireland Limited, a private limited company, located at Unit A15, Bracetown Business Park, Clonee, Co Meath, D15YDC1;
    6. United Kingdom as SmartSimple Software UK Limited, a private limited company, located at Mark J Rees Llp, Granville Hall, Granville Road, Leicester, Leicestershire, United Kingdom, LE1 7RU
    7. Australia as Foundant Technologies, A Proprietary Limited Company, located at 15 Pine Street, Stirling, South Australia, 5152, Australia

 

8.2 

You can contact us:

Foundant:

By post: 143 Willow Peak Dr, Bozeman, MT 59718, USA

by email: Privacy@foundant.com

SmartSimple:

by post: 501 - 56 The Esplanade, Toronto, ON, M5E 1A6 Canada;

by email: Privacy@foundant.com

GivingData:

by post: 45 Prospect Street, Cambridge, MA 02139

by email: Privacy@foundant.com

9. Data protection officer

9.1 Our data protection officer’s contact details are:

Dara O'Sullivan
(416) 591-1668
Privacy@foundant.com 

Foundant Privacy Policy Mobile Application Addendum

 

Effective Date: July 10, 2026

Introduction

This Mobile Application Addendum (“Addendum”) supplements and forms part of the Foundant Privacy & Cookie Policies (the "Privacy Policy"). It applies specifically to the Foundant mobile application, (the "App"), available for download on the Apple App Store and Google Play Store. To the extent this Addendum conflicts with the Privacy Policy, this Addendum controls with respect to mobile application data processing.

References in the Privacy Policy to "our website" include the App except where the context requires otherwise. All other provisions of the Privacy Policy continue to apply to App users.

1. Scope

App name

Foundant Fund Manager

Platform

iOS (App Store) and Android (Google Play)

Distribution

United States (current). Canada, Australia, EU/EEA/UK distribution is planned and will require a supplemental review before each regional launch.

Users

Fund advisors and fund donors whose accounts are created and administered by a community foundation client operating on the CSuite platform. End users cannot create accounts within the App.

Relationship to web policy

This Addendum is appended to and forms part of the Privacy Policy published at foundant.com. All capitalized terms not defined here have the meanings given in that Policy.

 

2. Additional personal data categories processed by the App

The following categories of personal data are processed by the App and are not described in the main Privacy Policy. All processing is subject to the purposes and legal bases set out below.

2.1 Authentication data

When a user logs into the App, an authentication token and a refresh token are generated by the CSuite platform and stored locally on the user's device using iOS Keychain or Android Keystore encrypted storage. These tokens are used solely to maintain the authenticated session and are not stored in plain text. No passwords are stored on-device.

  • Data elements: encrypted authentication token, encrypted refresh token, associated user ID
  • Legal basis: performance of a contract (enabling authorized access to the user's fund account).
  • Retention: tokens are invalidated upon logout or server-side session revocation. A foundation administrator may revoke access server-side through CSuite at any time.

2.2 Foundation session context

At first login, the App captures a QR code displayed by the community foundation to establish which foundation instance the user's account belongs to. This QR code binding associates the user's identity with a specific foundation client and determines the data environment presented within the App. The camera is used only to read this QR code; no photographs are captured, stored, or transmitted.

  • Data elements: foundation identifier derived from QR code scan, linked user account ID.
  • Legal basis: performance of a contract (necessary to present the correct fund data to the authenticated user).
  • Retention: persists for the duration of the authenticated session; cleared on logout.

2.3 Financial account data

The App retrieves and displays financial data associated with the authenticated user's fund account(s). This data is fetched in real time from the CSuite platform via the App's middleware layer (see Section 3) and is not cached or stored on-device beyond the active session.

  • Data elements: fund name(s), current balance, available balance, pending amounts, transaction history (date, amount, description).
  • Legal basis: performance of a contract; legitimate interests (enabling users to review their fund activity).
  • Retention: data is not persisted on-device. Records in CSuite are subject to the retention schedules maintained by the community foundation as data controller (see Section 7).

2.4 Grant and grantee data

The App displays grant history associated with the authenticated user's fund and allows users to search for prospective grantee organizations. Grant history data is retrieved in real time from CSuite. Grantee search results are sourced from Foundant's internal organization profile service and, where applicable, from Candid (a third-party nonprofit data provider).

