Privacy
Version 2026-10-01.2
Who holds what
SendGather is operated by Rope Labs LLC. When an organization uses it to collect things from its own people, that organization decides what it asks for and what it does with the answers; we store and process them on its behalf.
If you were asked to send something and want it corrected or removed, ask the organization that asked you — their name is in the message you got and on the page you sent it from. They decide, and they can export or erase everything you have ever sent them from their own screens.
What we store
For administrators: the email address you sign in with, your name if you give one, which organizations you belong to, and a record of significant actions taken in the organization (who sent a request, who downloaded submissions, who viewed a value marked sensitive).
We also email administrators a weekly summary of what needs chasing — and only when something does; a quiet week produces no email. To avoid sending you the same list twice we keep, against your membership, the date of the last one and a fingerprint of what it said. You can turn these off in your profile, which switches them off for every organization you administer.
For recipients: your name as the organization entered it, an email address if it gave one — some people are recorded without one and are handed their link another way — whatever you submit, and whether and when you submitted it. You have no account and no password with us.
An organization can also keep a short record about you of its own — fields it defines itself, such as a phone number, a shirt size or a certificate it has to hold. Two things can fill one in. An administrator can type it, the way they would write in an address book. Or, if they have pointed one of their questions at it, your answer is copied there when you submit, so their list stays current without anybody retyping it.
That record outlives the request your answer came from, which is the point of it and the part worth being plain about. Everything else an organization holds about you belongs to a particular request and stops being added to when that request closes; this does not. We keep where each entry came from — which request, and the date — so the organization can see whether it typed something or you told them, and we keep the one value it replaced, so an administrator can put back what was there if an answer overwrote something they meant to keep. Nothing older than that is kept.
A blank answer never erases what is already on that record: leaving a question empty tells them nothing new rather than telling them to forget what they had. A question marked sensitive can never be pointed at one of these fields at all — those answers are encrypted and masked, and a record cannot hold them that way. If a question asks for a file, the file itself can sit on your record; it is the same file you submitted, stored once, and it is served under the same permission check as everything else.
An organization can also have an update fill in one of those details — so a message to forty people reads with your own name, or your own plot number, rather than everyone’s. It is your record and nobody else’s that is read, and only for the details that message names. Anybody the organization has nothing recorded for reads a stand-in phrase the coordinator chose instead, which is typed when they write the message.
What was filled in is kept with that update, as it stood when it was sent, and this is the one place a copy outlives an edit to your record. It is there so the page you can open from the email still says what the email said: correcting your record next month does not rewrite a message that already arrived, and it should not. Nothing else is kept — only the details that update filled in, only for the people it went to, and it is deleted with the update and with you.
If an organization puts a decision to a vote, we also record that you were one of the voters, whether you returned a ballot, when you first voted, and when you last changed your vote — and, on a recorded ballot, how you voted on each motion, or which candidates you chose or ranked in each election. Some motions invite a comment; if you write one we keep it beside that vote, and the organization can read it, quote it in its minutes and include it when it exports the record. When the ballot closes we fix the result: the counts, the rule that was applied, and whether each motion carried or who was elected — with, where candidates were ranked, the round-by-round working that produced it. Those figures are then never recalculated, so they do not change if a record is later corrected or erased.
If an organization holds an election, it records the name of everybody standing — and a short statement from them if they gave one, saying why. The organization types those names itself: somebody can stand for a post without ever having been asked for anything through this service, without an address on file, and without knowing the software exists. The names are shown to everybody on that ballot, and when the vote closes they stay in the sealed result, in the minutes the organization keeps and in what it exports.
An organization can say which of its own contacts a candidate is — and most do not. The name is what stands and what is recorded; this only links the two, so that the organization can see on somebody’s own page what they were elected to. It changes nothing about the vote, and a candidate who is not one of that organization’s contacts is a perfectly ordinary candidate.
An organization can also keep a register of the posts it has — treasurer, secretary, trustee — and of who has held each one and between which dates. Some of those entries are written by a sealed election; the rest are typed in by hand, including an appointment, a resignation, and history from before the organization started using this service. Each entry keeps the name as the organization wrote it, and a note if they added one.
A name cannot be taken back out of a vote that has already happened, and it is better said here than discovered. Erasing a person removes what they submitted and the record an organization keeps about them; it does not reach an election they stood in, and a ballot that has been sent cannot be deleted at all — a record of who was elected that could be edited afterwards would not be a record. It goes when the organization goes. If you stood in an election run here and want your name out of it, that organization is the one to ask, because it is the only party that decides.
