Organization Portal & Gather Privacy Policy

Effective Date: June 18, 2026
Last Updated: July 11, 2026
Version: 1.1

Our Circle, Inc., an Illinois nonprofit corporation (“Our Circle,” “we,” “us,” or “our”), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard the personal information of organization administrators and staff (“Authorized Administrators,” “you”) who use the Our Circle Organization Portal (the “Portal,” at portal.ourcircle.org) and the Gather by Our Circle mobile application (“Gather,” and together with the Portal, the “Services”).
This is not the consumer Privacy Policy. If you are a parent or caregiver using the Our Circle mobile app, your information is handled under the consumer Privacy Policy, not this one.
Not a HIPAA Covered Entity: Our Circle is not a healthcare provider or HIPAA covered entity, and the Services are community-engagement tools, not tools for medical care or protected health information.

1. Scope & Who This Covers

  • Applies to: Authorized Administrators who access the Portal (web) and Gather (iOS/Android) to manage their Organization’s groups, events, Members, and community content, and individuals who submit our organization access-request form.
  • Audience: The Services are for adults aged 18+ acting in a professional or organizational capacity. They are not directed to children.
  • Does not replace the consumer Privacy Policy: Families and Members (parents and caregivers) who use the Our Circle mobile app are covered by the consumer Privacy Policy.
  • Dual-role accounts: One Our Circle login can hold both a parent role in the consumer app and an Authorized Administrator role in the Services. Information collected about you in your parent capacity is governed by the consumer Privacy Policy; this Policy governs your administrator capacity in the Portal and Gather, even when the same login is used for both.
  • Member Data you view as an administrator is the personal information of families, handled under the consumer Privacy Policy and the Our Circle Organization Subscription Agreement—not under this Policy. This Policy is about your information as an Authorized Administrator. See Section 8.
  • Relationship to the Subscription Agreement: This Policy, published at ourcircle.org/gather-privacy-policy, is the Privacy Policy referenced by the Our Circle Organization Subscription Agreement between Our Circle and your Organization, as amended from time to time. Family and Member information is handed off to the consumer Privacy Policy as described in Section 8.

2. Information We Collect

2.1 Information You or Your Organization Provide

  • Account & profile: Name and display name, email address, the organization(s) you represent, your assigned role, and your account status. Accounts are created for you by your Organization or by Our Circle with a temporary password—there is no self-signup.
  • Authentication: Your mobile phone number for SMS-based multi-factor authentication (MFA), and backup codes, which we store only as secure one-way hashes.
  • Organization content: Content you submit through the Services, such as group names and photos, event details, announcements, posts, comments, group resources and files (such as PDFs), messages with Members, and photos and videos you upload.
  • Support requests: The subject, category, and message of support requests you send us, along with any screenshots you choose to attach.
  • Application information: If you submit our public access-request form on behalf of a prospective organization, we collect the organization’s details together with your contact name, email address, optional phone number, and role.
  • Notification preferences: Your per-category notification settings, delivery frequency, and channel choices.
  • Billing acceptance and agreement records: When a super administrator accepts the Subscription Agreement during checkout, we record the acceptance timestamp, the accepting account, the version of the agreement accepted, and the IP address of the acceptance. When an Organization instead enters into the Subscription Agreement by signing a written order form, we retain a copy of the signed agreement, including the signer’s name, title, signature, and date of signing.

2.2 Information Collected Automatically

  • Device & log data: IP address, browser and device type, operating system and version, app or browser version, language and time zone, timestamps, and the pages and actions you use in the Services.
  • Identifiers & tokens: Firebase authentication tokens (kept in your browser’s or device’s local storage while you are signed in); server-side session records (refreshed during use and expiring after 7 days of inactivity); and—in Gather only—a push-notification token (FCM) together with your device platform, which is invalidated when you sign out.
  • Security signals: Firebase App Check device and app-integrity attestation—reCAPTCHA Enterprise on the web, and Google Play Integrity or Apple App Attest on mobile. On the web, Google receives browser and device signals and your IP address for risk scoring on every session; on mobile, Google (Play Integrity) or Apple (App Attest) receives device-integrity signals.
  • Audit logs: A record of administrative actions (for example, sign-ins, team changes, invites, posts, MFA events, and billing actions) with timestamps and, where available, IP address and browser user agent, retained for security and accountability.
  • Crash & diagnostics (Gather only): Crash reports, performance data, device model, operating system, app version, IP address, and sampled session replays (with on-screen text and images masked by default), collected through Sentry. The web Portal contains no analytics or crash-reporting SDKs.
  • What we do not collect: Device GPS or precise location; your contacts; advertising identifiers; biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act; or payment card numbers (payment details are entered directly with Stripe).

