Privacy Policy

Effective date: July 12, 2026

1. What We Collect

We collect the following categories of information:

  • Account information — your name and email address when you sign up
  • Committee data — the donations, expenditures, and committee details you enter into the Service
  • Donor and roster details — contact information (and, for donors, employer and occupation as required by SEEC) of contributors and committee roster members, entered by your committee; these individuals may not themselves be users of the Service
  • Bank data — transaction data fetched via Plaid when you connect a bank account
  • Billing information — subscription payments are processed by Stripe; we store your subscription status but never your card number
  • Usage data — pages visited, actions taken, and errors encountered, used to improve the Service
  • Cookies — session cookies required to keep you signed in

2. How We Use Your Data

We use your data to:

  • Provide and operate the Service
  • Generate SEEC Form 20 and Form 30 reports and other exports you request
  • Send transactional emails (account invites, password resets)
  • Send newsletters to your committee's roster members, only at your committee's direction and through your committee's own email account
  • Diagnose errors and improve reliability
  • Comply with legal obligations

We do not sell your data, use it for advertising, or share it with third parties except as described in Section 3.

3. Third-Party Services

We use the following sub-processors to operate the Service:

  • Vercel — application hosting
  • Supabase — authentication and database hosting
  • Stripe — subscription billing and payment processing
  • Plaid — bank account connectivity (only if you connect a bank account); Plaid's handling of your data is described in Plaid's End User Privacy Policy
  • Anedot — donation import (only if you use the Anedot integration)
  • Google (Gmail) — newsletter delivery through your committee's own Gmail account (only if you connect one)

Each sub-processor is subject to data processing agreements and their own privacy policies.

4. Data Retention

We retain your data for as long as your account is active. If you delete your account, your data is permanently deleted within 30 days. Bank access tokens are deleted immediately when you remove a bank account.

5. Security

All data is transmitted over HTTPS. Database access is controlled by row-level security policies. Bank access tokens (Plaid) and connected email credentials are stored encrypted and never exposed in the UI. Optional two-factor authentication (authenticator app) is available on every account. We conduct periodic security reviews.

6. Your Rights

You may at any time:

  • Export your committee data from the Settings page
  • Request a copy of all personal data we hold about you
  • Request deletion of your account and all associated data
  • Correct inaccurate account information in Settings

To exercise any of these rights, email support@cttreasurer.com.

7. Connecticut Residents

Connecticut residents may have additional rights under the Connecticut Data Privacy Act (CTDPA), including the right to opt out of certain data processing. We do not engage in the sale of personal data or targeted advertising as defined by the CTDPA.

8. Children

The Service is not directed at children under 13. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email before material changes take effect. The current effective date is always shown at the top of this page.

10. Contact

Questions about this policy? Email us at support@cttreasurer.com.