PRIVACY POLICY
Effective Date: The date shown with the published version of this Privacy Policy.
1. WHO WE ARE
Catholic Mission Network, Inc. ("CMN," "we," "us," or "our") operates the SaT Catalyst Fund website, platform, and related services (collectively, the "Services") through its wholly owned operating arm, SaT Catalyst, LLC. CMN determines how and why personal information collected through the Services is used. SaT Catalyst, LLC supports CMN in operating the platform.
Our mailing address is 1595 Peachtree Parkway, STE 204-370, Cumming, Georgia 30041. Questions or privacy requests may be sent to info@satcatalyst.com.
2. SCOPE
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit the Services, create an account, apply for a Designated PRI Account, submit a project, make or arrange a contribution, sign or receive an investment document, communicate with us, or otherwise use the Services.
The Services are intended only for persons in the United States who are at least 18 years old and for authorized representatives of organizations. They are not directed to children.
This Privacy Policy does not replace a separate agreement that governs a Designated PRI Account, project financing, promissory note, charitable contribution, or other specific transaction. If a separate agreement requires additional information or retention, that agreement and applicable law also apply.
3. PERSONAL INFORMATION WE COLLECT
We collect information that you provide directly, information created through your use of the Services, and limited information from service providers used to operate the Services.
Account and identity information may include your name, email address, telephone number, organization, organization type, account role, login credentials in hashed form, verification status, and account timestamps.
Designated PRI Account and fund-application information may include donor and co-donor names and contact information, mailing addresses, advisor information, beneficiary-charity information, Donor Advised Fund provider or account references, account preferences, application answers, notes, acknowledgments, signature dates, and related approval records.
Project and financing information may include business and owner information, contact information, biographies, business plans, financial statements, projected financial information, requested loan terms, pitch materials, images, videos, uploaded files, application history, public-project content, and project updates.
Contribution, payment, and ledger information may include contribution amount, service fee, deployable amount, payment method category, payment status, transaction date, internal ledger references, check or grant status, and limited provider identifiers used for confirmation and reconciliation. Stripe collects payment-method and bank information through its hosted payment experience. We do not intentionally store complete bank-account or payment-card credentials in the SaT Catalyst application.
Investment-document and signature information may include the parties' names, document terms, signature text, signature status, dates and times, Internet Protocol address or a privacy-protected derivative where used, browser or device information, delivery status, document version, file integrity evidence, and audit events needed to establish the completed record.
QuickBooks information may include the authorized QuickBooks company name and identifier, connection status and scope, encrypted OAuth credentials while connected, exact QuickBooks entity identifiers selected by an authorized administrator, transaction date, amount, currency, visible reference, synchronization token, verification result, and audit timestamps. Raw QuickBooks response bodies and unrelated accounting records are not retained by the current integration.
Communications and support information may include information you provide in email, support requests, application notes, and other correspondence.
Usage, device, and security information may include page paths, referral source, approximate location, browser and device type, operating system, authentication and rate-limit events, privacy-protected email or Internet Protocol hashes, user agent, request identifiers, and security or error events. Vercel Web Analytics is configured as a privacy-focused service that reports aggregated usage without third-party analytics cookies or cross-site identification. We do not intentionally send submitted form contents, passwords, financial documents, or raw QuickBooks responses to analytics.
4. HOW WE USE PERSONAL INFORMATION
We use personal information to:
- provide, maintain, secure, and improve the Services; - create and authenticate accounts and respond to password-reset requests; - receive, review, approve, reject, archive, or administer Designated PRI Account and project applications; - maintain the fund transaction ledger, contribution status, fee calculations, account balances, project commitments, disbursements, repayments, and related accounting evidence; - generate, review, sign, retain, deliver, and audit investment and legal documents; - process payments through Stripe and reconcile payment events; - connect to and read approved records from QuickBooks when an authorized administrator enables the integration; - send transactional communications, application notifications, account notices, document notices, and support responses; - prevent fraud, abuse, unauthorized access, and other security incidents; - diagnose availability and performance issues using privacy-limited operational logs and aggregated analytics; - comply with legal, tax, accounting, recordkeeping, reporting, and regulatory obligations; - establish, exercise, or defend legal rights; and - carry out other purposes that we describe when information is collected or that you authorize.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use submitted applications, financial documents, QuickBooks data, or private account information to train general-purpose artificial-intelligence models.
5. WHEN WE DISCLOSE PERSONAL INFORMATION
Within CMN and SaT Catalyst. Authorized personnel and administrators may access information when needed to review applications, operate accounts, process transactions, administer documents, reconcile accounting, respond to support requests, or protect the Services. Access is limited according to job responsibility and system permissions.
Service providers. We use service providers to operate the Services. These currently include Vercel for application hosting, runtime infrastructure, BotID, and aggregated Web Analytics; Supabase for PostgreSQL database hosting and private object storage; Stripe for payment processing; Resend for transactional email; Upstash for rate limiting and short-lived upload-completion grants; and Intuit for QuickBooks authorization and accounting data when the QuickBooks integration is enabled. These providers process information under their own agreements and only for the functions for which we use them.
Transaction participants. We may disclose information to a donor, advisor, Designated PRI Account participant, project owner, borrower, beneficiary charity, accountant, or other transaction participant when needed to administer an approved account, contribution, project, investment, payment, or signed document. A user is not entitled to unrelated information about another user or account.
Legal and safety purposes. We may disclose information if reasonably necessary to comply with law, a valid legal process, tax or regulatory obligations, or enforceable government requests; to protect CMN, SaT Catalyst, users, or others; to investigate fraud or security events; or to establish, exercise, or defend legal claims.
