Privacy policy
What we collect, and what we do with it
ChapterRoots builds and hosts private membership websites for fraternity and sorority chapters. This page covers two things: what this website collects from you, and how we handle the member information that lives on the chapter sites we host. It is written in plain English on purpose.
1 · This website
We don't set cookies and we don't run advertising or cross-site tracking. Our hosting provider (Cloudflare) may record standard server logs — the address and browser type of a request — for security and to keep the site running, and may count page views in aggregate without identifying anyone.
The walkthrough form. When you ask for a walkthrough you give us your name, email, your chapter and school, and whatever you write in the message. That's the only information this site asks for. We use it to reply to you, schedule the walkthrough, and keep a record of the conversation. The form is delivered to us by Formspree, which stores the submission on our behalf.
Email. If you write to us, we keep the correspondence as a normal business record.
2 · If your chapter becomes a customer
We keep the information needed to run the relationship: the chapter's name and school, the officers we work with and how to reach them, the signed agreement, and billing records. Payments are handled by Stripe. We never see or store your full card or bank details; Stripe holds them and emails receipts. Billing records are kept for as long as tax law requires, generally seven years.
3 · The chapter sites we host
Each chapter's site holds its members' information: names, pledge classes, big/little lines, photos, posts, and the email addresses members sign in with. That information belongs to the chapter, and the chapter decides who gets an account and what is posted. Each chapter site carries its own privacy policy, written for its members, and a built-in way to ask the chapter to see, correct, or remove your information.
ChapterRoots hosts and processes that information for the chapter, under our written Services Agreement. Concretely:
- We use our access only to run the service — hosting, monitoring, security updates, backups, and support the chapter asks for.
- We never sell, share, rent, or mine member information, and we never use it for advertising or to contact members for our own purposes.
- Every chapter's data lives in its own isolated database; no chapter's data shares a database with another's.
- Chapters can export all of their data at any time, and can take the whole site into their own accounts if they leave.
- If we discover a security breach affecting a chapter's site, we tell the chapter promptly and help it respond.
If you are a member of a chapter site and have a question about your information, the fastest route is the chapter's own contact on that site. You can also write to us and we'll help.
4 · Who handles data for us
We rely on a small number of service providers, each bound by its own privacy commitments: Cloudflare (hosting, DNS, and file storage), Supabase (each chapter's database and sign-in), Stripe (billing), Formspree (this site's contact form), Brevo and Resend (sending email such as sign-in links, notifications, and chapter digests), and Google (our email and the setup form chapters fill in). We don't sell information to anyone.
5 · How long we keep things
Walkthrough requests and correspondence: up to two years, then deleted unless you became a customer. Customer and billing records: the life of the relationship plus the period tax law requires. A chapter's site data: for as long as the chapter subscribes, plus twelve months after a lapse so the chapter can export or return — then deleted, with written notice first. Full details are in the Services Agreement.
6 · Your choices
Email hello@chapterroots.com to ask what we hold about you, to correct it, or to have it deleted; we'll answer within 14 days. Every bulk email we send on a chapter's behalf carries an unsubscribe link. We don't respond to browser "do not track" signals because we don't track.
7 · Security
Chapter sites are members-only behind sign-in, connections are encrypted, database access is governed by per-row permission rules, and every deploy passes automated checks for leaked secrets and injection. No system is perfectly secure, which is why the breach commitment in section 3 exists.
8 · Age
This site and the chapter sites are for adults. We don't knowingly collect information from anyone under 18.
9 · Changes and contact
If this policy changes in a way that matters, we'll update the date at the top and, for customers, tell the chapter's contact directly. Questions: hello@chapterroots.com.