Privacy Policy
Last updated: August 2026
CauseDB, LLC ("CauseDB," "we," "us," or "our") operates causedb.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using the Service, you agree to the practices described in this policy.
1. Information We Collect
Information You Provide
When you create an account or use our Service, we may collect:
- Account Information: Email address, display name (optional), and authentication credentials. If you sign in with Google OAuth, we receive your email address and profile name from Google.
- Payment Information: If you subscribe to a paid plan, payment details are collected and processed by our payment processor, Stripe. We do not store your full credit card number on our servers.
- User Content: Collections you create, organizations you follow, and other content you generate within the Service.
- Communications: Information you provide when you contact us through our contact form, including your name, email address, and message content.
Information Collected Automatically
When you access the Service, we automatically collect:
- Log Data: IP address, browser type and version, device information, pages visited, access times, and referring URLs.
- Usage Data: Information about how you interact with the Service, including features used, search queries, and navigation patterns.
Cookies and Tracking Technologies
We use the following cookies and similar technologies:
- Session Cookies: We use a secure, HTTP-only session cookie to maintain your authenticated session. This cookie expires after 14 days of inactivity.
- Authentication Tokens: Firebase authentication tokens are stored in your browser to manage your login state.
- Analytics: We use Google Tag Manager to collect anonymous usage data, including page views and interaction events. This helps us understand how the Service is used and improve the user experience.
Publicly Available Data We Aggregate
CauseDB aggregates publicly available information about nonprofit organizations, including:
- Marketing and fundraising emails from nonprofit mailing lists that are publicly available for subscription
- Advertisements from public ad transparency libraries (Meta Ad Library and LinkedIn Ad Library)
- Organization information from publicly available sources, including IRS 990 filings via ProPublica
This publicly sourced data is not personal information of our users and is collected for research and transparency purposes.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Create and manage your account
- Process payments and manage subscriptions
- Send transactional communications, such as email verification, password resets, and account notifications
- Respond to your inquiries and support requests
- Monitor and analyze usage patterns to improve the Service
- Detect, prevent, and address fraud, abuse, and technical issues
- Comply with legal obligations
3. Third-Party Services
We use the following third-party services to operate the Service. Each has its own privacy policy governing the use of your information:
- Firebase (Google): User authentication, including email/password and Google OAuth sign-in.
- Google Cloud Platform: Database hosting (Cloud SQL), file storage (Cloud Storage), and infrastructure.
- Stripe: Payment processing for paid subscriptions. Stripe receives your email address and payment information to process transactions. See Stripe's privacy policy at stripe.com/privacy.
- Loops: Transactional email delivery (email verification, password resets) and contact management. Loops receives your email address, name, and subscription plan information.
- Google Tag Manager: Analytics and usage tracking to help us understand how the Service is used.
- Vercel: Web application hosting and deployment.
- Cloudflare: Content delivery, DDoS protection, and web security.
We also use the Meta Ad Library API and LinkedIn Ad Library API to retrieve publicly available advertisement data. These APIs are used to fetch public nonprofit ad data only and do not involve sharing user information.
4. Information Sharing
We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:
- Service Providers: We share information with the third-party services listed above, solely to the extent necessary for them to perform services on our behalf.
- Legal Requirements: We may disclose information if required to do so by law, or in response to valid legal process such as a subpoena, court order, or government request.
- Protection of Rights: We may disclose information when we believe it is necessary to protect the rights, property, or safety of CauseDB, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change via email or prominent notice on the Service.
5. Data Retention
We retain your account information for as long as your account is active or as needed to provide you with the Service. If you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal, accounting, or security purposes.
Aggregated nonprofit data (emails, advertisements, organization information) is retained indefinitely for research and archival purposes, as this data is sourced from public records and does not constitute personal information of our users.
Server log data, including domain-lookup requests made through the CauseDB Org Lookup browser extension, is retained for 30 days for security, abuse-prevention, and diagnostic purposes, after which it is deleted or aggregated.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit using TLS/SSL
- Encryption of data at rest
- Secure, HTTP-only session cookies
- Access controls limiting who can access user data
- Regular security reviews of our infrastructure
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct any inaccurate or incomplete information.
- Deletion: Request deletion of your account and associated personal data.
- Data Portability: Request your data in a structured, commonly used format.
