Your data, and how we handle it.
Ovrture works inside a three-party relationship: your institution, your donors and prospects, and Ovrture as the platform. This policy explains what each party's data we collect, how we use it, and the rights you and your donors hold.
- We process data; your institution controls and directs it.
- Data encrypted at rest and in transit.
- Tracking can be disabled by request.
- Donor data never sold or used to market Ovrture.
- GDPR/CCPA rights apply.
Who this policy applies to.
Ovrture is a cloud platform that builds a personalized website for every major donor, so an institution's advancement team can make the case for a gift and report its impact one donor at a time. We serve advancement teams at universities, healthcare systems, and cultural institutions.
Three parties sit inside that work, and this policy speaks to each of them:
- Your institution, the client: the university, hospital, museum, or other nonprofit that subscribes to Ovrture and controls its donor data.
- Your donors and prospects: the individuals who receive a personalized website your institution builds through the platform.
- Ovrture: the technology platform, acting as a data processor.
Your institution owns and controls its donor data. Ovrture handles it only as your institution directs, and only to deliver the services you have contracted.
This policy explains
- How we collect and use information about platform users, your advancement team's own members.
- How we process donor data on your institution's behalf.
- What data Ovrture collects for platform operation and improvement.
- Your rights as a platform user, and a donor's rights when viewing a personalized site.
What information we collect.
Platform users: your advancement team
When your institution's staff use Ovrture, we collect account and authentication data, and platform usage data.
Account and authentication
- Name, email address, and job title.
- Institution name and department.
- Login credentials and authentication information.
- User role and permission level.
Platform usage
- Personalized website creation and editing activity.
- Content uploaded and templates used.
- Frequency and pattern of platform access.
- Feature usage and workflow patterns.
Support and training
- Support requests and help desk interactions.
- Training session participation.
- Feedback and feature requests.
Donor data, processed on your institution's behalf
When your institution builds a personalized website for a donor, Ovrture processes the donor information your institution provides.
Donor profile
- Name and contact information.
- Giving history and capacity indicators.
- Areas of philanthropic interest.
- Relationship to your institution: alumnus, parent, board member, grateful patient, and similar.
Engagement
- When a donor accesses their personalized site.
- Which content sections they view, and for how long.
- Downloads, video views, and interactive engagement.
- Survey responses submitted through the platform.
CRM integration
- Data synchronized from Blackbaud (including Raiser's Edge NXT) or another connected CRM your institution uses.
- Wealth screening information your institution chooses to sync.
- Solicitation stage and assigned fundraiser.
- Gift proposals and stewardship communications.
Your institution determines what donor data is loaded into Ovrture. We process it only as your institution directs and as your data processing agreement with us describes.
What a visitor sends us from ovrture.com
- Booking a demo: your name, email address, the time you choose, and anything else you enter in the booking form. Cal.com runs the scheduler and sends the booking to our team.
- Asking for a quote on the Pricing page: your email address, your number of internal users, and your number of reports a year. The request goes to our team in Slack.
Collected automatically, from every visitor
This is separate from what an institution, a donor or a visitor provides: it covers ovrture.com traffic and how the platform itself performs, in two categories.
Website analytics
- Browser type, device type, and operating system.
- IP address, anonymized.
- Pages visited on ovrture.com and referral sources.
- How a visitor uses each page: clicks, taps and scrolling, recorded by Microsoft Clarity. Clarity does not record what a visitor types into a form.
- Whether a visit came from one of our Google ads.
Platform performance
- Page load times and technical performance.
- Error logs and system diagnostics.
- Feature usage patterns, aggregated across users, not tied to one person.
How we use the information we collect.
Platform user data
- Providing access to the platform and authenticating users.
- Processing your institution's donor engagement work.
- Delivering updates and new features, and understanding how institutions use them.
- Customer support, training, and onboarding.
- Detecting and preventing unauthorized access, and meeting legal and regulatory obligations.
Donor data, on your institution's behalf
Ovrture processes donor data only to deliver the services your institution has contracted:
- Generating a personalized website from your content and the donor's profile.
- Personalizing proposals and stewardship communications.
- Tracking when a donor engages, and with what, to report back to your team.
- Synchronizing donor data and engagement metrics between your CRM and Ovrture.
Ovrture does not use donor data for any purpose beyond delivering services to your institution. We do not use it to market Ovrture to other institutions, share it with third parties, or aggregate it across clients.
The third-party vendors we use.
Delivering the platform means working with a small set of technology partners. Each reaches platform or donor data only to the extent its job requires, and every one is contractually held to security standards at least as strict as ours.
