← Legal

MissionHand Privacy Policy

Serve by Design, LLC | Effective Date: July 1, 2026 | Version 1.0



Compliance Check Summary

Applicable US laws considered:

  • Florida Information Protection Act (FIPA), Fla. Stat. § 501.171 — Florida's breach notification law; requires notification within 30 days of a breach; third-party agents (like us) must notify the covered entity within 10 days of discovering a breach.
  • CCPA/CPRA (California Consumer Privacy Act as amended) — Applies to for-profit businesses meeting revenue or data-volume thresholds. At early-stage revenue levels, MissionHand almost certainly does not meet the $26.625M revenue threshold and likely does not buy/sell/share data of 100,000+ California consumers. However, because your customers' donors or beneficiaries may be California residents, confirm whether you or your customers are covered. Nonprofits are generally exempt from CCPA as the "business," but you (Serve by Design) are for-profit.
  • Other state privacy laws (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, etc.) — Multiple new state privacy laws took effect 2023–2025. Most apply to larger businesses processing data of residents in those states.

Privacy Policy

Who This Policy Applies To

This Privacy Policy describes how Serve by Design, LLC ("Company," "we," "us," or "our") collects, uses, and protects information when you use MissionHand (available at missionhand.com).

This policy applies to.

  • Account Holders: Staff, administrators, and other representatives of nonprofit organizations that subscribe to MissionHand.
  • Visitors: People who visit our marketing website at missionhand.com without creating an account.

This policy does not directly govern the personal data of the donors, volunteers, and beneficiaries managed within MissionHand by our nonprofit customers. That data belongs to and is controlled by the nonprofit. If you are a donor, volunteer, or beneficiary of a nonprofit that uses MissionHand and you have questions about your data, please contact that nonprofit directly.


Part 1: Information We Collect About Account Holders and Website Visitors

A. Information You Give Us Directly

  • Account registration: Name, email address, job title, organization name, phone number, and billing information when you create a MissionHand account.
  • Communications: Information you send us when you contact support, request a demo, or communicate with us by email.
  • Payment information: We use Stripe to process subscription payments. We do not store your full credit card number; Stripe stores payment card data on our behalf.

B. Information Collected Automatically

When you use MissionHand or visit our marketing website, we may automatically collect.

  • Log data: IP address, browser type and version, operating system, pages viewed, time and date of visits, and referring URLs.
  • Usage data: Features used, actions taken within MissionHand (such as which modules are accessed), and session duration.
  • Cookies and similar technologies: We use session cookies to keep you logged in and functional cookies necessary for the platform to operate. We do not use tracking or advertising cookies inside the MissionHand application.

C. Information From Third Parties

  • Stripe: We may receive billing-related notifications from Stripe (e.g., payment failure alerts).

Part 2: How We Use Account Holder Information

We use the information we collect about Account Holders and visitors to.

  1. Provide the Service: Create and manage your account, process your subscription, and deliver MissionHand features.
  2. Communicate with you: Send transactional emails (receipts, password resets, security alerts, product updates). We use Resend to deliver these emails.
  3. Support: Respond to your questions and troubleshoot issues.
  4. Improve MissionHand: Analyze aggregate usage patterns to improve features and fix bugs. We do not use individual Customer Data to build or train AI/ML models.
  5. Legal and compliance: Detect fraud, enforce our Terms of Service, and comply with legal obligations.
  6. Business operations: Internal record-keeping, financial reporting, and business continuity.

We do not sell your personal information. We do not use your information for third-party advertising.


Part 3: Customer Data — Our Role as a Processor

When a nonprofit customer enters their donors', beneficiaries', or volunteers' personal data into MissionHand, that data is Customer Data. The nonprofit is the data controller — they decide what data to collect and why. We are the data processor — we store and process that data only on the nonprofit's instructions, as described in our Data Processing Addendum.

We commit that.

  • We will not use Customer Data for any purpose other than providing MissionHand to the customer.
  • We will not sell Customer Data.
  • We will not use Customer Data to send marketing communications to donors or beneficiaries on our own behalf.
  • We will not combine Customer Data from one customer with Customer Data from another customer.

If you are a donor, volunteer, or beneficiary whose information is stored in MissionHand by a nonprofit, please direct any privacy inquiries to that nonprofit. We will cooperate with the nonprofit in responding to your request.


Part 4: How We Share Information

We share information only in the following circumstances.

With Sub-processors (Service Providers Acting on Our Behalf)

We use a limited set of third-party service providers to deliver MissionHand. These providers process data only as we direct, under contractual data protection obligations. Our full Sub-processor List is available at https://missionhand.com/legal/subprocessors. The current sub-processors are.

Sub-processorPurposeData Location
SupabaseDatabase hosting, authentication, file storageUnited States
VercelApplication hosting and deliveryUnited States
ResendTransactional and bulk email deliveryUnited States
StripeSubscription billing and donation payment processingUnited States
PayPalDonation payment processingUnited States

For Legal Reasons

We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation, court order, or government request; (b) protect the rights, property, or safety of Serve by Design, our customers, or others; or (c) detect, prevent, or address fraud or security issues.

If we receive a government request for Customer Data, we will notify the affected customer as soon as legally permitted.

