Privacy Policy
Last updated: March 17, 2026
1. Introduction
DuesSync (“we,” “us,” or “our”) operates a council operations and membership management platform for Knights of Columbus councils, covering dues collection, officer compliance, fraternal surveys, member recruitment, and member engagement. This Privacy Policy explains what information we collect, how we use it, with whom we share it, how it is disclosed, and the security practices we employ to protect it.
By using DuesSync — whether as a council administrator or as a member making a payment — you agree to the practices described in this policy.
2. Information We Collect
Council Administrator Information
- Name and email address (collected during account setup)
- Council name, number, state, and district
- Stripe connected account identifiers for payment processing
- Communication preferences and workflow configuration settings
Member Information
Council administrators import and manage member records on behalf of their councils. This data includes:
- Full name, membership number, and membership class
- Mailing address, email address, and phone number
- Dues balance, billing status, and payment history
- Stripe customer identifiers created during payment processing
- Fraternal survey responses (Form 1728) submitted digitally by members
- Officer role assignments and compliance records (Form 185, Form 365, Safe Environment) managed by council staff
Prospect Information
Council administrators and authorized officers may record information about prospective members as part of a recruitment pipeline. This data is entered by council staff on behalf of the council and may include:
- Full name, email address, and phone number
- Date of birth, home address, parish, and employer
- Source of referral and recruitment stage
- Formal application data (sponsor name, certifications from Form 100)
- Notes and correspondence records maintained by council staff
Councils are responsible for ensuring they have an appropriate basis for collecting and storing this information under applicable law, and for informing prospects that their information is being maintained in this system. Prospects may contact their council directly to request access, correction, or removal of their information.
Member Accounts
Council administrators may invite individual members to create a DuesSync account. When a member accepts an invitation and signs in, we collect:
- Email address and name (provided during account creation)
- Sign-in timestamps and session IP addresses
Last sign-in date and IP address are visible to the council’s Financial Secretary within DuesSync for account verification purposes. Members may contact their council’s Financial Secretary to request account removal.
Payment Information
DuesSync does not store full payment card numbers or bank account numbers. Payments are processed by Stripe, which collects and stores payment method details directly on their platform under their own privacy policy. We receive and store only payment confirmation data (amount, date, Stripe transaction ID).
Automatically Collected Data
- Usage logs for audit and activity history within the platform
- Timestamps and status changes associated with dues notices and payments
- Sign-in timestamps for authenticated administrator sessions
3. How We Use the Information
- To operate the council operations and membership management platform
- To generate, send, and track dues notices on behalf of councils
- To process dues payments via Stripe
- To maintain billing status records and payment history for members
- To manage prospect records and support council recruitment workflows
- To send individual follow-up emails and SMS messages to prospects at the direction of authorized council staff
- To collect and manage fraternal survey (Form 1728) responses from members on behalf of councils
- To track officer compliance records, Form 185 officer assignments, and Form 365 program director designations on behalf of councils
- To generate personalized member birthday emails using an AI language model (see Section 4)
- To authenticate council administrators and members, and protect account access
- To display sign-in history (date and IP address) to authorized council administrators for account verification purposes
- To communicate platform updates or support information to administrators
We do not sell member data to third parties. We do not use member information for marketing purposes unrelated to council operations.
4. How We Share the Information
We share information only with the service providers necessary to operate the platform:
Stripe
Payment processing. Member names, email addresses, and payment amounts are transmitted to Stripe to create customers and process payments. Stripe is PCI-DSS compliant. Stripe’s privacy policy is available at stripe.com/privacy.
Resend
Transactional email delivery. Member and prospect email addresses and the content of dues notices and council-directed outreach messages are transmitted to Resend when sending emails on behalf of a council.
Twilio
SMS delivery. Member and prospect phone numbers and message content are transmitted to Twilio when SMS notices or outreach messages are sent on behalf of a council.
Anthropic
AI-assisted email generation. When a council has birthday emails enabled, member names and ages are transmitted to Anthropic’s API to generate personalized birthday email content on behalf of the council. No payment, billing, or sensitive personal data is transmitted. Anthropic’s privacy policy is available at anthropic.com/privacy.
Supabase
Cloud database hosting. All platform data is stored in a PostgreSQL database hosted on Supabase in the United States.
Supabase Auth
Authentication and session management. Email addresses and session data for council administrators are managed by Supabase. Supabase’s privacy policy is available at supabase.com/privacy.
We may disclose information if required by law or in response to a valid legal process (such as a court order or subpoena).
5. Method of Disclosure
Data is transmitted to the third-party providers listed above exclusively over encrypted HTTPS connections. No personal data is transmitted via unencrypted channels. Email and SMS notices sent to members are dispatched through Resend and Twilio respectively using authenticated API connections.
6. Security
We employ the following practices to safeguard information:
- All data in transit is encrypted using TLS (HTTPS)
- Database credentials and API keys are stored as encrypted environment variables and never exposed in source code
- Any links used to access member payment pages are tokenized and time-limited when applicable
- Administrator access is protected by industry-standard session-based authentication
- Payment card and bank account data is never stored on DuesSync servers — it is handled exclusively by Stripe’s PCI-DSS certified infrastructure
- Database access is restricted to application servers via connection pooling with credential-based authentication
No system is completely secure. If you believe there has been a security incident involving your data, please contact us immediately.
7. Data Retention
Member and council data is retained for the duration of the council’s active subscription. Upon account closure, all council member data will be permanently deleted from DuesSync servers within 30 days, with written confirmation provided upon request. We retain minimal records required for legal or accounting obligations (such as payment transaction records) for the period required by applicable law. No council membership or contact data is retained beyond 30 days after account closure. Councils may request deletion of their data at any time by contacting us at admin@duessync.com.
8. Sensitive Personal Information
Knights of Columbus membership and certain associated data — including parish affiliation, clergy status, and degree — may constitute religious or fraternal affiliation information. Under the California Consumer Privacy Act (CCPA) and similar state statutes, religious affiliation is classified as sensitive personal information subject to heightened protections.
DuesSync treats this category of data accordingly: it is never sold, shared for advertising or marketing, used to build inferred profiles, or disclosed to third parties for any purpose other than operating the specific council service for which it was collected. Anthropic receives only member name and age for birthday email generation — no religious, fraternal, or affiliation data is included in those transmissions.
9. California Resident Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA:
- Right to Know — You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, and the purposes for which it is used.
- Right to Delete — You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct — You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing — DuesSync does not sell or share personal information for cross-context behavioral advertising. No opt-out mechanism is required, but you may contact us to confirm this.
- Right to Limit Use of Sensitive Personal Information — We do not use sensitive personal information (including religious affiliation data) for purposes beyond what is necessary to operate the service.
- Right to Non-Discrimination — Exercising any of these rights will not result in discriminatory treatment.
To exercise any of these rights, contact us at admin@duessync.com. We will respond within 45 days. Note that many rights apply to your own personal information — council member data entered by a council administrator is controlled by the council; we will direct member requests to the appropriate council.
10. Your Rights (General)
Council members whose information has been entered by a council administrator may contact their council directly to request access, correction, or deletion of their personal information. Council administrators may contact us to exercise rights over their organization’s data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of DuesSync after changes are posted constitutes acceptance of the revised policy.
12. Contact
For questions or concerns about this Privacy Policy or your data, contact us at:
DuesSync
admin@duessync.com