Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how KINDRED GRANTS, LLC ("Kindred Grants," "we," "us," or "our") collects, uses, shares, and protects personal information when you use https://kindredgrantshq.com and the Kindred Grants application (the "Service").

Kindred Grants is a research tool for nonprofits. It helps you find grantmaking foundations by analyzing publicly filed IRS data. We are deliberately a low-data-collection product: we collect the minimum needed to run accounts, process subscriptions, and keep the Service working.

1. Information We Collect

Information you give us

WhatWhenWhy
Email addressAccount signupTo create and authenticate your account, and to send service and billing messages
PasswordAccount signupStored only as a salted cryptographic hash by our authentication provider; we never see or store your plaintext password
Organization name (optional)Account or profileTo personalize your account
Search inputs — cause area (NTEE code), state or ZIP code, and numeric filtersEach searchTo generate your results
Support messagesWhen you contact usTo respond to you

Information collected automatically

  • Log and technical data: IP address, browser type and version, device and operating system, referring page, pages viewed, and timestamps. Used for security, abuse prevention, and diagnosing problems.
  • Error and crash reports: When something breaks, our infrastructure provider captures the error, the route you were on, and technical context so we can fix it. These reports may incidentally include limited technical identifiers.
  • Analytics data: We use Google Analytics 4 to understand how the Service is used (pages viewed, route changes, and a small number of product events such as starting checkout or creating an account). Google Analytics sets its own cookies/identifiers and receives your truncated IP address, browser and device information, and the pages you view. We enable IP anonymization, and we do not send your email address, account ID, search inputs, or any other directly identifying information to Google Analytics.
  • Cookies and local storage: See Section 5.

Payment information

Subscription payments are processed by Stripe, Inc. Your card is entered directly into Stripe's checkout. We never receive or store your full card number, CVC, or expiration date.

What we do store is limited to: your Stripe customer ID, your Stripe subscription ID, subscription status, plan/price identifiers, the current billing period start and end dates, and whether the subscription is set to cancel. Stripe may collect additional information (including billing address and card details) under its own privacy policy.

What we do not collect

We do not collect Social Security numbers, government ID numbers, financial account numbers, precise geolocation, biometric data, health data, or information about your donors or beneficiaries. We do not ask you to upload your organization's constituent data.

2. Information About Grantmaking Organizations

The grantmaker records in the Service are compiled from public government records — IRS Form 990 and 990-PF e-filings and the IRS Exempt Organizations Business Master File. These records describe organizations, including their EIN, name, state, and reported grantmaking activity. They are public record and are not personal information about you.

If you believe a record about your organization is inaccurate, contact us at legal@kindredgrantshq.com and we will review it. Note that we cannot change what an organization filed with the IRS; corrections to the source data must be made with the IRS.

3. How We Use Information

We use personal information to:

  • create, authenticate, and secure your account;
  • provide search results and grantmaker profiles;
  • process subscriptions, billing, renewals, and cancellations;
  • send transactional messages (password resets, receipts, billing notices, service changes);
  • respond to support requests;
  • monitor, debug, and improve the Service, including analyzing aggregate and de-identified usage patterns to improve ranking quality and features;
  • detect, prevent, and investigate fraud, abuse, credential sharing, scraping, and security incidents;
  • comply with legal obligations and enforce our Terms of Use.

4. Legal Bases for Processing (EEA/UK Users)

If you are in the European Economic Area or the United Kingdom, we process personal information on these bases: performance of a contract (providing the Service and processing your subscription); legitimate interests (security, abuse prevention, and service improvement); consent (where required, such as non-essential cookies); and legal obligation (tax, accounting, and responding to lawful requests).

5. Cookies and Similar Technologies

We use strictly necessary cookies and local storage to keep you signed in, maintain your session, and protect against cross-site request forgery. The Service does not function without these.

We also use analytics cookies and identifiers set by Google Analytics 4 to measure aggregate usage of the Service. These are not strictly necessary; blocking them does not affect your ability to use the Service. Where consent is legally required, we will ask for it before setting non-essential analytics cookies. You can also opt out at any time using Google's browser opt-out add-on or your browser's cookie controls.