We email you about a ballot without being asked to, at most twice: once when you first vote, to confirm we have it, and once when it ends. Neither message contains how you voted. The first tells you how many motions or elections you answered and sends you back to your own link, which is the only place your answers are shown. The second depends on how it ended — if voting closed, it carries the counts and what was decided, whether each motion carried or who was elected, which are the organization’s record rather than anything of yours. If you have told this organization to stop emailing you, or your address has already bounced, we send neither.
If the vote is cancelled, that second message says so instead, and it is the one message we send that an administrator wrote. Two things can happen. A vote can be called off before it closes — a motion withdrawn, a meeting abandoned — and then there is no result and no record, so we say so. Or a vote that finished can have its result set aside afterwards: the vote was taken, it did decide something, and the organization has annulled that decision. If you were already sent the result, we tell you to disregard it.
A result that is set aside is not deleted, and we would rather you knew that than assumed either way. The count stays on the organization’s record, marked as set aside, and it stays in what that organization exports and keeps in its minutes. We do it that way on purpose: a record that could be silently emptied would be worse for the people who voted than one that shows both what was decided and that it was later annulled. Nothing about your individual vote becomes visible that was not already — on a secret ballot the link between you and your vote was destroyed when voting closed, and annulling does not bring it back.
Either way we tell everybody who was asked to vote, name the administrator responsible, and pass on the reason they typed, in their words. We do not write it, edit it or check it. Every other message here is composed by us out of what the organization already holds; this one is the organization writing to you through us, which is why it is worth saying separately. Neither message carries counts of its own — they point at the record rather than restating it.
The same is true of a request. If an organization calls off something it asked you for, everybody who was asked is told — including anybody who had already sent something in, who is told plainly that what they sent will not be used. That message carries the reason that administrator typed, in their words, which we do not write or check, and it replaces the copy of your own answers you would otherwise have been sent when the request closed. One message about the ending, never two.
On a secret ballot, nobody is shown how you voted — not the other voters, and not the person running it. We describe how this works rather than simply promising it. While the ballot is open your vote is stored against your record, because that is what lets you change your mind; no screen, export or email shows it to anybody. When voting closes, the link between you and your vote is permanently removed, and what remains is the count, the fact that you took part, and anything you wrote. Until that moment the link exists in our database, so this is secrecy from the organization rather than from us, and we would rather say so than let you assume otherwise.
A comment you write on a secret ballot is treated the same way as the vote it sits beside — held back entirely while voting is open, and shown to the organization afterwards without your name attached. There is one thing we cannot do for you: your own words can identify you in a way a choice between For and Against cannot, and no amount of removing your name changes that. The form says so before you type, and the decision is yours.
One kind of question is answered in front of the other people who were asked — a discussion question, which an organization turns on for a single question before it sends. Where it is on, what you write is shown to everybody else who was asked and has answered, alongside your name as the organization recorded it. People who have not answered are shown nothing, so nobody reads the others without adding their own. The question itself says so above the box, before you type.
Three things about it are fixed rather than promised. It is decided before the request is sent and cannot be turned on afterwards, so nothing you have already written can become visible later. It never appears in an email — it is only ever on the page you answer from. And a question marked sensitive can never be one of these; the two are refused together. An administrator can withhold any single answer from the others, which removes it from their screens and from nowhere else — the organization still has it, and so do you.
We also record whether each email we tried to send was accepted by the mail provider, how many times we have written to you, and when we last did — so an administrator can tell “nobody replied” from “nobody was asked”, and can see how much somebody has already been chased.
Our mail provider then tells us what happened to each message, and we record it: when it reached your mail server, or that it was refused, along with the reason your provider gave — for example that the address does not exist. The organization sees that reason, because it is usually a typed address that only they can correct. If your address is refused permanently we stop sending to it and mark it for them to fix; that mark is kept per organization, against the address, and is deleted when they erase you or when we are told the address works again.
We also record the first time one of these emails is opened. It is counted by a small image the message loads from us. The organization sees it, beside a note saying what it is worth — which is not much. Many mail apps load images automatically, so an open can be recorded without anybody reading a word; others block images entirely, so somebody may read the message carefully and show nothing at all. We do not record clicks: the links in our emails go straight to us and are not routed anywhere to be counted.
