Tallyside
Privacy Policy
Last updated 21 August 2026
1. Who we are, and who controls your data
Tallyside is membership, participation and impact software used by nonprofit organizations. When an organization uses Tallyside, that organization decides what data it collects about its members and participants and why. Tallyside stores and processes it on their behalf. In data-protection terms the organization is the controller and Tallyside is the processor.
This matters in practice: if you want a record corrected or want to know why something was recorded, your organization is usually the right place to ask. If they cannot help, or your question is about Tallyside itself, write to privacy@tallyside.com.
2. What we collect
Your account. Your name, email address and — if you provide one — your phone number. A password, if you set one; sign-in links are the alternative and no password is required.
Your profile, if you fill it in. A headline, biography, occupation, employer, industry, education, city and region, links such as LinkedIn, what you are open to (mentoring, hiring, board service and similar), and a photograph. All of it is optional, and you choose whether it is visible to your whole organization, to coordinators only, or to nobody.
Participation. Which shifts and events you signed up for, whether you attended, when you checked in and out, the hours credited to you, and any activity you logged yourself.
Check-in evidence. When you check in, we record how it was verified — a kiosk QR code, a scan, a geofence, NFC, or a manual entry by a coordinator. Where a check-in used location, we store the coordinates, the accuracy radius, whether the device reported a mock location, and a device fingerprint. Location is recorded at the moment of a check-in; Tallyside does not track your location in the background.
Giving. If you donate, we record the amount, the date, the fund and the processor’s fee. Card details never reach Tallyside — payments happen in your browser through Stripe, and we receive only the result.
Records the organization creates about you. Roles, team membership, training and background-check status where the organization requires them, and — in mentoring programmes — session notes and safeguarding records.
Technical. Server logs and the timestamps our servers record. The server timestamps everything: we do not trust a device’s clock or its claimed location as fact.
3. What we do not collect
We do not collect payment card numbers, bank details or government identifiers. We do not buy data about you from third parties, we do not sell your data, and we do not use it for advertising or share it with advertising networks.
Tallyside runs no advertising trackers and takes part in no advertising networks. We do use one product-analytics service, PostHog, and it is deliberately limited: it records which screens are used and events we chose to send, and it is configured not to record what you click, not to capture the text on the page, and not to replay your session. Addresses are stripped of anything identifying before they are sent — a page about a particular person is reported as a participant page, never as which participant.
4. Why we use it
To run the service you or your organization asked for: showing opportunities, taking signups, recording attendance and hours, producing the reports an organization needs, sending reminders about shifts you signed up for, and processing donations.
Organizations report hours to funders. Where hours are given a monetary value for that reporting, the rate used is stored alongside the record with the year it applies to, so a later rate change does not silently rewrite past reports.
We use it to keep the service secure and to investigate abuse, and to meet legal obligations.
5. Who it is shared with
Your organization. Coordinators and administrators of an organization you belong to can see your participation in it, and your profile subject to the visibility you chose.
Other organizations cannot see you. If you belong to more than one, each sees only its own records. This is enforced in the database itself rather than by the application, so a mistake in a screen cannot expose another organization’s data.
Service providers we actually use, and what each one holds:
- Supabase — the database, authentication and file storage. All of the above is stored here.
- Vercel — hosts the web application and runs scheduled jobs.
- Cloudflare — domain name service and email routing.
- Resend — sends transactional email such as sign-in links, shift reminders and scheduled reports. Receives your email address and the message.
- Stripe — processes donations in your browser. Stripe receives your payment details directly; Tallyside does not.
- Expo — delivers push notifications to the mobile app. Receives the device’s push token and the text of the notification. It receives nothing until you install the app and allow notifications.
- Sentry — error reporting, so a fault can be fixed rather than waiting for somebody to describe it. Receives the error, the page it happened on and the browser or device type. It is configured not to send personal details, and query strings are stripped from every address it reports, because that is where identifiers travel. It records nothing of what is on screen.
