Privacy Policy
Last updated: 10 September 2026
This policy explains how Element Software, trading as DonorPulse ("we", "us"), handles personal data. We are a company based in the United Kingdom. DonorPulse is a charity CRM, website builder, and donation platform.
Contact the data protection team at hello@donorpulse.uk.
Who is the controller?
- Visitors to donorpulse.uk (this marketing site) — Element Software is the controller.
- Charity staff accounts (sign-in, organisation settings, billing) — Element Software is the controller of account data needed to provide the service.
- Donor records and donationsstored in a charity's CRM or collected on a charity's donation site — the charity is the controller. DonorPulse is a processoracting on the charity's instructions.
What we collect
Marketing site (donorpulse.uk)
We collect technical data your browser sends (IP address, user agent, pages viewed) through our hosting provider (Vercel). If you consent to analytics cookies, we also collect usage data via Google Analytics 4 (GA4).
Product apps (auth, CRM, builder)
When you create an account we collect your name, email address, and organisation details, plus sign-in data from Google OAuth. We store plan, usage, and billing identifiers so we can enforce subscription caps and fees. If you consent, PostHog records product-usage events (for example signup, first donor, first donation, plan upgraded) in an EU-region project.
Donor and donation data
Charities may store donor names, emails, addresses, Gift Aid declarations, and donation amounts. Public checkout collects the details needed to take a payment and issue a receipt. DonorPulse processes this data only to provide the service the charity has configured.
Payments
Card details are handled by Stripe. We store Stripe customer, subscription, Connect account, and payment identifiers — not full card numbers.
Transactional email (invites, and receipts when that feature is enabled) is sent through Resend.
Lawful bases (UK GDPR)
- Contract — providing the SaaS, processing a checkout the donor started, and managing a paid subscription.
- Legitimate interests — keeping the service secure, preventing abuse, and understanding product reliability. We do not rely on legitimate interests to set analytics cookies.
- Consent — non-essential cookies (GA4 on this site; PostHog in the product apps). You can withdraw consent at any time via Cookie settings in the footer.
- Legal obligation — retaining records required for tax, accounting, and (where a charity is the controller) Gift Aid.
How long we keep data
- Analytics (GA4 / PostHog) — while consent remains in place, typically up to 14 months for marketing analytics unless you withdraw consent earlier.
- Staff accounts and organisation records — for the life of the account, then a short period needed to close the organisation.
- Billing and invoices — up to 7 years, as required for UK accounting.
- Donor PII— retained according to the charity's instructions and legal duties. Deleting an organisation removes its CRM records from DonorPulse systems, subject to backups that expire on a rolling schedule.
Processors
We use these processors. Each is limited to the purpose listed:
- Stripe — subscription billing (DonorPulse charging the organisation) and Connect destination charges (the organisation collecting donations).
- Google — staff/donor Google sign-in, and GA4 on the marketing site after consent.
- PostHog — product analytics in the CRM and builder after consent, configured for EU data residency because this product holds UK charity donor data.
- Resend — transactional email.
- Vercel — hosting and edge delivery.
- Neon — PostgreSQL database hosting in the UK/EU region we configure.
Your rights
Under UK GDPR you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent. Email hello@donorpulse.uk. You can also complain to the Information Commissioner's Office.
If you are a donor, contact the charity you donated to first — they are the controller of your donor record. We will support them in responding.
International transfers
Some processors (for example Google and Stripe) may process data outside the UK. Where that happens we rely on the UK International Data Transfer Agreement / addendum or an adequacy decision.
Changes
We will update this page when our practices change. The date at the top is the latest version. Related: Cookie Policy and Terms of Service.