Draft — not yet reviewed by counsel. ArcAngel CRM is in closed alpha and is not accepting public sign-ups. These documents describe how the Service is actually built and operated today, but they have not been reviewed by an attorney and should not be relied on as a final agreement. They will be reviewed before the Service is offered generally.
ArcAngel CRM (“ArcAngel CRM,” “we,” “us,” or “our”), a product of ArcAngel Technical Services, LLC, provides case-management and recordkeeping software (the “Service”) to non-profit organizations that run programs — transitional and emergency housing, recovery residences, food and clothing assistance, case management, workforce and education programs, and similar work. The Service holds detailed records about people in difficult circumstances, including children. This Privacy Policy explains what we collect, how we use and protect it, and what rights participants and organizations have.
In short: we collect only what is needed to run an Organization’s programs, we never sell it, rent it, or use it for advertising, we encrypt sensitive fields and every uploaded document, we keep each Organization’s data isolated from every other Organization’s, and the Organization stays in control of its records at all times. The sections below give the detail, including what we do not yet do.
For every customer, ArcAngel CRM acts as a service provider (a “processor”) handling information at the direction of, and under the control of, the non-profit that operates the account (the “Organization”). The Organization decides what information is collected, from whom, why, and for how long. We do not make those decisions, and we do not use the information for any purpose of our own.
People who receive services from an Organization are referred to here as “Participants.” If you are a Participant and have a question about your record, the Organization serving you is the right place to start; Section 9 explains what to do if that is not possible.
We do not have a field for a Social Security number and do not ask for one. An Organization may nonetheless upload a document that contains one; those files are encrypted and access-controlled as described in Section 7.
We do not use advertising or analytics trackers. The Service sets only the cookies required to keep you signed in and to protect forms against cross-site request forgery. There are no third-party trackers, no advertising pixels, and no cross-site profiling.
We use information only to operate, secure, and support the Service for the Organization: to maintain records and program enrollments, produce the reports a funder requires, run staff and participant portals, provide support when the Organization asks for it, keep the Service secure, and administer billing.
We will never: sell or rent Participant information; use it for advertising or to build commercial profiles; use it to train machine learning or artificial intelligence models; or use it for any purpose other than providing the Service to the Organization, except as the Organization directs or the law requires.
The Service can hold information that is specially protected. Responsibility for those rules sits with the Organization, which decides what to record; our responsibility is to provide controls that make compliance possible and to be clear about the limits of what we offer today.
These limits are stated plainly because the alternative — a policy that implies coverage we do not provide — would put an Organization at risk. Each will be removed from this list only when the corresponding agreement and controls actually exist.
We do not sell information, do not share it for anyone’s marketing, and do not combine one Organization’s data with another’s for any purpose, including benchmarking or statistics.
A small number of ArcAngel Technical Services personnel can access the system in order to operate and support it. That access is limited to named accounts, is used only to keep the Service running or to respond to a support request, and is recorded in the audit log — including the “view as” tool, which lets a support engineer see the Service exactly as a particular user sees it. The fact that this access exists is disclosed here rather than buried, because an Organization deciding whether to trust us with its records is entitled to know who can read them.
Our security measures are described in full on the Security page, which states both what is in place today and what is still being built. In summary:
If we become aware of a confirmed breach affecting an Organization’s data, we will notify that Organization without undue delay, and in any event within 72 hours of confirming it, with what we know, what we are doing, and what the Organization may need to do. We will cooperate with any breach-notification obligations that apply to the Organization.
What we do not promise. No online system can be guaranteed perfectly secure, and we do not claim to be. We commit to reasonable administrative, technical, and physical safeguards and to the specific measures above and on the Security page; we cannot guarantee that data will never be accessed, altered, or lost despite them. Keeping credentials confidential and assigning roles carefully remain the Organization’s responsibility.
We retain information for as long as the Organization’s account is active and as needed to provide the Service. An Organization may correct or delete records at any time and may export its data at any time, including while its subscription is inactive.
Retention periods for Participant records are the Organization’s to set: funders frequently require records to be kept for a period of years, and we do not delete records on our own initiative. When an account is closed, we will delete or return the Organization’s data within 60 days of its request, except where retention is required by law. Encrypted backups are purged on a rolling schedule of no more than 90 days, after which deleted data is gone from our systems entirely.
Organizations control their data and can access, correct, export, or delete it through the Service or by contacting us.
Participants may exercise access, correction, and deletion rights through the Organization serving them, which holds the record and is the party that can act on it. We will support the Organization in responding. If you are a Participant and cannot reach the Organization — for example, because it has closed — contact us at [email protected] and we will do what we can, which may be limited by our role as a processor and by the Organization’s own retention obligations.
Depending on where you live, you may have additional rights under state privacy law. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of in those categories.
All Service data — the database, uploaded documents, and backups — is stored in the United States (New York City region). The single exception is outbound transactional email, which is sent through a vendor located in the European Union and therefore carries the recipient’s email address and that message’s contents outside the United States; no Participant record, document, or database content is transferred. This is disclosed in Section 5 and will change if we move email to a United States provider.
We may update this Policy. We will post the updated version with a new effective date and, for material changes affecting Participant data, notify Organizations directly before the change takes effect.
For privacy questions or requests, contact [email protected]. To report a security problem, see the Security page.
Questions about this document? Contact
[email protected].
ArcAngel Technical Services, LLC