- PostHog — product analytics, so we can see which parts of Tallyside are actually used. Receives the screen you visited with identifiers removed, and events we deliberately send. It does not receive your name, your email, your IP address, what you typed, or a recording of your screen.
We share data when the law requires it, and if Tallyside were ever acquired, data would transfer with the same commitments and you would be told.
6. How long it is kept, and what survives deletion
Your account and the personal details in it are kept while your account exists. When you delete it, they are removed — see Delete your account for how, and for the thirty-day window in which you can change your mind.
Some records are deliberately kept after your account is deleted, with your identity removed. Specifically: attendance records, credited hours and their reported value, donations, and safeguarding records.
Why. These are the organization’s records of what happened rather than your personal data about yourself. Grant-funded programmes are audited against them, and an organization that could not evidence hours it has already reported would be unable to meet obligations it has taken on. Safeguarding records exist to protect people, and a child-protection record must not disappear because an adult closed an account. Attendance records are append-only by design: a correction adds a new record referencing the original, with who made it and why, and nothing is overwritten.
After deletion these records no longer name you and are not linked to you. Where an audit trail must record that somebody did something, it keeps the role rather than the person.
We tell you this here, and again on the deletion screen itself before you confirm, because retaining records without disclosing it would not be acceptable — and because you should be able to make the decision with the specifics in front of you.
7. Children and young people
Tallyside is used by programmes that serve minors, and it deliberately holds data about them. Mentoring and youth programmes are among its main uses, so saying that we do not collect data about children would be untrue.
Where an organization enrols a young person as a participant, it may record their name and preferred name, date of birth, whether they are a minor, the programme and group they belong to, attendance, and notes from mentoring sessions. Session notes and safeguarding records can contain sensitive detail about a young person’s circumstances.
The organization is responsible for obtaining consent from a parent or guardian before enrolling a young person, and Tallyside records that consent, its scope, when it was given, how, and when it expires. Consent can be withdrawn, and the withdrawal is recorded.
A guardian relationship is asserted by the organization, never self-claimed. Recording one is a coordinator’s job and grants no access by itself; an administrator must verify it before it grants anything. A verified guardian can see the young person’s shifts, times and attendance.
A verified guardian cannot read session notes. This is deliberate: a note may record a concern about the home, and the person a concern is about must not be able to read it.
An adult who has not been screened is never matched one-to-one with a child. A mentoring match cannot become active unless the adult’s background check is clear and unexpired and any required training is complete. This is enforced in the database, not merely checked in a screen, and lapsed clearances are surfaced rather than assumed to still hold.
A young person’s record does not require an account, and a young person who does hold one has the same rights described below. Requests about a minor’s data should go to the organization; where that is not possible, write to privacy@tallyside.com.
8. Your rights
You can see and correct your own profile at any time, and choose who it is visible to. You can export your data, and you can delete your account.
Depending on where you live you may also have rights to a copy of your data, to correction, to deletion, to restrict or object to processing, and to complain to a regulator. Ask your organization first, since they decide what is collected; or write to us.
Where a right cannot be fully met, we will say so and why rather than confirm a deletion that did not happen. The retention described in §6 is the main case, and it is a recognised limit rather than an exception we invented.
We do not discriminate against you for exercising any of these rights.
9. Security
Data is separated by organization in the database itself, and every table carrying organization data is covered by an automated test that attempts to read it across organizations and fails the build if it succeeds.
Access within an organization is by role. Sensitive records — safeguarding notes in particular — are restricted further than ordinary membership data. Sessions on mobile devices are stored in the device’s secure keychain rather than ordinary storage.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your data we will tell affected organizations and, where required, individuals and regulators.
10. Where data is held
Data is stored in the United States. Tallyside currently serves organizations in the United States. If you are accessing it from elsewhere, your data is transferred to and processed in the United States.
11. Changes
We will update this policy as the product changes — several sections describe behaviour that exists today and would otherwise go quietly out of date. Material changes will be notified to organizations rather than only posted here, and the date at the top always reflects the current version.
12. Contact
Questions, requests and complaints: privacy@tallyside.com.
See also Terms of Service and Delete your account.