Skip to main content
Privacy

Privacy

Golbi is built for people records, families, signups, dues, files, checklists, and staff activity. Those records need clear rules and simple defaults.

Golbi is built for people records, families, signups, dues, files, checklists, and staff activity. Those records need clear rules and simple defaults.

This is group data, not social media data

  • People and families. Groups need names, roles, emails, family links, teams, and guardian links to run programs. That data should stay inside the group.
  • Dues and payments. Balances, payment status, waivers, payment notes, and payment matching details are private money data. They should not show in public rosters or member lists.
  • Checklists and files. Training records, signed forms, uploads, review notes, due dates, and private files may be sensitive. Only the right person, guardian, or staff member should see them.

Show less unless the task needs more

  • Public pages should show group content, not private member data.
  • Member-only pages should require login and active membership.
  • Member and guardian pages should show only their own family information.
  • Staff pages should be limited by role.
  • Sponsors, partner campaigns, and planned messages should never get private member lists.
  • Important private admin actions should be saved in history.
  • Marketing examples should use totals or made-up data, not real personal information.

Your group still has decisions to make

Clubs, teams, schools, and nonprofits may have their own rules for consent, record keeping, child safety, medical information, payment records, volunteer checks, school verification, and public pages. Golbi can help organize the work, but each group still decides what it collects and how long it keeps it.

How long we keep your data

We keep different kinds of data on different clocks:

  • Group records you and your organization create — people, families, memberships, signups, forms, files, and checklists — are kept for as long as your organization needs them to run its programs. When you or your organization ask us to delete them, we remove the personal details and keep only what the law requires us to keep.
  • Payment and dues records may be kept after a deletion request when we need them for tax, accounting, or dispute-handling reasons. When we do, we keep the money record but remove the personal identity attached to it where we can.
  • Children's data is kept only as long as needed for the program it was collected for, or as required by law, and is covered by our Child Privacy Notice.
  • Operational data — sign-in tokens, sessions, delivery logs, and similar behind-the-scenes records — is kept only while it is needed and is cleared on a short schedule once it expires.
  • Security and audit logs that record important private admin actions are retained so your organization can review them, and are removed on the retention schedule your organization sets (kept until then if no schedule is set).

We publish the full, per-category retention schedule (what we keep, for how long, and how we dispose of it) as an internal compliance document and reconcile it with the deletion tools built into Golbi.

If there is ever a data security incident

If personal information is ever exposed, we follow a documented incident-response and breach-notification procedure. We investigate and contain the incident, notify affected organizations without unreasonable delay so they can meet their own legal obligations, and — where the law requires it — support notice to affected individuals and regulators within the timelines set by the applicable state laws.

Payment processing

When your organization subscribes to a paid plan, billing is handled by our payment processor, Stripe. Golbi does not store card numbers; payment details are handled by Stripe under its own terms.

Run your group on a platform that respects your data.

Set up the basics now and bring your team in when you are ready.