Business Transfers

If we are involved in a merger, acquisition, or sale of all or substantially all of our assets, Customer Data may be transferred as part of that transaction. We will notify affected customers before Customer Data is transferred and becomes subject to a different privacy policy.

With Your Consent

We may share information for other purposes if you give us explicit consent.


Part 5: Data Security

We implement reasonable technical and organizational measures to protect information against unauthorized access, alteration, disclosure, or destruction. Our current security measures include.

  • Encryption in transit: All data transmitted between your browser and MissionHand is encrypted using HTTPS/TLS.
  • Tenant isolation: Each nonprofit's data is logically separated from other nonprofits' data using row-level security controls in our database.
  • Audit logging: Changes to sensitive data are logged.
  • Encrypted backups: We perform daily encrypted database backups.
  • Least-privilege access: Our staff access to production data is limited to what is necessary to provide support and maintain the Service.

We do not currently hold SOC 2 or HIPAA certification. We will update this policy if we obtain certifications in the future.

No security system is perfect, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at info@servecustom.com.


Part 6: Data Breach Notification

If we experience a data breach involving Customer Data, we will.

  1. Notify the affected nonprofit customer(s) within 10 days of confirming the breach (consistent with Florida's FIPA requirements for third-party agents, Fla. Stat. § 501.171).
  2. Our notification will describe (to the extent known): the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the steps we have taken or plan to take.
  3. We will cooperate with the customer in any notifications the customer is required to provide to affected individuals or regulators.

If you are an Account Holder or website visitor and we experience a breach involving your own account data, we will notify you by email to your registered email address without undue delay and within the timeframes required by applicable state law (Florida requires notice within 30 days; other states have varying timelines). For breaches affecting more than 500 Florida residents, we will also notify the Florida Attorney General within 30 days.


Part 7: Data Retention

CategoryRetention PeriodBasis
Account holder contact informationDuration of account + 3 years for business recordsLegitimate business need
Subscription and billing records7 yearsFlorida and federal tax record requirements
Customer Data (on behalf of nonprofits)Duration of subscription + 60-day wind-down period, then deletedPer Terms of Service Section 14
Support communications3 yearsBusiness operations
Security logs1 yearSecurity monitoring

Part 8: Your Privacy Rights

For Account Holders

Depending on where you are located, you may have the following rights regarding the information we hold about you in your capacity as an account holder.

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Ask us to correct inaccurate information.
  • Deletion: Ask us to delete your personal information (subject to legitimate retention needs, such as billing records).
  • Portability: Request your personal information in a portable format.
  • Opt-out of marketing: Unsubscribe from our marketing emails at any time using the unsubscribe link in any email or by contacting info@servecustom.com.

To exercise these rights, email us at info@servecustom.com. We will respond within 45 days (or within any shorter period required by applicable law). We may ask you to verify your identity before fulfilling a request.

CCPA/CPRA Notice (California Residents)

If the CCPA applies, California residents have the right to.

  • Know what personal information we collect, use, disclose, and "sell" (we do not sell personal information).
  • Delete their personal information (subject to exceptions).
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information (we do not sell or share personal information for advertising).
  • Non-discrimination for exercising their rights.

To submit a request, contact us at info@servecustom.com. We do not sell personal information and do not have a "Do Not Sell or Share My Personal Information" link because we do not engage in such activities.

For Donors, Beneficiaries, and Volunteers (End Users in Customer Data)

If your personal data is stored in MissionHand by a nonprofit that uses our platform, that nonprofit is responsible for your privacy rights. Please contact the nonprofit directly. We will assist the nonprofit in responding to your request as required by our Data Processing Addendum.


Part 9: Children's Privacy

MissionHand is not directed at children under the age of 13, and we do not knowingly collect personal information directly from children under 13. Account holders must be 18 or older. We recognize that nonprofits may enter information about minor beneficiaries as part of case management; the nonprofit is responsible for compliance with the Children's Online Privacy Protection Act (COPPA) and any other laws protecting minors' data.


Part 10: Links to Other Websites

MissionHand may contain links to third-party websites (for example, Stripe's payment portal). We are not responsible for the privacy practices of those sites. Review their privacy policies before submitting information.


Part 11: If Your Nonprofit Serves EU/UK Data Subjects

This policy is written for US-based use. If you expect any of your customers' donors, beneficiaries, or volunteers to be located in the European Union or United Kingdom, significant additional compliance is required, including.

  1. GDPR (EU) / UK GDPR (UK) would apply to processing of EU/UK data subjects' personal data.
  2. We would need to complete an international data transfer impact assessment, as data is processed in the US.
  3. Our DPA would need EU Standard Contractual Clauses (SCCs, 2021 version) for EU data, and a UK IDTA addendum for UK data.
  4. Additional data subject rights apply (stricter than most US state laws).
  5. We may need to appoint an EU/UK representative.
  6. Special categories of data (health, social-services, etc.) require an explicit legal basis.

Part 12: Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify Account Holders by email or by posting a prominent notice in MissionHand at least 30 days before the changes take effect. The "Effective Date" at the top of this policy will always reflect the most recent version.


Part 13: How to Contact Us

For privacy-related questions, requests, or complaints. Serve by Design, LLC 7439 Midway Rd Jacksonville, FL 32244 Email: info@servecustom.com