Part One
Universal Section
Applies to everyone.
1. Who We Are and What This Policy Covers
This Privacy Policy explains how Sapling CRM, Inc. and Sapling Pay, Inc. collect, use, share, and protect personal information across their products: Sapling CRM (a constituent-relationship-management platform for fundraising organizations, operated by Sapling CRM, Inc.) and Sapling Pay (a donation and payment-facilitation platform, operated by Sapling Pay, Inc.). Both are Delaware corporations and wholly-owned subsidiaries of Silver Lion Technologies, Inc. (d/b/a The Sapling Group), located at 7014 E Camelback Rd, Suite B100a, Scottsdale, AZ 85251. Sapling CRM, Inc. and Sapling Pay, Inc. are separate entities; each is responsible for its own product and data practices as described in this policy.
This policy covers our websites, the products, and related communications. It does not cover the independent privacy practices of the organizations that use our products, or of third parties such as Stripe or a Sponsor, each of which maintains its own policies.
2. Our Role: When We Are a Controller vs. a Processor
Sapling CRM, Inc. and Sapling Pay, Inc. play different roles depending on the data:
- We act as a controller (we determine why and how data is processed) for: visitors to our websites, individuals who register for or administer an account with us, and our own marketing and business operations. This policy governs that data.
- We act as a processor / service provider (we process data on a customer’s behalf, under their instructions) for: the data that a fundraising organization (“Customer”) puts into Sapling CRM, and the donor and transaction data processed through Sapling Pay. For that data, the Customer is the controller, our processing is governed by the applicable Data Processing Agreement (DPA), and the Customer’s own privacy notice applies to the individuals (such as donors) whose data they collect.
Where we act as a processor, and you are an individual (for example, a donor) seeking to exercise rights over your data, we will refer your request to the relevant Customer, or assist that Customer in responding, as described in Section 9.
3. Information We Collect
Depending on how you interact with us, we may collect:
- Identifiers and contact data — name, email, phone, organization name, mailing address, account credentials.
- Organizational and account data — role, subscription/plan, settings, support communications.
- Payment-related data — for payments processed through Sapling Pay: billing details, donation and transaction records, recurring-gift schedules, payment tokens, and truncated card display data (brand and last four). We do not collect or store full card numbers, CVV/CVC codes, or bank credentials — those go directly to our payment partner (Stripe). See the Sapling Pay block.
- Usage and device data — IP address, device and browser information, log data, and interactions with our sites and products.
- Content you submit — data a Customer uploads into the CRM, prompts submitted to AI-assisted features, and communications.
4. How We Use Information
We use information to: provide, operate, secure, and improve the products; process and settle payments (via Stripe); provide support; communicate service and, where permitted, marketing messages; detect and prevent fraud and abuse; and comply with legal, tax, and payment-network obligations.
Legal bases (where GDPR/UK GDPR applies): performance of a contract; our legitimate interests in operating and securing the products; compliance with legal obligations; and consent where required (for example, certain marketing). Where we act as a processor, the Customer is responsible for the legal basis for its collection.
For AI-assisted features and service-improvement processing, see Block A (Sapling CRM): we use de-identified, aggregated data to improve the products and Orchid AI, we do not train AI on identifiable Customer Data without consent, and Customers may opt out.
5. How We Share Information
We do notsell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law. We disclose personal information only to:
- Service providers / subprocessors that help us run the products — for example, payment processing (Stripe), hosting and infrastructure, email delivery, authentication, and AI model inference. The current, authoritative lists are maintained in the Sapling CRM DPA and Sapling Pay DPA.
- Payment partners (Stripe) as necessary to process and settle payments.
- Legal, safety, and compliance recipients where required by law, to enforce our agreements, or to protect rights and safety.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
For the special case of the Sapling Pay Sponsorships program, see the Sponsors block — your data is not shared with a Sponsor unless you choose to engage with that Sponsor directly.
6. Cookies and Analytics
We use cookies and similar technologies on our websites for functionality, security, and analytics. Our website analytics currently include Google Analytics, Vercel Analytics, and Apollo, which collect information such as IP address, device and browser details, and site interactions from visitors to our marketing websites. These analytics run only on our marketing websites, not on Sapling Pay payment pages (the donation and embedded checkout flows), consistent with our payment-security posture.
We use these tools only for our own first-party analytics and site operation. We do not use them to sell your personal information or to share it for cross-context behavioral advertising. You can control cookies through your browser settings; some features may not work without them.
7. Data Retention
We retain personal information for as long as needed to provide the products, operate our business, and meet legal, tax, financial-recordkeeping, and payment-network obligations, after which we delete or de-identify it. Where we act as a processor, retention follows the applicable DPA and the Customer’s instructions. Residual copies may persist in backups until overwritten in the ordinary course.
8. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, multi-factor authentication for privileged access, tokenization of payment data, logging, and incident-response procedures. Card data is handled by our PCI-DSS Level 1 payment partner; Sapling Pay validates under PCI SAQ A and does not store card numbers. For more detail, see our Security page at saplingcrm.org/security-policy and the security measures in our DPAs. No system is perfectly secure, and we cannot guarantee absolute security.
9. Your Privacy Rights
Depending on where you live and our role, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to opt out of sale/share (we do not sell or share) and certain profiling, and to withdraw consent. California residents have rights under the CCPA/CPRA, and individuals in the EEA/UK/Switzerland have rights under the GDPR/UK GDPR.
- To exercise rights over data we control (website, account, marketing), contact us at privacy@saplingcrm.org.
- To exercise rights over data we process for a Customer (data in a Customer’s CRM, or donor/payment data), please contact the relevant organization (the Customer), which is the controller; we will assist them as required under the applicable DPA.
We will not discriminate against you for exercising your rights. You may also have the right to appeal a decision or to lodge a complaint with a supervisory authority.
California — Categories of Personal Information
The table below describes the categories of personal information (using the categories defined under the CCPA/CPRA) that we may have collected in the preceding 12 months, and the categories of recipients to which we may disclose it for a business purpose. We do not sell personal information or share it for cross-context behavioral advertising.
| CCPA/CPRA Category | Examples we may collect | Disclosed for a business purpose to |
|---|
| Identifiers | Name, email, phone, mailing address, IP address, account/organization identifiers | Hosting/infrastructure, email delivery, authentication, payment partner, analytics |
| Customer records (Cal. Civ. Code §1798.80) | Billing details, payment/transaction records | Payment partner (Stripe), hosting/infrastructure |
| Commercial information | Donation/transaction history, recurring-gift schedules, subscription/plan | Payment partner, hosting/infrastructure |
| Financial information | Payment tokens, truncated card display (brand, last four); no full card numbers, CVV, or bank credentials | Payment partner (Stripe) |
| Internet/network activity | Device/browser data, log data, site and product interactions | Hosting/infrastructure, analytics |
| Geolocation (approximate) | Coarse location inferred from IP address | Hosting/infrastructure, analytics |
| Professional/employment information | Role/title of account and organization users | Hosting/infrastructure |
| Inferences | Limited inferences drawn to operate and improve the products | Hosting/infrastructure |
We do not knowingly collect the CCPA/CPRA categories of sensitive personal information beyond those necessary to provide the products, and we do not use sensitive personal information for purposes that would trigger a right to limit its use. We retain each category for the period described in Section 7.
How and When We Respond
To exercise rights, contact us as described above. We will acknowledge and respond within the timeframes required by applicable law (generally within 45 days for CCPA/CPRA requests, extendable once, and within one month for GDPR requests). We will take reasonable steps to verify your identity before fulfilling a request, and, for data we process on behalf of a Customer, we will route or assist as described above. You may use an authorized agent to submit a request, subject to verification.
EEA, UK, and Switzerland (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described above, and you may exercise them by contacting privacy@saplingcrm.org. The legal bases on which we rely are described in Section 4. Where we act as a processor for a Customer, the Customer is the controller and its privacy notice applies.
International data transfers.We are based in the United States and process personal information there. Where we transfer personal information from the EEA, UK, or Switzerland to the United States or another country that does not provide an equivalent level of protection, we rely on an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, and we take additional measures where required.
Complaints and representative. You have the right to lodge a complaint with your local supervisory authority. Where legally required, our EU/UK representative and the relevant contact details will be identified here.
10. Children's Privacy
The products are not directed to children under 13, and we do not knowingly collect their personal information. Customers are responsible for not submitting children’s data in violation of applicable law (including COPPA). See the DPAs.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be indicated by updating the Effective Date and, where appropriate, by additional notice. Continued use after an update constitutes acceptance where permitted by law.
12. Contact
Privacy questions or requests: privacy@saplingcrm.org, or Silver Lion Technologies, Inc. (Attn: Privacy), 7014 E Camelback Rd, Suite B100a, Scottsdale, AZ 85251.
Block A — Sapling CRM (Organizations and Their Users)
This block applies to fundraising organizations that use Sapling CRM and to their personnel/users.
- Our role: For data a Customer uploads into the CRM (including its donor and constituent records), the Customer is the controller and Sapling CRM, Inc. is the processor/service provider under the Sapling CRM DPA. For the Customer’s own account and admin users, we act as controller of their account data.
- What we process: account and contact data, the Customer’s uploaded constituent/donor records, usage data, support communications, and prompts submitted to AI-assisted features.