  • Data elements:
    • grant history: grantee organization name, Employer Identification Number (EIN), grant amount, grant date, grant status.
    • grantee search: organization name, EIN, address, and profile data from the Foundant internal profile service or Candid.
  • Legal basis: performance of a contract; legitimate interests (facilitating grantmaking activity on behalf of the fund advisor).
  • Retention: grant history data is not persisted on-device. Grantee search results are displayed in-session only and not stored. Underlying records are maintained in CSuite under the community foundation's data retention obligations.

2.5 Payment processing data

The App supports fund contributions by presenting a Stripe-hosted payment link retrieved from the CSuite platform. The App itself does not collect, process, or store payment card data or ACH information. Payment processing is handled entirely within Stripe's hosted environment, and users are subject to Stripe's privacy policy when completing a transaction. Foundant does not receive raw card numbers or bank account details.

  • Data elements received by Foundant: contribution amount, transaction confirmation reference, payer identity (linked to the authenticated CSuite user account).
  • Legal basis: performance of a contract; legal obligation (financial recordkeeping).
  • Retention: contribution confirmation records are retained in CSuite in accordance with the community foundation's financial record-keeping obligations and applicable law.

2.6 Tax and grant receipt documents

The App provides access to downloadable financial and tax documentation (such as fund statements and charitable contribution receipts) associated with the authenticated user's account. These documents are retrieved from CSuite on demand and are not cached on-device.

  • Data elements: document files containing the user's name, fund identifier, transaction amounts, dates, and tax reference information.
  • Legal basis: performance of a contract; legal obligation (supporting the user's tax record-keeping requirements).
  • Retention: documents are not stored on-device after the session ends. Source records are maintained in CSuite under the community foundation's retention obligations.

2.7 Device analytics and diagnostic data

The App collects limited device and usage data to support debugging, performance monitoring, and production issue resolution. This data is transmitted to Firebase (a Google service) and is not used for advertising or cross-app tracking purposes. This data collection is triggered upon login and upon a crash or performance event.

  • Data elements: user ID, device model, operating system version, app version, crash reports (no personal data included in crash payloads), performance traces.
  • Legal basis: legitimate interests (maintaining app stability, diagnosing and resolving production issues).
  • Retention: Firebase Analytics and Performance data: 14 months. Crashlytics data: 90 days. These periods are governed by Firebase's default retention settings.

2.8 Biometric authentication data

The App supports login using the device's native biometric authentication (e.g., Face ID, Touch ID, or Android biometric unlock). Biometric authentication is processed entirely by the device operating system's secure hardware (such as the iOS Secure Enclave or Android StrongBox/TEE); the App and Foundant do not capture, receive, transmit, or store any fingerprint, facial geometry, or other raw biometric data. The App receives only a success or failure signal from the operating system, which is used to unlock the locally stored authentication token described in Section 2.1.

  • Data elements: none collected by the App or Foundant; only a local authentication success or failure result.
  • Legal basis: performance of a contract (enabling authorized access to the user's fund account via a secure, user-selected login method).
  • Retention: Not applicable. No biometric data is collected, transmitted, or stored by Foundant. Biometric templates remain solely within the device's secure hardware and are governed by the device manufacturer's and operating system provider's own privacy practices.

 

3. Data flow

All data exchanged between the App and the CSuite platform passes through a proprietary Backend-for-Frontend ("BFF") middleware layer developed and maintained by Foundant. The BFF is hosted on Amazon Web Services (AWS) infrastructure within the United States and acts as a proxy, handling authentication, query routing, and data formatting between the App and CSuite. The BFF does not independently store personal data; it processes data in transit only.

All connections between the App, the BFF, and CSuite use TLS 1.2 or higher. Authentication tokens are validated at the BFF layer before any data is returned to the App. AWS is added to the sub-processor table in Section 5 in its capacity as the hosting infrastructure for the BFF.

 

4. Device permissions

The App requests the following device permissions. All permissions are requested at runtime via the operating system's standard prompt. Users may grant or revoke permissions at any time through their device's system settings.

