Back to help center

Privacy, consent, and GDPR

Gratora provides built-in tools to help you comply with privacy regulations like GDPR. You can manage consent collection, data retention, donor redaction, and self-service data rights from the Privacy tab in settings.

Privacy settings

The Privacy tab gives you control over how donor data is collected, stored, and removed.

  • Privacy policy URL: Link to your organization’s privacy policy. The privacy-notice block on a donation form links to it, and leaves the link out when the field is empty.
  • Reunite window after redaction (days): How long an erased donor can come back and still be recognized as the same supporter. Default is 90 days.
  • Erase inactive donors automatically: Off by default. While it is off, a donor is erased only because they asked or because an admin erased them. Turning it on reveals Erase donors inactive for (years), which defaults to 7.
  • Keep the activity log for (days): Older activity log entries are deleted. Default is 730 days (2 years). Set it to 0 to turn this off.
  • Anonymize IPs in event logs: Enabled by default. Hashes the IP address recorded with each activity log entry.
  • What is in front of this site: Names the CDN, load balancer, or reverse proxy serving the site. Write cloudflare, or private_ranges for a proxy on your own network, or list addresses and CIDR ranges one per line. Leave it empty when nothing sits in front. Where something does and this is empty, every visitor arrives as the proxy’s address, so the whole site shares one visitor’s spam allowance.
  • Show Gravatar profile pictures: Off by default. Donor lists show Gravatars in place of initials, and each one sends a hash of the donor’s email address to gravatar.com from the visitor’s browser, on a public page. Anonymous donors are never shown one.
  • Default new donations to anonymous: Pre-checks the anonymous toggle on every donation form. Donors can opt out. Off by default.
  • Allow data export from portal and Allow account delete from portal: The two self-service rights described below. Both are on by default.

Gratora supports configurable consent purposes that let donors opt in to specific types of communication. You manage them in the Consent purposes card, at the bottom of the Privacy tab. None ship by default: a purpose names something your organization actually does, and only you know what that is.

Each purpose has a name, a donor-facing description, a key, a version, and two switches: Required to donate and Pre-selected. A purpose marked required cannot be withdrawn from the donor portal. Bump the version when you change a description, and every donor who consented to the older wording is asked to confirm it again.

You add and delete purposes here rather than enabling and disabling them. Deleting a purpose leaves the donor consent history in the audit trail.

Donors see these purposes in the Consents tab of the donor portal, where they can grant or withdraw any purpose that is not marked required. To ask for consent during a donation, add a consent block to the form and pick which of these purposes it asks for. Anything a donor agrees to there is recorded in the same audit trail.

Every consent action is recorded as a separate row in the database. When a donor grants consent, a new row is created. When a donor revokes consent, another new row is created.

This append-only approach ensures a complete audit trail. You can always trace when consent was granted or revoked, and no historical consent records are overwritten or deleted.

Erasing a donor keeps these rows, because the consent and its timestamp are your lawful-basis evidence for everything you sent before the erasure. Only the IP and user-agent hashes on them are cleared, since those could re-link the row to a person.

IP anonymization

Gratora records an IP address with each entry in its activity log. When IP anonymization is enabled, that address is stored as a salted SHA-256 hash, which cannot be read back or reversed. The country is kept separately, in clear text, so you still have a coarse geographic signal.

IP anonymization is enabled by default. Turning it off does not store full addresses: it records no IP at all.

The setting covers the activity log. Consent records keep a hashed IP and user agent of their own either way.

Donor data retention

Gratora uses configurable retention periods to manage how long data is kept.

  • Inactive donors are erased automatically, as if they had asked, once they have gone the configured number of years without a donation (default: 7 years). This runs only while Erase inactive donors automatically is on, and it is off by default. It is the redaction described below, so the record and its donations stay and only the personal details go. Anyone on an active or paused recurring plan is skipped.
  • Activity log entries are deleted once they are older than the configured number of days (default: 730 days). The activity log is the only data Gratora deletes on a schedule. Donations, donors, and receipts are kept.
  • Erased donors keep a hashed handle on their email address for the length of the reunite window (default: 90 days). Inside the window, a donor who gives again is un-erased and keeps their giving history. After it, the handle is replaced permanently and a returning donor counts as a new supporter. Their past donations stay counted either way. Setting the window to 0 severs the link immediately; it does not turn the behavior off.

These settings help you balance regulatory requirements with data minimization principles.

Donor redaction

Redaction removes personally identifiable information from a donor record while preserving the donation history for reporting purposes.

When you redact a donor:

  • Any active or paused recurring plan is canceled first, so nothing keeps billing the person who asked to be forgotten.
  • Personal details like name, email, address, phone number, company, tax ID, and staff notes are removed.
  • Donation records are kept with anonymized donor references.
  • Financial totals and campaign attributions remain intact for reporting.

Redaction is a one-way action. The erased details cannot be recovered. Use it when a donor requests erasure or when retention periods expire.

Data export and account deletion

Donors can manage their own data through the donor portal. Two self-service options are available when enabled in your Privacy settings.

  • Data export: Donors can download a JSON archive of their personal data and donation history. This supports the GDPR right of data portability.
  • Account deletion: Donors can request erasure of their account. This triggers the redaction process described above. Donations and receipts are kept either way, for tax and accounting; only the personal details go.

You control whether these options are available with the allow data export and allow account delete toggles in the Privacy tab. Both are on by default.

Privacy-notice form block

Gratora includes a privacy-notice block that you can add to your donation forms. It renders a short line of text with a link to the privacy policy URL from your Privacy settings. You can edit the wording, the link text, and the alignment on the block. When no privacy policy URL is set, the link is left out and only the text shows.

The privacy-notice block collects nothing. To ask donors for consent during a donation, add a consent block instead. Choices made there are recorded in the consent audit trail automatically.