- AI features (Orchid AI): AI-assisted features process Customer content using AI providers (currently Anthropic and OpenAI) acting as subprocessors; OpenAI is also used for voice-memo transcription. Under the Sapling CRM DPA: we may use Customer Data in de-identified, aggregated form to improve and develop the Services and Orchid AI; we do not use identifiable Customer Data to train, fine-tune, or improve AI or machine-learning models without your prior express written consent; and we do not use Customer Data to train generalized AI models for unrelated third-party commercial purposes. You may opt out of service-improvement processing by emailing privacy@saplingcrm.org, honored within thirty (30) days (opting out may reduce personalization or AI-feature performance). AI-generated outputs may contain inaccuracies and should be reviewed before you rely on them. The authoritative subprocessor list is in the Sapling CRM DPA.
- Your rights: Individuals whose data a Customer uploaded should direct rights requests to that organization; we assist as processor.
Block B — Sapling Pay (Payments and Transactions)
This block applies to payments processed through Sapling Pay.
- Our role: For donor and transaction data processed through Sapling Pay on a Customer’s behalf, the Customer (the organization receiving funds) is the controller and Sapling Pay, Inc. is the processor/service provider under the Sapling Pay DPA.
- Card data: Donor card details are entered directly into our payment partner’s hosted fields (Stripe Elements). We never receive or store full card numbers, CVV/CVC, or bank credentials. We store only tokens and truncated display data (brand, last four).
- Custody of funds: Sapling Pay is not a bank. Funds are held and settled by Stripe under the Stripe Connected Account Agreement; Sapling Pay facilitates the transaction.
- What we process: names, contact and billing details, donation/transaction records, recurring-gift schedules, payment tokens, and related metadata.
- Import/AI: Certain import and batching features may use an AI provider (Anthropic) as a subprocessor for the import process; it does not have standing access to payments data. See the Sapling Pay DPA, Exhibit C.
Block C — Donors
This block is for individuals who make a donation or payment through a Sapling Pay payment page.
- Who controls your data: Your gift is to the organization, not to Sapling Pay. That organization is the controller of your information; Sapling Pay processes it to facilitate the payment. The organization’s own privacy notice also applies, and questions about your data are best directed to them.
- What we do with it: process your payment (via Stripe), deliver receipts and confirmations, support recurring gifts you set up, prevent fraud, and meet legal/financial obligations.
- Card details: entered directly into Stripe’s secure fields; not stored by Sapling Pay.
- Marketing: we send transactional messages (like your receipt). Any Sponsor marketing is separate and optional — see the Sponsors block and the Donor Terms of Service.
- Giving to a political organization: If you contribute to a political organization (such as a PAC, super PAC, 527 organization, or candidate/campaign committee), that organization may be legally required under campaign-finance law to collect and publicly report certain information about you — which may include your name, address, employer, and occupation — to the Federal Election Commission and/or state authorities. This is the organization’s legal obligation as the controller of your information; Sapling Pay processes the contribution on the organization’s behalf.
Block D — Sponsors (Sapling Pay Sponsorships Program)
Some organizations participate in the Sapling Pay Sponsorships program, in which third-party sponsors help cover payment processing fees and may display branding in the giving flow.
- Your data is not shared with any Sponsor unless you choose to engage with that Sponsor directly (for example, by clicking through to the Sponsor or replying to a Sponsor message), and then only the information you provide or that is necessary for that interaction.
- We execute all Sponsor outreach. Sponsors are not given donor contact lists to enable a placement.
- Optional marketing. Any Sponsor marketing emails, texts, or calls are optional; marketing texts and calls require your separate opt-in and are never a condition of donating. Marketing emails include an unsubscribe mechanism, sender identification, and a physical address, consistent with the CAN-SPAM Act.
- After you engage a Sponsor, your relationship with that Sponsor is governed by the Sponsor’s own terms and privacy policy.
If you are a Sponsor: we also collect and process the contact, account, billing, and campaign information you provide to participate in the program. We use it to operate the program, coordinate placements, invoice and pay, and communicate with you, and we act as controller of that data. We do not sell Sponsor personal information or share it for cross-context behavioral advertising.
Block E — Website Visitors
This block applies to visitors to our websites (as distinct from product users and donors).
- We collect usage and device data, cookies, and any information you submit through forms (for example, sales or support inquiries), and we act as controller of that data. Our website analytics tools are described in Section 6 (Cookies and Analytics).
- We use it to operate and improve our sites, respond to inquiries, and, where permitted, send marketing you can opt out of. We do not sell this information or share it for cross-context behavioral advertising.
Questions about this Privacy Policy? Contact privacy@saplingcrm.org.
Last edited: July 20, 2026.