- Amazon Web Services (AWS), cloud hosting and data storage, with geographic redundancy and automated backup. Ovrture deploys in the AWS region your institution requires, with defined geographic residency available on request. Audited under our SOC 2 Type 2 examination. AWS Privacy Notice.
- Blackbaud, including Raiser's Edge NXT, for CRM integration. Data flows are encrypted and limited to the fields your institution authorizes.
- Wistia, video hosting for content embedded in personalized donor sites.
- Cloudinary, image and media hosting and processing for personalized site content.
- api2pdf.com, PDF generation for platform reports and exports.
- Mouseflow, session analytics on personalized donor sites; see Cookies below for what this tracks and how to opt out.
- Google Analytics, website traffic on ovrture.com only, never on a donor's personalized site. Anonymized visitor data. Google's privacy policy.
- Microsoft Clarity, on ovrture.com, shows us how visitors use each page (clicks, taps and scrolling) so we can improve the site. Form entries are not recorded. Microsoft's privacy statement.
- Google Ads, on ovrture.com, measures whether visits from our ads lead to demo requests. How Google uses information from sites or apps that use its services.
- Google Tag Manager loads Google Analytics, Microsoft Clarity and Google Ads on ovrture.com.
- Cal.com, the scheduler on the Book a demo page. It receives what you enter to book a demo and sends the booking to our team. Cal.com's privacy policy.
- Slack, where our team receives quote requests sent from the Pricing page. Slack's privacy policy.
- Amazon Simple Email Service, transactional platform email: password resets and system alerts. Not used for institution-to-donor communications, which your institution manages separately.
- A third-party payment processor, for platform subscription billing. Ovrture never stores your credit card information.
How CRM integration works
Ovrture connects to your institution's CRM to pull donor data in, constituent records, giving history, relationship information, and any custom field you choose to sync, and to push engagement data back: when a donor visits, what they engaged with, and any survey response they gave.
All transfers are encrypted in transit at TLS 1.2 or higher and scoped to only the fields your institution authorizes. Every synchronization event is logged for security review.
Your institution decides which records sync, which fields Ovrture can reach, and when synchronization runs: real time, daily, or manual. You can disconnect the integration at any time.
What donors experience, and what we track.
Each donor receives a unique URL and passcode from your institution. The personalized site is accessible only to the intended recipient, and no account or login is required.
What we track
- When the donor accesses their site, and which sections they view.
- How long they spend on each section, and what they download.
- Survey responses they choose to provide.
What we do not track
- Anything beyond what your institution provides.
- A donor's activity on other websites.
- Precise location: we hold city and region level only.
- Device identifiers or fingerprinting.
A donor's choices
A donor can decline a personalized site simply by not accessing it. To remove their information, correct it, or stop future personalized communications, a donor contacts your institution directly, not Ovrture: your institution is the data controller and the one who can act on the request. If a donor cannot reach your institution, contact@ovrture.com will help connect them.
How long we keep data.
Platform user data
Account information and usage data are retained for the length of your subscription, plus 90 days to support renewal or transition.
When an account is canceled
- All personalized sites are deactivated within 24 hours.
- Donor data is deleted within 90 days, unless your institution requests an export.
- Institution account information is kept for legal and financial records, 5 years.
Engagement analytics
Donor engagement data is retained in active form while a site is live, and in aggregated and anonymized form indefinitely for platform improvement. Your institution can request deletion of specific engagement data at any time.
How we protect platform and donor data.
Ovrture's fuller security posture, including our SOC 2 Type 2 examination and the controls behind it, is documented on our Security page. What follows here is the summary specific to how we protect the data this policy covers.
Infrastructure
- Data encrypted at rest, AES-256, and in transit, TLS 1.2 or higher.
- Regular security audits and penetration testing.
- Distributed denial-of-service protection.
- Automated backup with geographic redundancy.
Access
- Multi-factor authentication for platform users.
- Role-based access controls, limiting data access by job function.
- A unique, passcode-protected URL for each donor's personalized site.
- Session management, automatic timeout, and audit logging of data access.
Application and operations
- Regular patching, code review, and vulnerability scanning.
- Web application firewall protection and input validation.
- Employee background checks, security training, and confidentiality agreements.
- Least-privilege access: staff reach only what their role requires.
If a breach occurs
We contain the incident immediately, notify affected institutions through the channels described in your agreement with us, assist with any regulatory notification your institution owes under GDPR, CCPA, or another applicable law, and correct the underlying cause.
Your rights, and how to use them.
Platform users
As an authorized user of Ovrture at your institution, you can access the personal data we hold about you, correct your profile, delete your account with your institution's authorization, export your usage data, and opt out of non-essential communications. Reach your institution's Ovrture administrator, or contact@ovrture.com.
