← Pay It Forward OS

DATA OWNERSHIP

Your organization’s data belongs to your organization

Effective August 10, 2026

The short version

You keep what you put in. We get only the permissions we actually need to run the service for you. You can leave, and you can take your records with you — today that is a request we fulfil by hand, not a button in the app. We will tell you plainly what we cannot promise, including instant erasure from backups.

1. Four different things, four different answers

a. Your organization’s records. Contacts, supporters, events, volunteer assignments, donations and fundraising records, programs, bookings, documents, and notes. Your organization owns these. Our rights are limited to operating the service.

b. Content you create and publish. Your site copy, images, video, logos, and program descriptions. You own these. You grant us only the license needed to host, process, display, transmit, back up, secure, and administer them — including publishing the parts you choose to make public.

c. The PIFOS platform. The software, database design, interface, and the Pay It Forward OS brand belong to FitchCraft. Using PIFOS does not transfer any ownership of the platform to you, and hosting your data does not give us ownership of it.

d. Operational information about the service itself. Logs, error reports, and health metrics that tell us whether the platform is working. We use these to run and improve the service. We do not currently build or sell aggregated or de-identified datasets from organizations’ records. If that ever changes, we will say so here first.

2. Separation between organizations

Organizations share the same software foundation, but each organization’s records are scoped to that organization and enforced at the database layer as well as in the application. One organization’s private records are not another organization’s data. Within a workspace, access depends on role, and sensitive supporter records require an elevated permission rather than being open to every member.

The exception is deliberate: information your organization chooses to publish on its public site is public. Everything else stays inside the workspace.

3. Getting your data out

There is not yet a self-service export button. We are not going to pretend otherwise. Today, export is an administrative request: write to hello@payitforwardos.com from an administrator account and we will produce a copy of your organization’s records in a common structured format. We will confirm scope, format, and timing when you make the request.

You do not have to be leaving to ask, you do not need a reason, and there is no fee for a reasonable export request. Self-service export is on our roadmap; when it ships, this page will change.

4. Deleting your data — and what deletion really means

Administrators can delete individual records in the app — contacts, documents, events, donations, programs, bookings, videos and similar. Deletion removes the record from the live service immediately.

Backups are the honest caveat. We keep routine encrypted backups so we can recover from failure or mistake. A deleted record can persist in those backups for a period after you delete it, and it is removed as those backups age out. We cannot surgically erase a single record from an existing backup snapshot, and any service that tells you otherwise should be asked how.

We may also retain information longer where we genuinely need to: to comply with a legal obligation, to resolve a dispute, to investigate abuse or a security incident, or to enforce our agreements. We do not currently publish fixed retention or backup-expiry periods; those are under review and will be stated here once settled.

5. Leaving the platform

You can leave at any time — there is no contract term on the donated base workspace. A sensible order: request your export, confirm you have it and can read it, then ask us to close the workspace.

On closure we deactivate the workspace and its public site, and remove the organization’s records from the live service. Backup copies age out as described above. Tell us if you need a different sequence — for example keeping the public site up briefly while you redirect supporters elsewhere.

6. Where your data physically lives

PIFOS runs on third-party infrastructure in the United States — an application host, a database/authentication/file-storage provider, a payment processor, an email provider, and an AI provider for the optional in-workspace assistant. They process data on our instructions to deliver the service; they are not free to use your organization’s records for their own purposes. The categories are listed in the Privacy Policy.

7. People in your records who are not your users

Most of the people described in a nonprofit’s records — donors, volunteers, participants, families — never create a PIFOS account. Your organization decides what to collect about them and remains responsible for handling it lawfully, including any consents required for minors. If one of them contacts us directly, we will route the request to your organization and help you respond rather than acting on your records unilaterally.

8. Questions

Ask us. If something on this page is not true of your situation, we would rather correct the page than let it stand. hello@payitforwardos.com · See also Terms of Use.

Interim Policy — Pending Formal Legal Review. This policy describes our current practices in good faith and is provided for transparency while Pay It Forward OS operates in limited release. It has not yet completed formal legal review, and it is not legal advice. We expect to revise it as our practices develop and that review concludes. Nothing here should be read as a certification of compliance with any particular law or standard.

Questions? hello@payitforwardos.com