- Restriction: Request that we restrict certain processing of your data.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
8. Account Deletion
You may delete your account at any time through your account settings. When you delete your account:
- Your personal information (email, profile data, collections, followed organizations) will be permanently removed within 30 days.
- Any active paid subscription will be cancelled.
- Your contact information will be removed from our email service provider.
- Authentication credentials will be deleted from our authentication provider.
You may also request account deletion by contacting us at [email protected].
9. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
- Right to Know: You have the right to request that we disclose what personal information we collect, use, and share about you.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. Because we do not sell personal information, there is no need to opt out.
The categories of personal information we collect are described in Section 1 and include internet or network activity information — specifically, the website hostnames read by the CauseDB Org Lookup browser extension as you browse, whether or not its side panel is open (see Section 12). We do not "sell" or "share" personal information as those terms are defined under California law.
To exercise your rights under the CCPA, contact us at [email protected].
10. International Users
The Service is intended for users in the United States and is hosted on servers located in the United States. If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States.
11. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe that a child under 13 has provided us with personal information, please contact us at [email protected].
12. Browser Extension (CauseDB Org Lookup)
We offer an optional Chrome browser extension, "CauseDB Org Lookup," that displays the public CauseDB profile and recent email previews for the nonprofit whose website you are viewing. It also marks its toolbar icon when the site you are on belongs to an organization in our database, so you can see whether there is anything to look at without opening the panel. The extension does not require an account and does not sign you in. Installing and using it is entirely optional. This section supplements the rest of this Policy.
Information the Extension Accesses
- Active-Tab Domain: As you browse, the extension reads the domain (hostname) of the website in your active browser tab — for example,
example.org. It reads this whether or not the side panel is open, because it uses the domain to decide whether to mark its toolbar icon as a match. It does not read the full page URL or path, the content of the pages you visit, form entries, keystrokes, your browsing history, or your bookmarks, and it injects no code into the sites you visit.
How the Extension Uses and Shares Information
- Domain Lookups: The extension sends the domain of your active tab to our servers (causedb.com) for two purposes. First, as you browse, it asks whether we have a matching organization at all; the answer is a simple yes or no, and is used only to mark the toolbar icon. Second, when you open the side panel, it retrieves that organization's public profile and recent email previews (subject, date, type, and thumbnail — the same non-sensitive information shown on our public website). If no organization matches, no profile is shown and the icon is not marked. To keep these requests to a minimum, the extension remembers the yes/no answer for a given domain for up to one hour, so moving between pages on the same site does not repeat the lookup. As with any request to our servers, these lookups include your IP address (used for rate-limiting and abuse prevention), as described in Section 1.
- No Account or Tokens: The extension does not sign you in, does not access any CauseDB account, and does not store authentication tokens or personal data on your device. Reading a nonprofit's full archived emails is free but requires a CauseDB account on our website; the extension only links you there.
- Purpose Limitation: We use domain information solely to provide the org-lookup feature. We do not use it for advertising, we do not sell it, and we do not share it with third parties except the infrastructure service providers listed in Section 3. Domain-lookup requests are otherwise processed subject to the log-data and retention practices described in this Policy.
Permissions
The extension requests the browser's tabs permission — which is what lets it read your active tab's address — along with permission to display a side panel and to communicate with causedb.com. The tabs permission is broader than the extension uses: our code only ever reads and transmits the hostname of your currently active tab, never the URLs of your other open tabs, and never for any other purpose. The extension requests no access to your browsing history, bookmarks, or the content of the pages you visit.
Limited Use
Our collection and use of information received through the extension complies with applicable browser-extension program requirements. We use this information only to provide and improve the org-lookup feature; we do not sell it, we do not transfer it except to the infrastructure providers in Section 3 or as required by law, we do not use it for advertising, we do not use it for any unrelated purpose, and we do not permit humans to read it except for security, to comply with law, or with your consent.
Availability
The CauseDB Org Lookup extension is intended for users in the United States. Where it is distributed through the Chrome Web Store, we limit its availability to the United States.
Your Control
The extension is optional. You can disable or remove it at any time from your browser's extensions settings.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any changes by posting the updated Privacy Policy on this page and updating the "Last updated" date above. For material changes, we may also provide notice via email to the address associated with your account. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact us at:
CauseDB, LLC
Email: [email protected]