Skip to main content
Our 2026 primary beneficiary: The LGBTQ+ Center Long Beach
IslandPitch.in
← Guides
🔐 Chapter 3 · The Vault of Trustvs Chaos & The Mundane

The safest data is the data you never collected.

Data Privacy & Protecting the People You Serve

For many organizations, the data issensitive by nature — health, immigration status, LGBTQ+ identity, survivors of violence, kids. The people you serve hand you their secrets because they trust you. That trust is a vault, and you're the keeper of the keys.

Two villains circle it. Chaos wants to pry the vault open — a breach, a leak, a misdirected email. The Mundaneis subtler: it whispers “keep everything, just in case,” until you're hoarding a mountain of data you never needed and can't protect. The Crew guards the vault a simple way: collect less, and fiercely guard what's left. For community and mission-driven organizations, a privacy breach isn't just embarrassing — it can endanger the very people you exist to help.

Masked Crewsader
Masked Crewsader

People trusted you with their story. That's sacred. Protecting their privacy isn't paperwork — it's keeping a promise to the people we're here to serve.

IP Bot

The safest data is the data you never collected. Minimize every form, set a deletion schedule, and map where everything lives. Less to guard means less to lose. #AutomateThis!

IP Bot

The Crew's playbook: a practical privacy checklist

  1. 1

    Collect only what you need

    Every field you gather is a field you have to protect. If you can't name why you need a piece of personal data, don't collect it.

  2. 2

    Write a plain-language privacy notice

    Tell people what you collect, why, and who you share it with — in words a human can read. (Ours is a fine starting template.)

  3. 3

    Get real consent

    Consent buried in fine print isn't consent. Ask clearly, especially for anything sensitive, and let people say no without losing service.

  4. 4

    Set retention and deletion rules

    Decide how long you keep each type of data, then actually delete it on schedule. Data you no longer hold can't leak.

  5. 5

    Control third-party sharing

    Know which tools and partners receive your data. Don't export your full contact list into every shiny new platform.

  6. 6

    Map where data lives

    A simple list: what you collect, where it's stored, and who can reach it. You can't protect what you can't find.

  7. 7

    Honor data-subject requests

    Under laws like CCPA and GDPR, people can ask to see or delete their data. Have a simple, known process to respond.

The Data Inventory worksheet

You can't protect what you can't find. Before you write a single policy, write down what you hold. A five-column table on one page, revisited every quarter — and every row is a chance to ask “do we still need this?”

Data you holdWhere it livesWho can see itHow long you keep itWhy you have it
Donor / customer emailsCRM / email platformDev & comms staffUntil they unsubscribeNewsletters & receipts
Payment infoPayment processor (not you)Finance lead onlyProcessor's retentionProcess donations
Volunteer recordsOrg drive / schedulerVolunteer coordinator1 yr after last shiftScheduling & safety
Website analyticsAnalytics toolMarketing staff14 months, then purgeMeasure reach
Support messagesInbox / help deskSupport team90 days after resolvedAnswer requests

Add a row for every kind of data you touch: intake notes, photos, case files, the lot. The version of this table where the “why” column is honest — and a few rows have been crossed out and deleted — is the version that actually protects the people you serve.

Data minimization, in practice

Minimization sounds abstract until you look at your own intake form. A few real examples:

Every field you remove is one fewer thing Chaos can steal and one fewer thing you have to defend.

Your vendors are data processors

The moment you put personal data into a tool, that vendor is handling it on your behalf. Ask where the data is stored, who can access it, whether it's encrypted, and — critically — whether it's used to train the vendor's products. Prefer vendors who'll sign a data processing agreement and put their answers in writing. (Want to see a real, plain-language example? Read our own Privacy Policy.)

US-first, but know where your people are

Most US organizations anchor on US rules like CCPA/CPRA (California) and sector laws such as HIPAA for health data. But privacy law follows the people in your database, not just your office. If you serve or fundraise from people in Europe, the GDPR can apply; in Canada, PIPEDA and Quebec's Law 25may too. The throughline is the same everywhere: collect less, be transparent, get real consent, and let people see or delete their data. Do that, and you're standing on solid ground in any jurisdiction.

How Chaos & The Mundane win

Common questions

How do I know what data I actually need to collect?

Start from the outcome, not the form. For every field, finish the sentence "I need this because…" out loud. If the answer is vague — "it might be useful someday," "the old form had it" — that's The Mundane talking, and the field comes off. The safest data is the data you never collected, so default to asking for less and add a field only when a real, present need forces your hand.

What does real consent actually look like?

Real consent is specific, readable, and refusable. You tell people in plain words what you collect, why, and who sees it — before they hand it over — and they can say no without losing the service they came for. Consent buried in fine print, pre-checked boxes, or a 14-page policy nobody reads isn't consent; it's a trap with a signature line. If you'd be embarrassed to read the ask aloud to the person, rewrite it.

Who inside my organization should be able to see sensitive data?

As few people as the work allows. Access should follow the job, not the org chart — the volunteer coordinator doesn't need the case notes, and the board doesn't need the intake spreadsheet. Map who can reach each kind of data, and when someone's role ends, their access ends the same day. Every extra person with a key is one more way the vault gets left open.

We've been keeping everything for years. Where do we even start?

Start by writing down what you hold — a one-page data inventory beats a perfect policy you never finish. Once you can see it, pick the highest-risk pile (anything tied to health, immigration, kids, or money) and set a deletion date for the parts you no longer need. You don't have to clean the whole vault in a day; you just have to stop adding to the hoard and start retiring the oldest, riskiest data first.

Prefer a story? See these ideas play out in our comic-book field guide, The Vault and the Volunteer.

Ready to reach your Pitch?

You don't need a full-time CTO to do this right. Island Pitch works as your Fractional CTO — senior technology leadership at a nonprofit's budget, helping you choose well, lock the doors, and sleep at night.

Get the whole field manual

The full Right-Way Tech Guide — all seven chapters, including the privacy & retention checklist.

The field manual is yours — grab it now.

Our signup form is being upgraded. In the meantime, here's the full PDF — no form to fill out.

Download the field manual (PDF)

Want occasional tech tips by email too? Talk to a Fractional CTO above — we'll get you on the list.