← Pay It Forward OS

PRIVACY

Privacy Policy

Effective August 10, 2026

1. Who we are and what this covers

Pay It Forward OS (“PIFOS,” “we,” “us”) is a multi-tenant operating system for nonprofits and community organizations, built and operated by FitchCraft. This policy covers the platform site at payitforwardos.com and the organization workspaces we host, including each organization’s branded public site.

Participating organizations are independent. When you interact with an organization’s programs, events, or fundraising, that organization decides what information it collects and how it uses it, and it may publish its own notice. We host and process that information on the organization’s behalf. For questions about information an organization holds about you, contact that organization first.

2. Information we collect

Workspace request details. When you ask for a workspace we collect your organization name, your name and role, email address, and — if you choose to provide them — phone number and a website or social link, along with your region, organization type, team size, priority areas, and the message and fit answers you write.

Account information. Accounts are created and authenticated through our infrastructure provider. This includes your email address, authentication credentials managed by that provider, and your membership and role within an organization (administrator, staff/member, or vendor).

Organization records. Organizations enter operational information into their workspace. Depending on how an organization uses PIFOS this can include contacts and supporter records, events and volunteer assignments, donation and fundraising records, programs and bookings, quote requests, documents and videos, and internal notes. This information is entered by the organization, belongs to the organization, and may describe people who never visit our site.

Notification subscriptions.If you opt in to browser notifications, we store the push endpoint your browser issues, the keys required to deliver a message to it, your chosen notification scope, a management token, and your browser’s user-agent string. Notification sign-up does not require an account.

Newsletter. If you subscribe, we store the email address you provide.

Technical and log information. Operating the service produces server and request logs at our hosting and database providers, which typically include IP address, request metadata, and timestamps. Our own application logs are written as structured events and are automatically scrubbed of credential-like fields.

Payment information. On-site card processing is not currently enabled. If and when it is, card details are handled by our payment processor — we do not receive or store full card numbers. We would retain transaction metadata such as amount, currency, status, and the identifiers needed to attribute a gift to the correct organization.

3. Cookies and similar technologies

We do not use advertising, analytics, or cross-site tracking technologies. There is no analytics SDK, advertising pixel, or behavioral tracking script in this application.

What we do use:

  • Essential session cookies set by our authentication provider so you stay signed in. Without these you cannot use a workspace.
  • Local browser storage for small interface preferences — remembering that you dismissed the app-install prompt, the intro animation, a welcome card, or a setup checklist. This stays on your device.
  • Embedded media. Pages that embed video from third-party platforms load content from those platforms, which may set their own cookies and receive your IP address and page context. That is governed by their privacy policies, not this one.

4. How we use information

  • To provide, operate, maintain, and improve the platform and each workspace.
  • To review workspace requests and communicate with you about fit, setup, and support.
  • To authenticate users and enforce organization membership and roles.
  • To secure the service, investigate abuse, and prevent fraud.
  • To send messages you asked for, such as notifications or a newsletter.
  • To meet legal obligations and respond to lawful requests.

We do not use organization or supporter records to build advertising profiles, and we do not run advertising on the platform.

5. The AI assistant

PIFOS includes an optional in-workspace assistant. When a signed-in member of an organization sends it a message, that message is transmitted to our AI provider (Anthropic) to generate a response. Do not enter information you would not want sent to a third-party processor. The assistant is available only to authenticated members of an organization; it is not exposed to anonymous visitors.

6. How information is shared

We do not sell personal information for monetary consideration, and we do not share it for cross-context behavioral advertising. We do not operate as a data broker.

We share information only in these circumstances:

  • Within your organization — with members of that organization according to their role and permissions.
  • With service providers that operate the platform under contract. These currently include our application host, our database/authentication/file-storage provider, our payment processor, our transactional email provider, our AI provider, and browser push services.
  • When required by law, or to protect the rights, property, or safety of users, the public, or the service.
  • In a business transfer — if the service is transferred to another operator, information may transfer with it, subject to this policy.

7. Separation between organizations

Each organization’s records are scoped to that organization and access is enforced by database-level access rules in addition to application checks. Access depends on membership and role, and particularly sensitive supporter records require an elevated permission rather than being visible to every member by default. Information an organization deliberately publishes on its public site is, by design, visible to the public.

8. Security — and its limits

We use measures including authenticated access, role-based permissions, database-level isolation between organizations, encrypted transport, file-type and size limits on uploads, signature verification on payment webhooks, and logging designed to keep credentials out of logs.

No online service can be completely secure. We do not guarantee absolute security, and we make no certification of compliance with any particular security standard. If you believe you have found a vulnerability, please write to hello@payitforwardos.com.

9. Retention

Organization records are retained for as long as the organization maintains them and its workspace remains active. Administrators can delete individual records within the app. Workspace request and newsletter information is retained while it remains relevant to operating and supporting the service.

Deleting a record removes it from the live service. Copies may persist in routine encrypted backups for a period after deletion, and we may retain information where necessary to resolve disputes, prevent abuse, or comply with legal obligations. We do not currently publish fixed retention periods; they are under review.

10. Your choices and requests

You may ask us to access, correct, or delete information we hold about you, or ask an organization to export its records. These requests are currently handled administratively — there is not yet a self-service export or deletion tool. Write to hello@payitforwardos.com and we will verify the request and respond within a reasonable time.

If your information sits inside a participating organization’s workspace, that organization controls it. We will route your request to them and support them in responding.

You can unsubscribe from the newsletter using the link in the email, and turn off browser notifications in your browser settings or with the management link provided when you subscribed.

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, or to appeal a decision. Where such rights apply, we honor them through the contact method above. We do not claim certification under any specific privacy regime.

11. Children

PIFOS is built for organizations and their staff and volunteers. It is not directed to children, and we do not knowingly collect personal information directly from children through the platform site. Accounts are intended for adults acting for an organization.

Some organizations run youth programs and may enter information about minors into their own workspace as part of their operations. That organization is responsible for obtaining any required parental or guardian consent and for handling that information lawfully. If you believe a child’s information has been provided to us improperly, contact us and we will work with the relevant organization to address it.

12. International users

The service is operated in the United States and information is processed there. If you use PIFOS from another country, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.

13. Changes to this policy

We may update this policy as the service develops. We will change the effective date above and, for material changes, make a reasonable effort to notify organization administrators.

14. Contact

FitchCraft — Pay It Forward OS · hello@payitforwardos.com

Interim Policy — Pending Formal Legal Review. This policy describes our current practices in good faith and is provided for transparency while Pay It Forward OS operates in limited release. It has not yet completed formal legal review, and it is not legal advice. We expect to revise it as our practices develop and that review concludes. Nothing here should be read as a certification of compliance with any particular law or standard.

Questions? hello@payitforwardos.com