Privacy Policy

Effective October 2, 2026

How Conferus collects, uses, shares and protects personal information, and the choices you have.

1. Who we are

Conferus is a service of Night Raven Enterprises LLC, a New Mexico limited liability company ("Conferus," "we," "us"). Conferus is software that membership organizations — associations, chambers of commerce, clubs, nonprofits and their chapters — use to manage members, dues, events, communications and their books.

Questions about this policy or your personal information: privacy@conferus.net. Legal notices: legal@conferus.net.

2. Our two roles

When an organization uses Conferus to manage its members, donors, event guests and contacts, the organization decides what information to collect and how to use it. For that information the organization is the controller (or "business"), and Conferus is its processor (or "service provider"), handling it only on the organization's instructions under our Data Processing Addendum. If you are a member, donor or guest of an organization that uses Conferus, please contact that organization first about your information; we will help them respond.

Conferus is the controller of the information described in Section 3: the accounts of people who sign up and work in Conferus for their organization, our own billing, visitors to our website, newsletter subscribers, and support requests.

3. Information we collect as controller

  • Account information: name, email address, password (stored only as a secure hash by our authentication provider), role and permissions, and the organization you belong to.
  • Organization and billing information: the organization's name, address, tax ID, plan and billing email. Payment cards for your Conferus subscription are collected and stored by Stripe; we keep only Stripe's customer and subscription references.
  • Agreement records: who accepted the Organization Agreement or Data Processing Addendum, when, and which version.
  • Support and communications: messages you send us and our replies.
  • Newsletter: your email address, language and topic preferences, and confirmation and unsubscribe history.
  • Technical information: IP address, browser and device details, pages requested and error reports, used to run, secure and fix the service, for example to limit repeated login attempts.

4. Information organizations store in Conferus

Organizations decide what they store. Typically this includes members' names, email addresses, phone numbers and contact preferences, mailing addresses, photos, member numbers, membership level and status, dues and payment history, donations, event registrations and check-ins, and the organization's own accounting records. Card and bank account numbers used for online payments are entered on Stripe's pages and stay with Stripe; Conferus does not receive or store them.

Organizations should not store sensitive information (such as health information or government ID numbers) unless they need it and have a lawful basis to do so. Only the last four digits of a contractor's taxpayer number are stored.

5. How we use information

  • To provide, maintain and support Conferus, including sending the emails organizations ask us to send on their behalf.
  • To bill for subscriptions and keep financial and tax records.
  • To keep the service secure: authentication, rate limiting, fraud and abuse prevention, and the automated review of bulk emails and public content described in the Organization Agreement.
  • To fix problems and improve the service.
  • To send our newsletter, only if you subscribed, and service announcements to account holders.
  • To comply with the law and enforce our agreements.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use the information organizations store in Conferus for our own marketing.

6. AI features

Some features use an AI model provided by Anthropic: drafting and translating emails and pages, suggesting categories, reading an uploaded member list during import, drafting support replies, and reviewing outgoing bulk emails and public content for prohibited material. Only the content needed for that feature is sent. Under Anthropic's commercial terms, this content is not used to train its models.

7. Who we share information with

  • Subprocessors that host and run the service for us, listed with their purpose on our Subprocessors page. They may use the information only to provide their service to us.
  • Stripe, when an organization connects its own Stripe account: payments its members make go to that account under Stripe's own terms with the organization.
  • The organization you belong to, for information in its account.
  • Authorities or others when required by law, or to protect the rights, safety and property of our users, the public or Conferus.
  • A buyer or successor if Conferus is involved in a merger, acquisition or sale of assets, subject to this policy.

8. Cookies and similar technologies

Conferus uses only cookies and browser storage needed to run the service: to keep you signed in, and to remember your language and light or dark theme. We do not use advertising or cross-site tracking cookies.

On our public website pages (home, pricing, blog, legal, security, sign-up and login) we measure traffic and page speed with our own privacy-friendly analytics, without cookies. We record the page visited, the referring site, the visitor's country, device type, language and page-load timings. To count unique visitors, we combine a visitor's IP address and browser details into a one-way code that uses a random value we delete after two days, so it cannot be linked across days; we do not store IP addresses or user IDs for analytics. We do not count signed-in users, and we honor Do Not Track and Global Privacy Control signals. We keep these records for up to 400 days.

9. How long we keep information

We keep information for as long as the account is active and as described in our Data Retention Policy. When an organization's subscription ends, its data is kept for 90 days so it can be reactivated or exported, then deleted, except records we must keep by law (such as our own billing and tax records and signed agreements).

10. Security

Connections to Conferus are encrypted, data is encrypted at rest by our hosting provider, and each organization's data is kept separate by database access rules. Staff access within an organization follows the roles and permissions its administrators set, and financial changes are recorded in an activity log. No system is perfectly secure; if we learn of a breach affecting your information we will notify you or the organization as the law requires. More detail is on our Security page.

11. International transfers

Conferus and its subprocessors operate in the United States. If you use Conferus from another country, such as the Dominican Republic or a member state of the European Union, your information is transferred to and processed in the United States. Where the law requires, we rely on appropriate safeguards for these transfers, such as standard contractual clauses.

12. Your rights and choices

Depending on where you live (for example under US state privacy laws, the Dominican Republic's Law 172-13 or the GDPR), you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, to object to or restrict some uses, and not to be treated differently for exercising these rights.

  • Account holders can update their details in Conferus, or write to privacy@conferus.net.
  • Newsletter subscribers can unsubscribe from any newsletter, and download or delete their data from the newsletter preferences page.
  • Members, donors and guests of an organization should contact that organization; we will help it respond.

We will verify your request before acting on it and respond within the time the law requires. You may also complain to your local data protection authority.

13. Children

Conferus is a tool for organizations and is not directed to children under 13. We do not knowingly collect personal information from children for our own purposes. An organization that stores information about minors (for example, youth members) is responsible for obtaining any consent the law requires from a parent or guardian.

14. Changes to this policy

We will post any changes on this page with a new effective date. If a change is material, we will also notify account holders by email or in Conferus before it takes effect.

Questions? Write to legal@conferus.net.