GLODA • Privacy

Privacy policy

Effective July 7, 2026 · Policy version 1.1

This privacy policy describes how Global Development Alliance LLC(“we,” “us,” or “GLODA”) collects, uses, and shares personal data when you use our websites, applications, and related services (the “Services”). If you do not agree with this policy, do not use the Services.

Data controller

The data controller responsible for personal data processed in connection with the Services is Global Development Alliance LLC. Contact: privacy@gloda.org.

Personal data we collect

Depending on how you use the Services, we may process:

  • Account and profile data: name, email address, organization, and similar identifiers you provide when you register or update your profile.
  • Billing data: subscription and payment information processed by our payment partners (we generally receive limited payment metadata rather than full card numbers).
  • Service and usage data: product interactions, preferences, in-product events (such as searches or saved views), and technical diagnostics needed to operate and improve the Services.
  • Communications: messages you send to us (for example support requests) and related metadata.
  • Security and reliability data: IP address, device and browser type, timestamps, and similar technical logs used to protect accounts, detect abuse, and troubleshoot issues.

How we use personal data

We use personal data to:

  • Provide, maintain, secure, and improve the Services;
  • Authenticate users, administer accounts, and process subscriptions;
  • Communicate about the Services. Essential account, billing, and security messages are sent as part of providing the Services; optional product updates and tips are sent only if you opt in, and you can withdraw that consent at any time;
  • Measure usage, understand product performance, and develop new features;
  • Comply with law, respond to lawful requests, and enforce our terms and policies;
  • Protect the rights, safety, and security of our users, the public, and GLODA.

Where required, we rely on appropriate legal bases such as performance of a contract, legitimate interests (consistent with your rights), compliance with legal obligations, and, where applicable, your consent.

How we share personal data

We do not sell personal data. We may share personal data with service providers that assist us (for example hosting, email delivery, analytics, customer support, security, and payment processing), when required by law, in connection with a business transaction (such as a merger) subject to appropriate safeguards, or when you direct us to share information.

Our key subprocessors are:

  • Hostinger — application hosting and managed database.
  • Stripe — subscription and payment processing.
  • Resend and Postmark — transactional and digest email delivery (we use the provider configured for your deployment).
  • Sentry — error and reliability monitoring, where enabled.

We enter into data processing terms with these providers where required and update this list as our providers change.

International transfers

Some of our providers process personal data in the United States or other countries. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the EU-U.S. Data Privacy Framework (and its UK extension) where a provider is certified, or Standard Contractual Clauses. You can request more detail about the safeguards for a specific transfer by contacting us at the email above.

Retention

We keep personal data only as long as needed for the purposes described in this policy. In practice:

  • Account and profile data is kept while your account is active. When you delete your account, we erase your personal data — including saved views, alerts, bookmarks, API keys, and sessions — and anonymize the underlying account record.
  • Billing records are retained after account closure where we are legally required to keep them (for example tax and accounting obligations).
  • Product analytics is retained for up to 12 months and then deleted.
  • Security and diagnostic logs are kept for a limited period to protect accounts, detect abuse, and troubleshoot issues.
  • Compliance and audit records, and records of content-removal requests, are retained as long as needed to document how a request or account action was handled and to meet legal obligations.

We may retain limited information longer where required or permitted by law, such as for dispute resolution or to enforce our agreements.

Security

We use administrative, technical, and organizational measures designed to protect personal data. No method of transmission or storage is completely secure.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export certain personal data, and to object to or restrict certain processing. To exercise a right, contact us at the email below; we may need to verify your request. If you are in the EEA/UK and believe we have not resolved your concern, you may have the right to lodge a complaint with a supervisory authority.

If your personal data appears in content we index from public sources, you can request its removal at /data-requests. Signed-in users can permanently delete their own account from account settings.

Cookies and similar technologies

We use a strictly necessary session cookie to keep you signed in, and a first-party identifier for privacy-conscious product analytics. We do not use third-party advertising or cross-site tracking cookies, and our analytics honors browser “Do Not Track” and Global Privacy Control signals. You can control cookies through your browser settings; disabling the session cookie will prevent you from signing in.

Children

The Services are not directed to children under 16, and we do not knowingly collect personal data from children in violation of applicable law.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and revise the effective date. Where changes are material, we will provide notice as required by law.

Contact

Questions or requests about this policy or your personal data: privacy@gloda.org. For EU/UK-specific requests, include that in the subject line so we can route your request efficiently. For terms of use, see Terms of use.