Security & trust

An overview of how DonorDesk isolates your organization's data, who processes it on our behalf, and how to exercise your data rights.

Tenant data isolation

Every tenant-scoped database table enforces Postgres row-level security (RLS): each row carries the owning organization's tenant ID, and the database itself — not just the application — refuses to return or modify a row unless the current session is scoped to that tenant. The application's database role has no bypass: RLS is enabled and forced on every tenant table, so a bug in application code cannot leak one organization's data into another's request.

Subprocessors

  • Creem — payment processing and subscription billing (merchant of record).
  • Google Drive — optional, tenant-selected evidence storage (link-first; DonorDesk never copies file contents by default).
  • Cloudflare R2 — optional managed object storage for tenants that opt into DonorDesk-managed uploads.

No subprocessor is engaged for a tenant's content unless that tenant's configuration selects it.

Data export and deletion

You can export your projects, reports, and evidence at any time from within the product. Downgrading or canceling a subscription never deletes data — your organization keeps read, export, and delete access on the free Starter tier. To request full account deletion, contact privacy@donordesk.online.

Data processing agreement (DPA)

Enterprise and Growth customers may request a signed Data Processing Agreement. Email privacy@donordesk.online or use the sales contact form.

See also our Privacy Policy and Terms of Service.