Privacy Policy
This policy explains how SorrelSites handles personal information across our marketing site (joinsorrel.com), the SorrelSites admin console and member portal, and the organization websites we host on sorrelsites.com and custom domains.
1. Who we are and the roles we play
SorrelSites (“we”, “us”) provides a membership management platform to non-profit and membership organizations. We play two different roles. For information about you as a visitor to joinsorrel.com or as a SorrelSites account holder, we decide how the information is used and are directly responsible to you. For the member records an organization keeps in SorrelSites, that organization controls the data — we process it on the organization's behalf and at its direction. If you are a member of an organization that uses SorrelSites, your organization is your primary point of contact for privacy questions and requests about your member record.
2. Information we collect
Visitors to joinsorrel.com: if you join our waitlist we collect your email address and, optionally, your organization's name. If you send feedback through the site widget we collect your message, the page it was sent from, your browser type, and your email address if you choose to include it. Our marketing site also uses Google Analytics (Section 7).
SorrelSites account holders (organization admins, staff, and members with portal logins): name, email address, and password (stored only as a strong one-way hash — we cannot read your password); optional two-step verification and passkey credentials (authenticator secrets are stored encrypted; passkey private keys never leave your device); sign-in history; and, for security throttling, the IP addresses of failed sign-in attempts.
Member records we process for organizations: contact details (name, email, phone, mailing address), membership status and history, any custom fields the organization defines, event registrations and attendance, dues and payment history, communications sent to the member and their delivery status, documents, photos (hidden location metadata such as GPS coordinates is stripped from uploaded member photos), electronic signature records (which include the signer's IP address and browser as signing evidence), meeting recordings and transcripts when the organization uses a meeting notetaker, and location check-ins (recorded only with the member's explicit consent at check-in). What appears in custom fields is chosen entirely by the organization.
Payment information: payments are processed by Stripe. Card numbers are entered directly on Stripe's secure payment surfaces and never touch or get stored on SorrelSites' systems; we store only Stripe's reference identifiers and transaction records (amounts, dates, status).
3. How we use information
- To provide the service: hosting organization websites, maintaining member records, running events, sending the communications organizations compose, and processing dues and payments.
- To operate accounts and billing for organizations that subscribe to SorrelSites.
- To secure the platform: authenticating sign-ins, throttling abuse, verifying webhooks, and keeping audit logs of significant actions.
- To support you and improve the product, including aggregated, non-identifying usage measurement.
- To meet legal obligations.
We do not sell personal information, and we do not use it for third-party advertising.
4. AI features and your information
SorrelSites' AI features help organization admins draft website content, emails, and configuration. They operate under a strict no-contact-details rule that is enforced in code: member email addresses, phone numbers, mailing addresses, dates of birth, government identifiers, and custom-field values are never sent to AI models. Requests are automatically redacted, and a validator blocks any request that still contains contact-like data before it leaves our systems. At most, a member's name may appear where an admin is drafting content about that person. The AI produces instructions and drafts; our own software applies them to your real records.
Documents an organization uploads are readable by AI features only if an admin switches on AI reading for that specific document; switching it off withdraws the document's content from AI features. Every AI request is logged for the organization's audit trail, and AI output is always a draft until a person publishes it. We do not use your information to train AI models.
5. Google user data
SorrelSites offers two optional Google integrations: Sign in with Google, and a Google Calendar connection used to create meeting links. This section describes exactly how we access, use, store, share, and delete information received from Google APIs.
- What we access: Sign in with Google shares your basic profile — your name, email address, and Google account identifier. The Calendar connection additionally asks for permission to create events on your calendar (the calendar.events scope) and for your email address so the connection can be labeled in your admin console. We request no other Google permissions.
- How we use it: sign-in information is used solely to authenticate you and to create or link your SorrelSites account. The Calendar permission is used for exactly one operation — inserting a calendar event with a Google Meet link on your calendar when you schedule a meeting in SorrelSites. We do not read, list, or search your existing calendar events.
- What we store: your Google account identifier, email, and name are stored with your SorrelSites account. For the Calendar connection, we store the OAuth tokens Google issues, encrypted at rest with Google Cloud KMS; the sign-in flow stores no Google tokens at all.
- What we share: nothing. Information received from Google is never sold, never shared with third parties, never used for advertising, never used to train AI or machine-learning models, and never sent to AI features. It travels only between SorrelSites and Google's own APIs.
- How to delete it: you can disconnect Google sign-in from your account settings at any time, which removes the link to your Google account. Disconnecting a Calendar connection deletes the stored tokens and asks Google to revoke SorrelSites' access. You can also revoke SorrelSites' access from your Google Account at myaccount.google.com/permissions. Closing your SorrelSites account removes stored Google data.
SorrelSites' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Separately from these user integrations, an organization's Google Workspace administrator may choose to share a Google Shared Drive with a SorrelSites-provided service account so the organization's designated documents are available inside SorrelSites. That access is read-only and configured entirely by the organization's administrator.
6. Cookies
SorrelSites' application surfaces (admin console, member portal, and organization sites) use only strictly necessary cookies: a session cookie that keeps you signed in (httpOnly, so scripts cannot read it), a companion security cookie that protects against request forgery, and — if you choose “remember this device” for two-step verification — a trusted-device cookie that lasts 30 days. There are no advertising or cross-site tracking cookies on any SorrelSites application surface. Our marketing site, joinsorrel.com, additionally sets Google Analytics cookies as described in Section 7; you can block cookies in your browser settings.
