OrgHQ

Association Platform

Privacy Policy

What we collect. Account emails, the content organizations publish, and the details members submit when they register, join, or send a message (name, email, organization). Payment card details go directly to Stripe — we never see or store them.

How it's used. To run the service: signing you in, processing registrations, sending the emails you'd expect (confirmations, reminders, receipts, newsletters with unsubscribe links). We don't sell personal data or use it for third-party advertising.

Who sees it. Each organization sees only its own members' data. Our infrastructure providers (hosting, database, email delivery, payments) process data on our behalf under their own security commitments.

Connected services (including Zoom). Organizations may connect their own accounts with services like Zoom, Stripe, and Resend. When an organization connects Zoom, we store its OAuth credentials encrypted (AES-256-GCM) and the details of meetings we create for its events (meeting ID, join link, passcode, dial-in numbers). After a meeting ends, we read Zoom's participant report (names and email addresses) once, solely to mark attendance against the event's own registration list — the report itself is not retained. Meetings we create are configured with cloud recording enabled, so the organization has a recording available in its own Zoom account for its members' on-demand library; the recording never leaves that Zoom account and is governed by the organization's own Zoom retention settings. We never access, download, or store recordings, transcripts, chat, or meeting content, and we never join meetings. Disconnecting Zoom in the organization's admin, or uninstalling the app from Zoom's side, deletes the stored credentials immediately.

Financial records. When an organization connects its Stripe account, we process its payment records (payer name and email, amounts, dates, and payment descriptions) to power its bookkeeping tools — recording dues and event revenue and, when the organization runs an import, summarizing its own Stripe payment history into its ledger. These records stay inside that organization's workspace, are used only for its own bookkeeping and reports, and are never sold or used for advertising. We do not collect bank account credentials or bank transaction data; if we ever add an optional bank feed, this policy will be updated first and the feature will be strictly opt-in.

This marketing site's analytics. On orghq.org itself (not on organizations' own sites) we measure our own traffic first-party — no Google Analytics, no advertising pixels, no third-party trackers. One cookie, oh_a, holds a random identifier so a visit that starts on a marketing page and ends at signup counts once instead of three times; it also decides which version of the home page you see when we're comparing two. We store that random id with the page path and time. We do not store IP addresses, user agents, names, or anything else that identifies you, and the id is never linked to your account or shared. Events older than 180 days are deleted automatically, and clearing your cookies resets the id. Because it is strictly first-party measurement with no personal data and no ad tracking, there is no consent banner.

Retention & deletion. Data is kept while the organization's workspace is active; deleting a workspace removes all of its data, including connected-service credentials. Ask an organization to remove your record, or contact us and we'll help.

Security. Traffic is encrypted in transit (TLS 1.2+), credentials are stored encrypted, and each organization's data is isolated.