3. How We Use Information

  • Provide the Services: Authenticate you, secure your account (including MFA), and operate the Portal and Gather administrative tools.
  • Communications: Send service emails and, if you use Gather and enable them, push notifications about account activity, security, and important updates. We also send notification emails and daily or weekly digest emails according to your preferences; digests may include excerpts of platform activity (see Section 7).
  • Billing & subscriptions: Administer your Organization’s subscription and any sponsored family memberships under the Subscription Agreement through our payment processor (Stripe). We do not store complete payment card numbers.
  • Safety, security & fraud prevention: Verify legitimate access, maintain audit trails, detect and prevent abuse, and enforce our Terms and policies.
  • Content moderation: Review posts, comments, and uploaded media through automated systems—including a third-party artificial-intelligence provider—and through human review.
  • Support: Respond to your requests and troubleshoot issues.
  • Diagnostics & improvement: Diagnose crashes and errors, fix bugs, improve performance, and develop new features.
  • Legal compliance: Comply with applicable laws and respond to lawful requests.

4. Support Access & Account Impersonation

For support, security, or troubleshooting purposes, Our Circle platform administrators may access or sign in to an Authorized Administrator’s account using a time-limited support session (approximately 60 minutes). Support sessions can be initiated only by verified Our Circle platform administrators, display a visible banner while active, cannot be used to access other platform administrators’ accounts, and are recorded in our audit logs—including the acting administrator, the target account, the timestamp, and, where available, IP address and browser user agent.

5. Cookies, Local Storage & Tracking

  • Portal (web): The Portal sets no advertising or analytics cookies. Our application code uses browser local storage and session storage for essential functions only: your authentication session (managed by Firebase), your last-selected organization and group, and dismissed help messages. Google reCAPTCHA Enterprise and Firebase App Check run for abuse prevention and may set their own identifiers.
  • Gather (mobile): The app uses mobile SDKs for authentication, push messaging, app integrity, and crash diagnostics.
  • No advertising or cross-site tracking: We do not use advertising SDKs, do not engage in cross-site tracking, and never use your data for targeted advertising or retargeting.
  • Do Not Track / Global Privacy Control: Because we do not engage in cross-site tracking and do not sell personal information or share it for cross-context behavioral advertising, the Services do not respond differently to Do Not Track or Global Privacy Control browser signals.

6. Third-Party Services We Use

We share information with service providers who process data on our behalf, strictly for the purposes described below. These service providers act under contracts that limit their use of your information to providing services to us and require them to protect it with safeguards at least as protective as those described in this Policy. Apple and Google, where they act as app-store, push-notification, or device-attestation platforms, process certain data under their own privacy policies, linked below:

  • Google (Firebase & Google Cloud): Authentication (including delivery of SMS MFA codes), database, file storage, hosting, serverless computing, push messaging for Gather, app-integrity attestation (App Check), and configuration, in US data centers. Privacy & Security
  • Render: Hosts our API services (api.ourcircle.org) in the United States (Ohio) and processes requests to the Services, including authentication tokens and request content. Privacy Policy
  • Mailgun (Sinch): Delivers our service, notification, and digest emails. Privacy Policy
  • Stripe: Subscription billing and payment processing. Payment details are entered directly with Stripe; Stripe receives your Organization’s name and billing email address, not individual administrator profiles. Privacy Policy
  • Cloudflare: Hosting and delivery of uploaded images and videos. Privacy Policy
  • Sentry: Crash and performance diagnostics for Gather and error monitoring for our API. Privacy Policy
  • OpenAI: Automated content-moderation review of posts, comments, and uploaded media. Privacy Policy
  • Google reCAPTCHA Enterprise: Abuse and bot prevention on the Portal. Privacy Policy
  • Apple & Google: Distribution of the Gather mobile app and delivery of push notifications (APNs/FCM). AppleGoogle