Organizational transactions. If CMN reorganizes the platform or transfers operational responsibility to a controlled successor, information may be transferred subject to appropriate confidentiality, security, and use limitations. We will not treat a charitable or operational restructuring as permission to sell personal information for advertising.
With your direction. We may disclose information when you direct or authorize us to do so.
We do not expose QuickBooks credentials or raw QuickBooks data to platform users, Stripe, Resend, Upstash, advertising networks, or a general-purpose third-party API. If a managed accounting connector is added later, we will update this Privacy Policy and complete the required organizational review before using it with Production data.
6. COOKIES, SESSIONS, AND ANALYTICS
The Services use first-party session and security technologies needed to authenticate users, protect forms, maintain an authorized session, complete OAuth connections, and prevent abuse. Disabling these technologies may prevent protected account features from working.
Vercel Web Analytics provides aggregated page-view and technical statistics without third-party analytics cookies and without identifying the same visitor across different websites. We do not use advertising cookies or third-party behavioral-advertising trackers in the current Services.
7. PAYMENT AND QUICKBOOKS PROVIDERS
When you choose an online payment method, Stripe receives payment and bank information necessary to process the transaction, prevent fraud, and comply with its legal obligations. Stripe's handling of that information is also governed by Stripe's privacy terms. SaT Catalyst receives transaction status and limited provider references needed to update and reconcile the internal ledger.
When an authorized CMN or SaT administrator connects QuickBooks, Intuit provides OAuth authorization and approved Accounting API records. The current integration is admin-only and read-only: it does not create, edit, delete, void, or pay QuickBooks records. Connection credentials are stored server-side in encrypted form while the connection is active. Disconnecting revokes provider access and removes token ciphertext from SaT Catalyst, while limited connection and transaction-mapping evidence may remain for accounting and audit purposes.
8. RETENTION AND DELETION
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, tax, accounting, security, dispute, and recordkeeping needs.
Short-lived authorization state, upload grants, and similar transient security data expire automatically. Password-reset links expire after one hour. Privacy-limited runtime logs are targeted for no more than 30 days for most categories and 90 days for Stripe reconciliation events; a provider's native retention may be shorter. Vercel's daily analytics visitor identifier expires after 24 hours.
QuickBooks access and refresh tokens are retained in encrypted form only while a connection is active and usable. They are revoked and erased from SaT Catalyst on a completed disconnect and erased after a terminal refresh failure. Raw QuickBooks response bodies are processed for the requested read and then discarded.
Account profiles, submitted applications, uploaded materials, transaction records, signed documents, approval history, accounting mappings, and audit evidence are retained while the related account, application, contribution, project, loan, or legal obligation is active. Approved or linked applications, posted ledger entries, signed investment documents, contribution substantiation, and other financial or legal records may be retained after account closure when needed to preserve the authoritative history, comply with law, administer repayments or reporting, or resolve disputes.
When information is no longer needed and no retention obligation applies, we will delete it, de-identify it, or allow it to age out of provider backups under the applicable backup cycle. A deletion request will not require us to destroy another party's records or records we must retain, but we will limit retained information to the purpose requiring retention and restrict access to it.
9. SECURITY
We use administrative, technical, and organizational safeguards designed for the sensitivity of the information we handle. Current controls include role-based access, server-side authorization, private storage, encrypted network connections, password hashing, encrypted QuickBooks tokens, restricted database privileges, row-level security, privacy-limited logging, rate limiting, deployment review, and integrity checks.
No system can guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and for notifying us promptly if you believe your account or information has been compromised. If a security incident requires notice under applicable law, we will provide the required notice.
10. YOUR CHOICES AND REQUESTS
Subject to verification, applicable law, and necessary record retention, you may ask us to:
- confirm whether we maintain personal information about you; - provide access to or a copy of information associated with your account; - correct inaccurate profile or application information; - close your account or delete information that is not required for an active transaction, legal obligation, or authoritative record; - explain or object to a particular use or disclosure; - disconnect an authorized QuickBooks company; or - provide information about the service providers used for the Services.
Send requests to info@satcatalyst.com. We may need to verify your identity, authority, account relationship, or organizational role before acting. An authorized agent may submit a request where applicable, but we may require evidence of the agent's authority and may verify the request directly with you. We will not discriminate against you for making a privacy request.
Account closure or deletion may limit access to the Services and does not undo a completed contribution, signed agreement, posted transaction, or other action that is legally effective. If information relates to multiple parties, we will balance the request against the rights and records of those parties.
11. CHILDREN
The Services are not directed to anyone under 18, and we do not knowingly collect personal information from a child through the Services. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
12. UNITED STATES SERVICE
The Services are operated in the United States and intended for United States users and organizations. Information may be processed in United States regions by us and our service providers. Do not use the Services if you are not permitted to transfer information to and process it in the United States.
13. THIRD-PARTY SITES
The Services may link to third-party websites or services. We do not control their privacy or security practices. Review the privacy terms of a third party before providing information directly to it.
14. CHANGES TO THIS PRIVACY POLICY
We may revise this Privacy Policy to reflect changes in the Services, providers, law, or our practices. The published page will identify the effective date of the current version. If a change is material, we will provide additional notice or obtain renewed consent when required. An earlier version remains part of the record for actions governed by that version.
15. CONTACT US
Catholic Mission Network, Inc.
SaT Catalyst Fund Privacy
1595 Peachtree Parkway, STE 204-370
Cumming, Georgia 30041
Email: info@satcatalyst.com