Three limits on that, and they are the reasons it is worth stating rather than burying. We record the FIRST open and never a running tally — not how many times you came back, not when you last looked, because that would be a record of your reading habits rather than of whether our message arrived. We keep no other detail: not what you were using, and not where you were. And nothing acts on it. No reminder, no chasing, no suppression and no charge depends on whether you opened anything; it is shown to the organization and used for nothing else. It is deleted with the rest of your delivery record when the organization erases you.
What you type is saved as you go, before you send it, so a closed tab or a flat battery does not cost you the paragraph you were part-way through. The organization cannot read a part-written answer — it can see only that you have started, which is what stops it chasing somebody who is already working on it. An unsent answer stays until you send it or the organization erases you, and it is left out of everything the organization exports.
If you mark one of these emails as spam in your mail client, your provider tells ours and ours tells us. We treat that as asking that organization to stop and record it exactly as if you had used the link in the message — so they are told you asked them to stop, and not which mailbox reported it.
If you ask an organization to stop emailing you, we keep your email addresses and the date, so that we can recognise them and refuse to send. That record is kept per organization — it says nothing to any other organization here — and it is the one thing that survives being erased from an organization’s records, because deleting it is what would let the next list they upload undo your request. It goes when the organization does.
If somebody creates an organization through another user’s referral link, we record who introduced them. It is kept for as long as the organization exists.
When you report something to us
Reporting a bug, sending feedback, or reporting a request as abusive sends us what you wrote, your name and email address, the page you were on, and the time you sent it. If you were signed in, it also records which account sent it — the internal identifier we hold for your account, alongside the address, so that a support conversation still lines up if your address changes later. Reporting a request as abusive does not require an account — the link you were sent is enough, there is no account to record, and the report goes to us, not to the organization you are reporting.
With those reports we also record the browser and device you used, from the identification your browser sends with every request, and an approximate location — town or city, region and country — worked out from your connection. We keep the location rather than the network address it came from, and no third party is asked to resolve it. This is so a bug report can be reproduced and an abuse report can be placed. It is captured with anything sent through that form — including, for example, a request about tax exemption, where it tells us nothing useful and we simply do not look at it. It is not used for anything else, and nothing else in the service records it.
If you ask about sales-tax exemption you can attach your certificate to that form. We keep the file, and a copy travels to us by email so a person can read it. We keep it as the record of a tax decision we made for your organization — which means it survives the organization being deleted, because it is our own evidence for not having charged you rather than something we hold on your behalf. It is the only file this form accepts, and attaching one is always optional.
Files and photographs
Files sent to an organization are stored privately. They are never published, never given a guessable address, and are only served after a permission check — to an administrator of the organization, to the person who uploaded them through their own link, or, in the one case described next, to the people an organization sends an update to.
A photograph somebody submitted can be used as the picture at the top of an update, and then everybody that update is sent to can see it. This is the only way something a person submitted is shown to anyone outside the organization, and it is bounded in four ways. It is only ever a picture, never a document, and never an answer to a question marked sensitive or a file attached to one. The address it is served from carries the same unguessable token as the rest of that person’s update, so it is not a public link. It stops working on a date — an update that carries one of these pictures cannot be sent without one, and withdrawing the update stops it immediately. And the administrator choosing it is shown whose photograph it is, by name, and has to confirm.
Choosing one stores a second, smaller copy, cut to fit the top of a message; the original is left as it was. Both are that person’s, and both go when they go: erasing somebody removes the copy along with the photograph it was made from.
Files an organization sends OUT are different, and deliberately so. An administrator can attach the organization’s own documents — a brief, a form to fill in, last year’s example — to a request, and everybody asked can open them from their own link. They are still not public: the link has to name a request the file is attached to, and a request that has closed stops serving them. Those documents are uploaded from a computer, or copied in from an administrator’s own Google Drive — copied, not linked, so we hold our own copy and never reach back into that Drive afterwards.
An organization’s logo is the one thing served to anyone who has the address, without a check. It has to be, because the thing that fetches it most is a mail program showing an email, which cannot sign in. It is branding an organization published on purpose; nothing anybody submits is treated this way.
An administrator can mark a question as sensitive. Answers to it are encrypted before storage, hidden behind a deliberate reveal, left out of downloads by default, never included in any email, and never shown back to the person who sent them. Each reveal is recorded.