Donors viewing a personalized site
Ovrture processes your data on behalf of the institution that built your personalized site. Your institution is the data controller responsible for it. You can ask to know what information your institution has shared with us, ask your institution to correct it, ask for your site and its data to be removed, and decline to access personalized communications sent to you.
Contact the institution that sent you the site: they are identified in your access email and the site's own branding. If you cannot reach them, contact@ovrture.com will help.
If you are in the European Union
Under the General Data Protection Regulation, you additionally hold the right to data portability, the right to restrict or object to processing based on legitimate interests, the right to withdraw consent, and the right to lodge a complaint with your supervisory authority.
If you are a California resident
Under the California Consumer Privacy Act, you hold the right to know what personal information is collected, used, and shared, the right to delete it, subject to legal exceptions, the right to opt out of a sale of personal information (Ovrture does not sell personal data), and the right to non-discrimination for exercising these rights. Platform users reach contact@ovrture.com; donors reach the institution that sent them their personalized site.
Your institution's responsibilities.
Ovrture processes donor data as directed. Your institution remains responsible for the decisions that direct it:
- Obtaining appropriate donor consent, and honoring opt-out requests and privacy preferences.
- Keeping donor data accurate, and removing records for deceased individuals or those who ask to be removed.
- Using Ovrture only for donor engagement, and keeping unrelated data, student records, patient medical information, out of it.
- Managing who on your team has access, and protecting login credentials and passcodes.
- Reporting a suspected security incident to Ovrture support.
To help you meet those obligations, we provide a data processing agreement template, data export on request, audit logs and access reports, and training on privacy and security practice.
Some healthcare clients use Ovrture to engage grateful patients. Ovrture does not process protected health information and is not subject to HIPAA. Keep clinical and diagnostic information out of the platform. If you're unsure whether a use case is appropriate for the platform, contact us to talk it through before you begin.
Children's privacy, policy changes, and contact information.
Children's privacy
Ovrture is built for major donor engagement with adults who hold significant giving capacity, and it is not directed to anyone under 18. We do not knowingly collect a minor's personal information. If a minor's information reaches the platform, an institution can remove the record directly, and a parent or guardian can contact the sending institution or contact@ovrture.com, and we will help remove it promptly.
Changes to this policy
A minor update, a clarification or an added example, shows up as a new "Last updated" date at the top of this page. A material change, a new data use, a new subprocessor, or a change to your rights, brings an email to institution administrators and a 30-day notice before it takes effect. A change significant enough to affect how donor data is processed goes to every institutional client directly, with the option to object, terminate, or export data before it takes effect.
Contact
Institutional clients and platform users: contact@ovrture.com, subject line "Privacy Request, [Your Institution Name]." Donors: contact the institution that sent your personalized site; if you cannot reach them, contact@ovrture.com will help connect you. General support: support@ovrture.com.
Ovrture, Inc.Post Office Box 1139
State College, PA 16804-1139
Foster Avenue
Ovrture and Foster Avenue are separate legal entities in a strategic partnership. Many institutions engage both, Foster Avenue for campaign strategy and creative, Ovrture for digital donor engagement, each under its own contract. Data moves between the two companies only with an institution's explicit authorization, and each maintains its own privacy policy: this one governs Ovrture's platform, and Foster Avenue's own policy governs its consulting services.
Frequently asked questions.
What is the relationship between Ovrture, my institution, and my donors?
Your institution subscribes to Ovrture and controls every decision about donor data: what is shared, which donors receive a personalized site, and when a site is created or removed. Ovrture processes donor data only as your institution directs. A donor has no direct relationship with Ovrture, and any privacy request from a donor goes to your institution first.
What donor information does Ovrture actually process?
Only what your institution provides: name, contact information, giving history, philanthropic interests, and relationship to your institution, plus the engagement your donor generates by using the site. We do not collect anything beyond that.
Is donor data secure on the platform?
Ovrture is examined annually under SOC 2 Type 2 and runs encryption at rest and in transit, multi-factor authentication for staff, and a passcode-protected, unique URL for every donor site, not indexed by search engines and logged for your institution's own review.
What happens to donor data if we cancel our subscription?
Every personalized site deactivates immediately. Within 90 days all donor data is permanently deleted unless you request an export first.
Can a donor opt out of a personalized site?
Yes, simply by not accessing it. Since your institution sends the link and passcode directly, a donor who declines to engage never has to. To stop future communications altogether, they contact your institution's advancement office.
Does Ovrture ever use our donor data for its own purposes?
No. We process donor data only to deliver your institution's own platform services. We never use it to market Ovrture, share it with a third party, or combine it with another institution's data.
Questions before you sign?
Book a demo, and bring your security or privacy reviewer along. We can answer it now, before a contract is signed.