Effective date: August 27, 2026
Stonebridge CRM, LLC, a Florida limited liability company ("Stonebridge," "we," "us")
Contact: info@stonebridgecrm.com
Stonebridge CRM is a management platform used by synagogues, congregations, and other membership-based and nonprofit organizations ("organizations") to manage their members, households, donations, pledges, invoices, and — where the organization chooses — a public website. Stonebridge CRM, LLC operates the platform. This policy explains what information moves through the platform, who controls it, and what we do and do not do with it.
One idea organizes everything below: most of the information in Stonebridge belongs to the organization that entered it, about its own members — not to us. We host it, protect it, and process it on that organization's instructions. We do not sell it, rent it, or use it for advertising. We do not use it to train artificial-intelligence models.
1. Organization members and their households. If a synagogue or other organization uses Stonebridge, its staff may record information about you as a member: your name and contact details, household and family relationships, membership status, donation and pledge history, invoices and payments, and — because many of our organizations are religious communities — religious lifecycle information such as Hebrew names, memorial (yahrzeit) dates, and family remembrance records. The organization, not Stonebridge, decides what is recorded and who on its staff may see it. We act as the organization's service provider. If you want to see, correct, or delete information an organization holds about you, contact that organization directly; we support them in honoring such requests, and we will refer any request we receive to the responsible organization.
2. Organization staff who sign in to Stonebridge. If you have a Stonebridge login, we hold your email address, authentication credentials (stored as one-way hashes — we cannot read your password), optional two-factor authentication enrollment, and records of administrative actions you take in the system. Action records exist for security and accountability and are retained as part of the platform's audit history.
3. Donors who give through an organization's public website. If you make a pledge or donation through an organization's Stonebridge-hosted site, we process the name, email address, and gift details you provide, on that organization's behalf. Payment card details never touch Stonebridge. When payment occurs, it happens on a payment page hosted by Stripe, our payment processor; we receive confirmation that a payment occurred, not your card number. We never receive, store, or transmit payment card numbers.
The platform collects limited technical information needed to run and secure the service: authentication session data, IP addresses in connection with security controls (for example, rate-limiting of the public giving flow), and error reports (via Sentry, our error-monitoring service) that may include technical details of a failure. We use browser storage only for essential functions such as keeping you signed in. We do not use advertising cookies, tracking pixels, or analytics that profile individuals.
We use information solely to provide, secure, support, and improve the service: operating the features organizations use, delivering the emails the service generates (invoices, receipts, statements, sign-in emails), preventing abuse, diagnosing errors, and maintaining backups so organizations' data survives failures. We do not use platform data for marketing to members or donors. We contact organization staff about the service itself.
We use a small set of established infrastructure providers to run Stonebridge. Each processes data only as needed to provide its function:
| Provider | Function | Notes |
|---|---|---|
| Supabase | Database, authentication, and server functions | Data is stored on Amazon Web Services infrastructure in the US East (N. Virginia) region |
| Stripe | Payment processing for organizations that enable it | Card details are provided by payers directly to Stripe and never pass through Stonebridge |
| Resend | Transactional email delivery (invoices, receipts, sign-in emails) | |
| Vercel | Application and website hosting, and DNS | |
| Sentry | Error monitoring | Receives technical error reports |
| Google Workspace | Our own business email (e.g., info@stonebridgecrm.com) |
We will update this list if our providers change. We do not share data with data brokers, advertisers, or any party not listed here, except where the law requires it.
Every organization's data is isolated from every other organization's data by access controls enforced in the database itself. Our own administrative access to an organization's production data is deliberately restricted: it requires a logged, time-limited, reason-stated grant, and those grants form a permanent audit record. Data is encrypted in transit. The database is backed up daily, and our restore procedure is tested, not assumed. Passwords are stored only as one-way hashes, with minimum-strength and known-breach checking applied by our authentication provider.
We describe our safeguards in the honest tense: they are the protections we actually operate today, and we improve them on a published-to-ourselves schedule as the platform grows. We do not claim certifications we do not hold: Stonebridge has no PCI-DSS attestation (we architecturally avoid handling card data instead) and no SOC 2 report at this time.
Organization data is retained while the organization's account is active and as long as needed for the audit and financial records the organization relies on. Database backups are kept on a rolling seven-day cycle, so deleted data may persist in backups for up to seven days before aging out. When an organization ends its relationship with Stonebridge, we will export its data to it and delete it from the live system on request, subject to any records we are legally required to keep.
Stonebridge is not directed to children, and children may not create accounts. Organizations may record household information that includes the names of minors in a family — for example, a family's membership record — as directed by the family's own community organization; that information is controlled by the organization, subject to the section above about member data.
Stonebridge is operated from the United States and data is stored in the United States (US East region). The service is offered to organizations in the United States; if you access it from elsewhere, you understand your information will be processed in the United States.
Because our customers are often religious communities, the fact that a person appears in an organization's Stonebridge records may itself suggest religious affiliation, and records may include religious lifecycle information. We treat all member data with the same protections regardless of its sensitivity, we process it only on the organization's instructions, and we never use it for any purpose beyond operating the service the organization signed up for.
If we change this policy, we will post the updated version with a new effective date and note what changed. If a change meaningfully reduces protections for information already in the system, we will notify organizations before it takes effect.
Questions, requests, or concerns: info@stonebridgecrm.com, or write to Stonebridge CRM, LLC, 4436 James Estate Lane, Lake Worth, FL 33449, USA.