An organization can connect a cloud folder of its own — Google Drive today — and copy what it collects there, into an account it controls. Nothing is copied automatically: an administrator exports a particular request, and only then. Only submitted work goes: part-written answers do not, and neither do answers to questions marked sensitive or the files attached to them. The folder belongs to the organization, under whatever arrangement it has with that provider, and what becomes of a copy once it arrives is the organization’s to decide — including who else it gives access to that folder.
When you sign something
An organization can ask you to sign a document — a permission slip, a photo release, a volunteer agreement. Signing is different from sending something in, and what we keep is different too, so it has its own section.
Before you sign, you are shown the document and told what signing electronically means, including that you can ask the organization for paper instead. You agree to sign electronically as a separate step, before any signature exists. Nothing is recorded until you press Sign.
To confirm the mailbox is yours, we email a short code to the one address the organization used to reach you, and you enter it. This is so the record can say that you signed, rather than only that somebody holding the link did.
When you sign we keep, as one record: the document exactly as it was at that moment, the name you typed, the address it was sent to, the date and time, which version of the consent wording you were shown, and the network address you signed from, the rough location that address suggests, and the browser and device you used. We keep those last three for signatures and for reports sent to us, and nowhere else.
We also keep a copy of the document with your name written on it as a signature, made at the moment you signed. It is yours alone: everybody who signs the same document gets their own copy carrying their own name, and the document as it was before any mark was added is kept unchanged beside it.
You are sent your own copy immediately — a certificate saying what you signed and when, with your countersigned copy attached, to the address the code went to. The document exactly as you signed it stays available from the link in that email. It does not expire and it does not depend on a link still working.
Questions answered on the same page are ordinary submissions and are covered by everything above; they are not part of what you signed, and the certificate says so.
Payments
Paying for credits happens on a page hosted by our payment provider. Card details never reach us and we never store them. What we keep is a reference to the payment, the amount, and the credits it bought, so a purchase can be matched to an organization and a receipt reissued.
Anyone can buy credits without an account, in which case the only personal data involved is the email address the receipt is sent to and whatever the provider needs to take the payment.
How long we keep it
Submissions are kept until the organization deletes them, and so is anything on the record an organization keeps about you. An organization can set answers to sensitive questions to delete themselves after a period it chooses; this is off unless it is turned on, and it applies to those answers only — it does not reach the record. There is no other automatic deletion — nothing expires on its own.
An organization’s owner can delete the whole organization, which destroys every request, submission and uploaded file it holds, in both the database and the file storage, with no grace period and no copy kept. A short record that the deletion happened — the organization name, who asked, when, and how much was destroyed — is retained afterwards.
If an organization has connected its own cloud storage folder, copies already placed there belong to the organization and are never touched by any of the above.
If nobody signs in to an organization for about a year, we email everyone who administers it and then, thirty days later, close its open requests — which stops the links it sent from working. Signing in at any point stops that happening. Nothing is deleted: every submission and file stays where it is and can still be read and downloaded. We do this because a recipient’s link is the only key to a request, and leaving keys working on an organization nobody is watching is the part we are not comfortable with.
There is no overall time limit. Nothing is deleted because it has reached a certain age, and an organization’s data stays until the organization removes it or removes itself. If that ever changes we will amend this policy and say so before it takes effect, rather than applying a limit to things collected under a policy that did not have one.
Who else touches it
Five companies, each doing one job. All are in the United States, so data submitted from elsewhere is transferred there.
- Neon — the database. Their data processing terms
- Cloudflare R2 — uploaded files. Their data processing terms
- Vercel — hosting and delivery. Their data processing terms
- Resend — outgoing email, and what happens to it. Their data processing terms
- Stripe — payments, and it never shows us a card number. Their data processing terms
There is nobody else. We add to this list only by changing this page.
One flow is deliberately not on that list, because the arrangement is not ours: if an organization connects a cloud folder, copies of files are sent to whoever provides it — Google today — under the organization’s own account and its own agreement with them. The organization chooses that provider and holds that relationship; we put the files where it told us to.
Cookies
Only functional ones: a cookie that keeps an administrator signed in, one remembering which organization they last worked in, and a short-lived one that lets a page tell a download has started. Connecting an organization’s own cloud folder — or adding a document to it from Google Drive — sets two more that last ten minutes and exist only while that is being done. There is no advertising and no third-party analytics.