7. How We Share Information

  • No selling of personal information: We do not sell or rent your personal information.
  • Service providers: We share data with the vendors listed above to operate and improve the Services under contracts that limit their use of your data.
  • Within your Organization and with Members: Your name or display name is visible to Members on community posts you publish and in messages you send; posts and events are presented under your Organization’s or group’s name and image, not a personal photo of you. Your name, role, contact details, and activity are visible to other administrators of your Organization.
  • Notification & digest emails: Notification and digest emails sent to you contain excerpts of platform activity, which may include Members’ names and content excerpts. Handle those emails in accordance with your Member Data obligations in the Organization Portal & Gather Terms of Use.
  • Aggregated or de-identified data: We may create and use aggregated or de-identified data (for example, for impact and grant reporting or benchmarking) that does not identify you, your Organization, or any Member. We maintain and use such data only in de-identified form and do not attempt to re-identify it.
  • No advertising sharing: We do not share personal information for cross-context behavioral advertising and do not use it for targeted advertising.
  • Legal and safety: We may disclose information if required by law or to protect the rights, safety, and integrity of our users and the Services.
  • Business transfers: In a merger, acquisition, or asset sale, information may be transferred subject to this Policy.

8. Member Data You Access as an Administrator

When you act as an Authorized Administrator, you can view limited information about families in your groups: a Member’s display name, profile photo, account email address, general location (city and state), join date and how the Member joined (including any invite code used), engagement summary (such as counts of posts and comments, and RSVP responses to your Organization’s events), and any badges your Organization assigns. Administrators do not receive children’s profiles, support-needs details, Member phone numbers, precise location, or Members’ private family-to-family messages. That Member Data is the personal information of families and is governed by the consumer Privacy Policy and the data-handling terms of the Our Circle Organization Subscription Agreement, not by this Policy. Your obligations when handling Member Data—including confidentiality and use restrictions—are set out in the Organization Portal & Gather Terms of Use. When a Member leaves a group, their membership record is removed and their profile is no longer visible to your Organization; you may not retain their Member Data (see the Terms of Use).

9. Data Retention

  • Account & profile data: Retained while your account is active. When you are removed from an Organization, that Organization’s access is revoked; when you are removed from your last (or only) Organization, your account is deactivated and the record is retained until a deletion request is received and processed (see Section 13).
  • MFA phone number: Retained while MFA is enrolled on your account and removed when MFA is removed from your account by Our Circle or your Organization, or upon a deletion request.
  • Gather push token: Invalidated when you sign out.
  • Audit logs, session records, acceptance and signed-agreement records, support tickets, and access-request applications: Retained for as long as necessary for security, dispute-resolution, legal, and compliance purposes.
  • Billing records: Retained as required for tax, audit, and legal purposes. Stripe also retains billing records under its own policy.
  • Digest queue items: Deleted after the digest email is sent.
  • Content you posted for your Organization: Retained according to your Organization’s direction and the Subscription Agreement.

10. Security

  • Protections: Encryption in transit, secure cloud infrastructure, strict access controls, App Check, audit logging, EXIF stripping for uploaded images, and regular monitoring.
  • Multi-factor authentication: SMS-based MFA is required to protect access to the Services, and MFA backup codes are stored only as one-way hashes.
  • Limitations: No method of transmission or storage is 100% secure. Use a strong, unique password, keep MFA enabled, and keep your device updated.

If we become aware of a data incident affecting your information, we will provide notices as required by law and may temporarily restrict features to protect users.

11. Your Rights & Choices

We provide the following rights and protections as best practices for all Authorized Administrators, regardless of location:

  • Access & portability: Request a copy of your data.
  • Correction & deletion: Update your information or request deletion of your account and data. Note that some account information is controlled by your Organization, and certain records (such as audit logs and billing records) may be retained as required for security, compliance, or legal purposes.
  • Preferences: Manage notification preferences in the Services and in your device settings.
  • Cookies & storage: Control cookies and local storage via your browser and device settings.

