You were trusted with other families' information.
You are a volunteer, not an IT department. But when a family fills out your interest form, they hand you a phone number, an email address, and their child's name. Here is exactly what happens to all of it, in language you can forward to a committee.
The short version
-
A database of your own
Your organization gets its own separate database, not a shared one with your name in a column.
-
Copied every night
A full copy goes off site to encrypted storage each night and is kept for thirty days.
-
Encrypted coming and going
Every page and form is HTTPS only, and the storage it rests on is encrypted too.
-
No password to steal
Leaders sign in with a one-time link sent to their email, or with Google. There is no password on file.
-
Cards never touch us
Payment details go straight to Stripe. We never see, hold, or store a card or bank number.
-
Yours to take with you
Export everything from your settings page, any time, on any plan, including the free one.
Separate by design, not by filter.
Most systems keep every organization's records in the same tables, with a column noting who each row belongs to. MemberCairn does not work that way.
How most systems store it
One table, everyone in it
It works right up until one query forgets to check that column, and then a pack is looking at another pack's families.
How MemberCairn stores it
Pack 42
Troop 7
Rotary club
One database each, its own file
There is no shared table to filter correctly, because there is no shared table. Your roster, messages, payments, and website live behind your own front door.
That line holds everywhere downstream. Your backups are yours alone. Your export is a copy of your own file. And if you ever leave, deleting your organization deletes that file and its backups, rather than trying to pick your rows out of everyone else's.
If your committee wants the detail
Open the ones they asked about.
How does anyone sign in?
Volunteer accounts collect reused passwords, shared logins, and the leftover credentials of a leader who stepped down two years ago. So MemberCairn does not use passwords at all. Sign-in is a one-time link to the leader’s own email, or Sign in with Google, which means there is nothing on file to reuse across sites, guess, or leak.
- Only the parts they need. Each leader is given a role, and the role decides what they can open. A den leader does not get the treasurer’s screens by default.
- Written down as it happens. Changes made inside the admin are recorded with who made them and when, so a question about what happened has an answer.
- No member login at all. Families never get an account, so there is no member password anywhere to be compromised. They act through a personal link that opens only their own RSVP or payment.
- The usual protections, in place and staying there. Every page is served over HTTPS only, browsers are instructed to refuse an unencrypted connection to us, the app cannot be loaded inside a frame on someone else’s site, forms submitted from anywhere but your own screen are rejected, and sensitive pages are rate limited so nobody can sit and guess at links.
If something breaks, does our roster come back?
A backup nobody has ever restored is a rumor. Ours is a plain database file, so bringing one back is a copy, not a rescue project.
- Every night. A clean, complete copy of your database is taken while the site keeps running, so nothing is captured half written.
- Off the machine it runs on. The copy is stored encrypted with a different company than the one running the app, so losing one does not lose the other.
- Kept for thirty days. Not just last night’s. If something went wrong two weeks ago and nobody noticed until now, there is still a good copy to go back to.
- Taken before the nightly cleanup. The routines that clear out old message contents run after the backup, never before it.
- Snapshot on the way out. Deleting an organization takes a fresh copy first and holds it through a waiting period, so a delete made in error is recoverable rather than final.
Does MemberCairn ever hold a card number?
No. When a family pays dues or pays at RSVP, the card details go directly to Stripe, which handles payments for millions of businesses. They never pass through MemberCairn, and we never store them. What we see is that a payment succeeded and which family it was for. Money lands in your organization’s own bank account, in your organization’s own Stripe account, not ours.
What does the AI assistant read, and what does it never do?
MemberCairn’s assistant reads the messages families send you, so it can summarize them, sort out which ones need a leader, and draft replies in your voice. That is the job, and it cannot be done without reading them. A draft goes to a leader before it goes to a family, and automatic replies happen only where you have deliberately turned them on for routine cases, inside the quiet hours and daily limits you set.
- Never training data. Your families’ messages are used to serve your organization and nothing else. They are not used to train general purpose AI models, and they are never sold.
- Nobody is being followed. No advertising or tracking code runs inside the app or on the pages you publish for your members, so a parent who opens their RSVP link is not being followed around the internet afterward.
What do you hold about a child?
MemberCairn is built for leaders and for the parents and guardians they talk to. Children do not have accounts, do not sign in, and are never asked for anything directly. We collect nothing from a child.
- It comes from an adult, and you decide what goes in. What the system holds about a youth member is what your organization needs to run that child’s participation, and it comes from a parent, a guardian, or the organization itself. The full detail of what that covers, and how a parent can review, correct, or remove it, is spelled out in the privacy policy.
What happens if we leave?
A full export lives on your settings page and downloads in one click. It is not a paid feature, it is not a support ticket, and it is not reduced on the free plan. We also never cap how many families or members you can have, on any plan. Both of those are written into our terms, so they cannot quietly become upsells later.
- Then it goes. We do not sell personal information. Old message contents are cleared out on a schedule rather than kept forever, and people who opt out of contact are anonymized. If you decide to leave, your data stays available to export for at least thirty days, and then it is deleted.
The paperwork behind all of this
This page is the plain-language version. These are the documents it rests on, including the full list of the companies that handle anything on our behalf and what each of them is allowed to do with it.
- Privacy Policy : what is collected, why, and how long it is kept.
- Data Processing Addendum : the named list of providers, the security commitments, and the breach-notification terms.
- Terms of Use : including the export and no-member-cap commitments.
A question your committee asked that this page does not answer? Write to privacy@membercairn.com and you will get a real answer from a person, not a form letter.