A recipient is set one cookie, and only on a vote that has an access code. Where an organization has protected a ballot with a code, typing that code correctly leaves a cookie recording that it was entered for that one ballot, so you are not asked for it again every time you open the link. It holds nothing but the ballot it belongs to and the date it stops working, it is not readable by the page you are on, and it is not used to recognise you anywhere else or on any other vote. Recipients are set no other cookies of any kind.
One thing in our emails does count something, and it is not a cookie. A message carries a small image that tells us it was opened. Our links are not routed through anything to be counted, so we do not know what you clicked. The open is described in full under what we hold about recipients above, including the three limits on it: first-open-only, nothing else recorded, and nothing decided on the strength of it. We say it here too because a reader who comes to a Cookies section looking for “is this thing watching me” is owed the answer in the place they looked.
Your rights over this data
An administrator can, from their own screens and without asking us, export everything one person has ever submitted and everything on the record it keeps about them, and erase that person entirely — rows, record and files together. The export tells the two apart, so you can see which entries you gave them and which they wrote down themselves.
One limit on that, stated plainly rather than left to be discovered. If the organization has copied files into a cloud folder of its own, erasing somebody here does not reach the copies already sitting in that folder. We have no way to delete anything from it and never attempt to — our own copies go, and the ones in their folder are theirs. The organization is the only party that can remove those, so that is who to ask.
A second limit, and it is about records of office. If you stood as a candidate in an election an organization ran here, erasing you does not take your name out of that vote. A sent ballot cannot be deleted and a sealed result is never rewritten, which is what makes it a record at all. The same is true of the register of who has held a post: an entry naming you stays, because a register with a gap in it is not a register. In both places the link to your contact record is removed, so nothing there points at you any more, and the name goes when the organization goes.
A third limit, and it is about signatures. If you signed a document an organization sent you, erasing you does not delete that signature. The document as it stood, the name you typed, the address it went to and the time you signed it all stay, because the record is evidence of something you did rather than information the organization collected about you — and a signature that can be removed afterwards is not one. The link to your contact record is removed, so nothing there points at you any more. You are told this before you sign, not afterwards.
Those three are the only places this applies. Everything you submitted, and everything else an organization wrote down about you, is removed in full.
A signature record is kept for as long as the organization has an account with us. Deleting the organization destroys it with everything else, and nothing else removes it — it does not expire, and the setting that deletes sensitive answers after a period does not reach it.
If what you want is simply to stop hearing from one organization, you can do that yourself, without asking them and without an account. Every reminder we send carries a link to it, and so does your own request page. It takes effect immediately and covers every address that organization holds for you.
Depending on where you live you may also have the right to ask for a copy of the personal data held about you, to have it corrected or erased, to object to or restrict how it is used, and to complain to your data protection authority. Who answers that request depends on whose data it is, and the two cases are genuinely different.
Things we hold in our own right — your administrator account, and anything you sent us in a bug report, a piece of feedback or an abuse report. Ask us directly and we will answer within one month.
Things an organization asked you for — your submissions, the name and address it holds for you, and anything on the record it keeps about you. There, the organization decides and we act on its instructions. Asking it directly is both faster and the right route, because it can export or erase you from its own screens without involving us at all.
SendGather is built for organizations in the United States asking people in the United States, and that is the service we offer. We have not appointed a representative in the European Union or the United Kingdom, and this policy does not claim the protections that come with one. If your organization needs to ask people in the EU or UK, this is not yet the right tool for it.
If something of yours has reached us through an organization that uses this, that organization is the one to ask — it decides, and it can act without us.
If something goes wrong
If personal data we hold is lost or exposed, we will investigate, take steps to contain it, and notify the organizations affected without undue delay, describing what happened, what data was involved and what we are doing about it. Where an organization is the controller, notifying the people affected and any regulator is that organization’s decision, and its own clock starts when we tell it — which is why we tell it as soon as we know, rather than waiting until we know everything.
Rope Labs LLC performs the above, and notifications come from legal@ropelabs.io. If you think something has gone wrong with data we hold, that is the address to tell us at.
Changes to this policy
If this policy changes materially we will tell the administrators of affected organizations in the application, before the change takes effect. The version in force is shown at the top of this page.
Contact
Write to legal@ropelabs.io about anything we hold in our own right — your administrator account, or something you sent us as feedback, a bug report or an abuse report — or to tell us you think something has gone wrong. For anything you were asked to send to an organization, ask that organization directly. If you need a postal address to write to, ask and we will give you one.
What the service asks of recipients, and how to check a request is genuine, is explained at our help pages.