Permission

Data Categories

Purpose

How Requested / Disclosed

Camera

Foundation session context (Section 2.2)

Reading QR code at first login to identify the user's foundation instance. No images are captured or stored.

Runtime OS prompt (iOS / Android)

Persistent analytics identifier

Device analytics (Section 2.7)

App-scoped identifier used by Firebase for crash and performance analytics. Not used for advertising.

Disclosed in App Store / Play Store privacy labels

Face ID / Touch ID / Android Biometric

Biometric authentication (Section 2.8) — no biometric data captured by the App

Allows the user to log in using the device's biometric authentication instead of re-entering credentials

Runtime OS prompt (iOS / Android)

The App does not request access to: microphone, location (precise or approximate), contacts, photos/media library, calendar, health data, Bluetooth, motion sensors, clipboard, or installed application lists.

 

5. Mobile app sub-processors

The following sub-processors are used specifically in connection with the App and are additional to the sub-processors listed in Section 3.2 of the main Privacy Policy.

All are situated in the United States. Transfers are protected by Standard Contractual Clauses where applicable and by the respective vendor's Data Processing Agreement.

Sub-processor

Data Categories

Purpose

Transfer Mechanism

Firebase (Google) — Core, Crashlytics, Analytics, Performance

Device model, OS version, app version, user ID, crash reports (no personal data in crash payloads)

Crash reporting, performance monitoring, and usage analytics to maintain app stability and diagnose production issues

Google/Firebase DPA; SCCs where applicable

AWS (Amazon Web Services)

Authentication tokens, query data in transit

Hosting of BFF middleware; all App-to-CSuite data passes through BFF hosted on AWS

AWS DPA; SCCs where applicable

Stripe Connect

Transaction confirmation reference, payer identity (via CSuite link)

Payment processing for fund contributions; Stripe hosts the payment interface

Stripe DPA; Stripe processes card/ACH data as an independent controller under PCI DSS

Candid

Grantee organization search queries

Nonprofit organization profile data for grantee search functionality

Candid Data Use Agreement

 

6. Data controller and processor relationships

6.1 Foundant as data controller

Foundant acts as data controller for: (a) device analytics and diagnostic data collected via Firebase (Section 2.7); (b) authentication data generated by the App login process (Section 2.2); and (c) any data processed for the purposes of operating, securing, and improving the App infrastructure.

6.2 Community foundation as data controller

For financial account data, grant and grantee data, payment records, and tax documentation (Sections 2.3 – 2.6), the community foundation that operates the relevant CSuite instance is the data controller. That foundation determines the purposes and means of processing the fund advisor's or fund donor's personal data within the platform. Foundant processes such data as a data processor on behalf of the foundation, in accordance with the terms of the SaaS license agreement between Foundant and the foundation. Users wishing to exercise rights over this category of data (access, erasure, rectification, portability) should direct requests to their community foundation in the first instance. Foundant will cooperate with foundations in responding to such requests in accordance with its processor obligations.

 

7. Retention periods — mobile app data

The following retention periods supplement the schedule in Section 5.2 of the main Privacy Policy for data categories specific to the App.

Authentication tokens

Duration of authenticated session; invalidated on logout or server-side revocation.

Foundation session context

Duration of authenticated session; cleared on logout.

Financial account data (balances, transactions)

Not stored on-device. Retained in CSuite under the community foundation's retention schedule and applicable financial record-keeping law.

Grant and grantee data

Not stored on-device. Grantee search results are session-only. Underlying grant records retained in CSuite under the foundation's retention schedule.

Payment confirmation records

Retained in CSuite. Period determined by the community foundation and applicable financial/tax record-keeping obligations.

Tax and receipt documents

Not stored on-device. Source documents retained in CSuite under the foundation's retention schedule.

Firebase Analytics / Performance data

14 months (Firebase default retention).

Firebase Crashlytics data

90 days (Firebase default retention).

Device analytics identifier

Retained for the period of app installation; deleted on app uninstall.

Biometric authentication

Not collected, transmitted, or stored by Foundant. Processed entirely within the device's secure hardware under the operating system provider's controls.

