Koolay

Privacy Policy

Last updated 2026-04-17 · Effective date 2026-04-17

Koolay Inc. ("Koolay", "we") operates the Koolay nonprofit management platform (the "Service"). This Policy explains what personal data we collect, how we use it, and the rights you have over it. By using the Service, you agree to this Policy.

1. Who we are

Koolay Inc. — a Delaware C-Corporation · 8 The Green STE D, Dover, DE 19901, USA · EIN 93-1609662 · Contact: [email protected].

We act as a Data Processor for personal data we handle on behalf of our nonprofit customers (the "Tenants") and as a Data Controller for data we collect from visitors to koolay.com and Tenant admins.

2. Data subjects

Tenant admins, end users of a Tenant's website (donors, members, event attendees, scholarship applicants, volunteers, newsletter subscribers, contact-form submitters), and marketing-site visitors.

3. Personal data we collect

3.1 Provided directly

CategoryExamples
IdentityName, email, phone
ContactMailing address, city, state, ZIP, country
AccountUsername, password hash, MFA secret
Financial (donors)Donation amount, Stripe payment token — we never store card numbers
Application dataScholarship applications, volunteer registrations, event registrations, membership records
CommunicationsEmails and messages
Marketing consentOpt-in status

3.2 Collected automatically

3.3 We do NOT collect

4. Why we use the data (lawful bases)

PurposeLawful basis (GDPR)
Provide and operate the ServiceContract (Art. 6(1)(b))
Process donations and receiptsContract + legitimate interest
Security, fraud prevention, audit logsLegitimate interest (Art. 6(1)(f))
Transactional emailsContract
Marketing / product emailsConsent (Art. 6(1)(a)) — opt-in
Tax, accounting, legal complianceLegal obligation (Art. 6(1)(c))

5. Who we share data with

We do not sell personal data. We share data with vendors under DPA to operate the Service. Current subprocessor list: koolay.com/subprocessors. Principal subprocessors: Supabase, Vercel, AWS (via Supabase/Vercel), Stripe, OpenAI, Anthropic, Elastic Email.

6. International transfers

Infrastructure is in the United States (AWS US-East-1). EU/UK personal data is transferred under Standard Contractual Clauses (SCCs). A copy of the SCCs is available in our DPA.

7. Retention

Data typeRetention
Account data (active Tenant)For as long as the account exists
Tenant data after account closure — on requestDeleted immediately via Admin → Settings → GDPR
Tenant data absent requestPurged 90 days after closure
Backups7–30 days (rolling)
Security audit logs12 months
Financial/tax records7 years (IRS)

8. Your rights

Tenant admins: self-service at Admin → Settings → GDPR.

End users of a Tenant: contact the Tenant directly; if no response, email [email protected].

California residents (CCPA/CPRA): rights to know, delete, correct, and opt out of sale/share. Koolay does not sell personal information.

9. Security

TLS 1.2+ in transit · AES-256 at rest · RLS tenant isolation · Encrypted secrets vault · Mandatory MFA for admin accounts · Audit logging · Least-privilege access. Full overview: Security.

10. Children's privacy

The Service is not directed to children under 13. We do not knowingly collect data from children under 13. Scholarship applicants aged 13–17 require parental/guardian consent per the Tenant's process.

11. Cookies

We use only strictly necessary cookies (authentication + UI preferences). No advertising, no cross-site trackers, no third-party analytics cookies.

12. Changes

Material changes are posted at this URL and admin email notification is sent at least 30 days before effect. Continued use after effective date constitutes acceptance.

13. Contact

[email protected] · Koolay Inc. · 8 The Green STE D, Dover, DE 19901, USA