To exercise your rights, email privacy@ourcircle.org or submit a support request within the Portal or Gather. We may request information to verify your identity. We aim to respond within 30 days, with one extension if needed for complex requests. If we decline a request, you may appeal by replying to our response or emailing privacy@ourcircle.org, and we will respond to your appeal.

12. US State Privacy Rights

To the extent applicable law grants you these rights, this section describes them and how to exercise them:

  • Categories of personal information we collect: Identifiers (such as name, email address, phone number, IP address, and device identifiers); professional or employment-related information (such as your organization affiliation and role); internet or other electronic network activity (such as log data, audit records, and your actions in the Services); audio-visual information (photos, videos, and files you upload); and sensitive personal information limited to account log-in credentials and security data (your password, MFA phone number, and hashed MFA backup codes). We do not generate inferences about you for profiling.
  • Sources: You, your Organization (which provisions your account), automatic collection when you use the Services, and our service providers.
  • Purposes: The business purposes described in Section 3.
  • Categories of recipients: The service providers listed in Section 6, and the other recipients described in Section 7.
  • No sale or sharing: We do not sell personal information and do not share it for cross-context behavioral advertising. We use and disclose sensitive personal information (account log-in credentials and security data) only to authenticate you and secure your account, and as otherwise permitted by applicable law.
  • Your rights: To know and access the personal information we hold about you, to correct inaccurate information, to request deletion, and to not be discriminated against for exercising these rights.
  • Authorized agents: You may use an authorized agent to submit a request on your behalf; we may require proof of the agent’s authority and verification of your identity.
  • How to exercise: Email privacy@ourcircle.org or submit a support request within the Portal or Gather. We will respond within the timeframes required by applicable law (generally within 45 days, with one extension where reasonably necessary).

13. Account & Data Deletion

Because administrator accounts are provisioned by Organizations, account deletion works as follows:

  • Removal by your Organization: Your Organization’s super administrator can remove you from the Organization, which revokes your access for that Organization. When you are removed from your last (or only) Organization, your account is deactivated.
  • Deletion request in Gather: In Gather, open the More menu and choose “Delete my account” to send a deletion request directly to us from within the app.
  • Deletion request without the app: Email privacy@ourcircle.org or submit a support request in the Portal.

We process deletion requests, subject to information we must retain for security, fraud-prevention, legal, or compliance reasons (such as audit and billing records), as described in Section 9.

14. Data Accuracy & Authority

Authorized Administrators are responsible for maintaining accurate account and Organization information and for ensuring they have the authority to act on behalf of their Organization.

15. Children’s Privacy & Health-Related Information

  • Adults only: The Services are intended for adults aged 18+ acting in an organizational capacity and are not directed to children. We do not knowingly collect personal information from children under 13 through the Portal or Gather.
  • Children’s information you may view: Information about Members’ children that you can view as an administrator is provided by parents through the consumer Our Circle app and is governed by the consumer Privacy Policy.
  • Health-related information: Member information may reveal health- or disability-related information about children. We never sell such information, never use it for targeted advertising, and never use it to train third-party AI models; content is shared with our AI moderation provider solely to review it for safety, as described in Sections 3 and 6.
  • Not for medical records: The Services are not intended for medical records—do not upload medical records or insurance information. We are not a covered entity or business associate under HIPAA; information on the platform is protected by this Policy and applicable consumer-privacy laws, not HIPAA.
  • No biometrics: We do not collect, capture, or store biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act.

16. International Data Transfers

Your information is stored and processed in the United States, including in Google Cloud US regions and at our API host in Ohio. If you access the Services from outside the United States, you understand and consent to your information being processed in the United States.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated policy here and, for material changes, provide additional notice (for example, in the Services or by email). The effective date and last-updated date are maintained at the top of this Policy.

18. Contact Us

For privacy questions or requests, contact us:

By using the Organization Portal or Gather, you acknowledge that you have read and understand this Privacy Policy.