 

8. Exercising your rights in relation to App data

The rights described in Section 7 of the main Privacy Policy apply equally to personal data processed through the App. The following practical guidance is specific to the App context.

8.1 Data controlled by Foundant (device analytics)

To exercise rights over device analytics and diagnostic data collected via Firebase, contact Foundant at Privacy@foundant.com. Foundant will process requests within the timeframes required by applicable law.

8.2 Data controlled by your community foundation (fund and grant data)

To exercise rights over fund account data, grant records, payment records, and tax documents, contact your community foundation directly. As data processor, Foundant will assist the foundation in responding to verified requests.

8.3 Account deletion and data erasure

Because user accounts are created and administered by the community foundation (not within the App itself), account deletion requests must be directed to the foundation. Upon account deletion, authentication tokens stored on-device will be invalidated. Device analytics data held by Firebase may be deleted by contacting Privacy@foundant.com; Foundant will submit a deletion request to Firebase on your behalf.

8.4 Revoking device permissions

Camera access granted for QR code login may be revoked at any time through your device's system settings (iOS: Settings > Privacy & Security > Camera; Android: Settings > Apps > [App name] > Permissions). Revoking camera access after initial login setup will not affect your ability to use the App.

Biometric login (Face ID, Touch ID, or Android biometric unlock) may be disabled at any time in the App's login settings or through your device's system settings (iOS: Settings > Face ID & Passcode; Android: Settings > Security > Biometrics). Disabling biometric login will not affect your ability to log in using your standard credentials.

 

9. App Store and Google Play compliance

The App's Apple App Store listing includes a link to this Privacy Policy. The Apple App Store Privacy Nutrition Label and Google Play Data Safety disclosures have been completed and reflect the data practices described in this Addendum. In the event of any conflict between the app store disclosures and this Addendum, this Addendum is the authoritative statement of Foundant's data practices.

 

10. Security measures specific to the App

In addition to the security practices described in the main Privacy Policy, the following measures apply to the App:

  • All network traffic between the App, BFF middleware, and CSuite uses TLS 1.2 or higher.
  • Authentication tokens are stored using iOS Keychain and Android Keystore encrypted storage; no credentials are stored in plain text on-device.
  • The BFF middleware validates authentication tokens before returning any data, ensuring that fund data is accessible only to the authenticated account holder.
  • Session access can be revoked server-side by a foundation administrator through CSuite, which invalidates the user's tokens and prevents further data access from the App.
  • No personal data is cached on-device outside of the authenticated session.

 

11. Future regional distribution

The App is currently distributed in the United States only. Before distribution is expanded to Canada, Australia, or the EU/EEA/UK, this Addendum will be reviewed and updated to address the applicable regional requirements, including but not limited to:

Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) / Law 25 (Quebec).

Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles.

EU/EEA/UK: General Data Protection Regulation (GDPR) / UK GDPR, including lawful basis assessment, data subject rights, international transfer mechanisms, and appointment of a local representative if required.

 

No data from users located outside the United States is collected or processed under this Addendum until the relevant regional update has been completed and published.

 

12. Changes to this Addendum

Foundant may update this Addendum from time to time. The current version will be published at foundant.com/privacy and linked from within the App. Material changes will be communicated in accordance with Section 6 of the main Privacy Policy.

 

Cookie Policy

About cookies

A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.

Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

Cookies used by our service providers

Our service provider uses cookies and those cookies may be stored on your computer when you visit our website.

 

We use Google Analytics to analyse the use of our website. Google Analytics gathers information about website use by means of cookies. The information gathered relating to our website is used to create reports about the use of our website. Google's privacy policy is available at: https://www.google.com/policies/privacy/

Managing cookies

Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:

 

  1. Chrome
  2. Firefox
  3. Opera
  4. Internet Explorer
  5. Safari
  6. Edge

Blocking all cookies will have a negative impact upon the usability of many websites.

If you block cookies, you will not be able to use all the features on our website.

 

How to manage your cookie preferences

You can review and change your cookie preferences at any time by clicking on the “Cookie Settings” icon or the button below. This will allow you to withdraw your consent or modify your selections. 

 

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Functional Cookies

These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly. 

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.

Targeting cookies

These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.