Skip to main content

Privacy & Compliance

How your information is protected

Grant intake involves sensitive organizational information. These are the practices in place, stated without embellishment.

Access control

Internal access is role-based. Reviewers see only what their role requires, and every administrative action on a request is recorded in an audit log.

Encryption

Information is transmitted over encrypted connections and stored in access-controlled systems.

Private document storage

Uploaded documents are held in private storage with no public access path. Files are retrieved only by authorized reviewers.

Data minimization

We ask only for what a funder or reviewer will need. We do not request Social Security numbers, payment card data or bank credentials at any point.

Consent records

Cookie and marketing choices are recorded with the policy version in effect, and can be changed or withdrawn at any time.

Accessibility

The intake experience targets WCAG 2.2 Level AA, because a process no one can complete protects no one.

These are descriptions of our own practices. We do not claim any third-party certification, attestation or audit standard, and no compliance badge is displayed anywhere on this site.

Privacy Requests

Access, correct or delete your information

Submit a request below and we will respond within 30 days. We may need to verify your identity or your authority to act for an organization before releasing information.

We use this only to verify and respond to your request.

Include your organization name and Request ID if you have one.

You can also change cookie choices at any time with , or read the Privacy Policy.