We do not use advertising cookies, and we do not run third-party ad networks or cross-site advertising trackers on the Service. We have disabled Google Analytics advertising features, and we do not use Google Analytics data for remarketing or ad personalization.

You can block or delete cookies through your browser settings, but doing so may prevent you from signing in.

Global Privacy Control. We honor the Global Privacy Control (GPC) signal where required by law. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing for GPC to opt you out of, but we treat it as a valid opt-out request.

6. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We share personal information only as follows:

Service providers (subprocessors) who process data on our behalf under contract:

ProviderPurposeData involved
Lovable CloudApplication hosting, error reportingLog data, error reports
SupabaseDatabase, authenticationEmail, hashed password, organization name, subscription records
Google LLC (Google Analytics 4)Aggregate usage analyticsTruncated IP address, device/browser data, pages viewed, product events (no email, account ID, or search inputs)
Stripe, Inc.Payment processing, billing portalEmail, payment details (collected directly by Stripe), subscription data
Our transactional email providerPassword resets, receipts, and other service messagesEmail address, message content

Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or a security incident.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

With your direction. When you ask us to share something on your behalf.

7. Data Retention

  • Account information: retained while your account is active and for up to 90 days after you delete it, to allow for recovery and to resolve disputes.
  • Billing and subscription records: retained for up to seven (7) years to meet tax, accounting, and audit obligations.
  • Search inputs and log data: retained for up to 12 months, then deleted or de-identified.
  • Analytics data: retained by Google Analytics for up to 14 months under our configured retention setting, then automatically deleted.
  • Backups: deleted data may persist in encrypted backups for up to 30 days before being overwritten.

8. Security

We use industry-standard safeguards, including encryption in transit (TLS), encryption at rest for our database, password hashing, row-level security policies that restrict each account's records to that account, and access controls limiting internal access to personal information.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your password confidential. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.

9. Your Privacy Rights

Depending on where you live, you may have the right to:

  • know / access the personal information we hold about you;
  • correct inaccurate personal information;
  • delete your personal information;
  • obtain a copy of your data in a portable format;
  • opt out of sale or sharing of personal information (we do not sell or share);
  • limit use of sensitive personal information (we do not collect sensitive personal information as defined by applicable law);
  • object to or restrict certain processing, and withdraw consent where processing is based on consent (EEA/UK);
  • not be discriminated against for exercising these rights.

How to exercise. Email legal@kindredgrantshq.com from the address associated with your account, or use the controls in your account settings. We will verify your request by confirming control of your account email and will respond within the period required by law (generally 45 days under California law; one month under GDPR). You may use an authorized agent where the law permits; we may require proof of authorization.

Appeals. If we decline your request, you may appeal by replying to our response with the subject line "Privacy Appeal."

Complaints. EEA/UK users may lodge a complaint with their local supervisory authority. California residents may contact the California Privacy Protection Agency or the Attorney General.

10. International Data Transfers

We are based in the United States and process data there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction. Analytics data collected through Google Analytics may also be processed by Google in the United States and other countries. Where required, we rely on the European Commission's Standard Contractual Clauses or another approved transfer mechanism.

11. Children's Privacy

The Service is intended for adults using it in a professional capacity. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact legal@kindredgrantshq.com and we will delete it.

12. Third-Party Links

The Service may link to third-party websites, including grantmakers' own sites and Stripe's billing portal. Google's handling of analytics data is governed by the Google Privacy Policy and How Google uses information from sites that use our services. We are not responsible for their privacy practices. Review their policies before providing information.

13. Changes to This Policy

We may update this Privacy Policy. We will post the revised version with a new "Last updated" date and, for material changes, notify you by email or an in-app notice before the changes take effect.

14. Contact Us

Questions, requests, or complaints about privacy:

KINDRED GRANTS, LLC
1310 U St NW, Suite 320
Washington, DC 20009
legal@kindredgrantshq.com