7. Website analytics (joinsorrel.com only)
On our public marketing site we use Google Analytics to understand how visitors find and use the site. Google Analytics sets cookies and processes usage data such as pages viewed and approximate location derived from your IP address; it does not receive your name or contact details, and we do not use it to advertise to you. Analytics runs only on joinsorrel.com — never in the admin console, member portal, or on organization websites. You can opt out with Google's browser opt-out add-on (tools.google.com/dlpage/gaoptout) or by blocking analytics cookies.
8. Service providers we rely on
We share personal information only with the service providers that help us run SorrelSites, each limited to its purpose:
- Google Cloud Platform — hosting, databases, file storage, encryption key management, and secret storage for the entire platform (United States).
- Stripe — payment processing for organization subscriptions and for the dues and event payments organizations collect (Stripe receives payer name and email; card details go directly to Stripe).
- Twilio SendGrid — email delivery (receives recipient addresses and message content).
- Twilio — text message delivery, for organizations with texting enabled (receives recipient phone numbers and message content).
- Browser push services (Google, Apple, Mozilla) — deliver push notifications; notification content is encrypted so the push service cannot read it.
- Recall.ai — meeting recording and transcription, only when an organization uses the meeting notetaker (processes meeting audio, captions, and participant names).
- AI model providers (Anthropic and Google) — generate AI-assisted drafts, subject to the strict data limits in Section 4.
- Google Analytics — marketing-site usage measurement only (Section 7).
- Have I Been Pwned — when you set a password we check a privacy-preserving fingerprint (the first five characters of a hash) against known breach lists; your password never leaves our systems.
9. How we protect information
- All traffic is encrypted in transit (HTTPS), and data is encrypted at rest by our cloud provider; especially sensitive stored fields, such as connector tokens, carry an additional layer of encryption with managed keys (Google Cloud KMS).
- Sessions use httpOnly cookies that scripts cannot read, with request-forgery protection on every state-changing action.
- Passwords are stored only as strong one-way hashes; new passwords are screened against known breaches; sign-in attempts are throttled.
- Two-step verification and passkeys are available to every account and required for SorrelSites staff; changing your password signs out all existing sessions.
- Each organization's data is isolated: every database query is scoped to the organization, and inbound webhooks from payment and delivery providers are cryptographically verified.
- Significant actions are recorded in audit logs, and SorrelSites staff access to organization data is limited and logged.
No system is perfectly secure, but if we learn of a breach affecting your personal information we will notify affected organizations and authorities as required by law.
10. Data retention and deletion
- Active accounts: we keep your information for as long as your organization's account is active.
- Individual member records: organization admins can permanently delete a member record at any time; deletion takes effect immediately in the application.
- Electronic signature records: retained for the period the organization configures (7 years by default, reflecting common document-retention practice), then purged down to a minimal audit stub (signer name and email, document title, and signing date) that preserves the integrity of the signing history.
- Cancelled organizations: after the wind-down window described in our Terms (90 days for paid subscriptions, 30 days for trials), the account is closed and its data is scheduled for deletion from production systems in the ordinary course of our data-retention practices; residual copies may persist in encrypted backups for a limited period before being overwritten.
- We may retain records we are legally required to keep (for example, financial and tax records) and minimal logs needed for security and abuse prevention.
11. When we share information
Beyond the service providers in Section 8, we share personal information only: at an organization's direction (for example, when it publishes a member directory on its site — always subject to per-field visibility controls and each member's opt-out); to comply with law or valid legal process; to protect the rights, safety, or security of SorrelSites, our users, or the public; or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to the transferred information. We never sell personal information.
12. Your rights and choices
- Members of organizations: your organization controls your member record — contact your organization to access, correct, export, or delete it. SorrelSites also gives you direct self-service controls: a member portal to view and update your profile, directory visibility preferences including a full opt-out, per-channel communication preferences, and a one-click unsubscribe link in every broadcast email.
- Account holders: you can view and update your account details in settings, disconnect Google sign-in, manage two-step verification and passkeys, and contact us at support@joinsorrel.com to request a copy or deletion of your account information.
- Depending on where you live, you may have additional statutory rights (such as access, portability, correction, or erasure). We honor valid requests; where we process data on an organization's behalf, we will route your request to that organization and assist it in responding.
13. Where information is processed
SorrelSites is operated from the United States, and information is processed and stored on Google Cloud Platform infrastructure in the United States. If you use SorrelSites from outside the United States, you understand that your information is transferred to and processed in the United States.
14. Children
SorrelSites accounts are for adults, and our services are not directed to children under 13. Organizations may keep member records that relate to minors (for example, youth programs) — the organization controls those records and is responsible for obtaining any required parental or guardian consent, and SorrelSites' signature tools support a guardian signing on a minor's behalf.
15. Changes to this policy
We may update this policy as the service evolves. For material changes we will notify organizations by email or in the admin console before the changes take effect. The “Last updated” date below reflects the current version.
16. Contact us
For privacy questions or requests, contact us at support@joinsorrel.com. If you are a member of an organization that uses SorrelSites, please also contact your organization, which controls your member record.
Last updated: July 29, 2026 · Questions? support@joinsorrel.com