CauseComp Privacy Policy
Effective date: July 12, 2026
This Privacy Policy explains what information RB Consulting Services, LLC (“we,” “us”) collects when you use CauseComp at www.causecomp.org, how we use it, who we share it with, and the choices you have.
The short version: we collect only what we need to run the Service, we don’t sell your data, and we’ll delete your data if you ask. The details follow.
1. Information We Collect
Information you give us:
- Account email address — used to create and secure your account and to send you service-related email.
- Organization name — used to personalize your account and reports.
- Password — stored only as a cryptographic hash. We cannot see your actual password.
- Lead information — if you request a demo, download a sample report, or contact us, we collect the contact details you provide (such as name, email, organization, and role).
- Payment information — collected and processed directly by Stripe, our payment processor. We never store your credit card numbers. We receive only limited billing information from Stripe, such as your subscription status and the last four digits of your card.
Information collected automatically:
- Search and query history — the benchmark searches and report parameters you run, which we use to power your account features, support you, and improve the Service.
- Session and usage data — standard technical data such as IP address, browser type, pages viewed, and timestamps, collected through server logs and cookies (see Section 4).
- API and connector credentials and activity — if you enable API access or connect CauseComp to an AI assistant (such as Anthropic’s Claude), we create and store credentials for that access: API keys (stored only as cryptographic hashes, like passwords) and OAuth authorization grants and tokens. We also keep a log of each metered request made with them (requests for benchmarks, comparables sets, board reports, and filing data): the time, your account email, the request inputs (such as role, sector, state, and budget-size parameters), a summary of the result where there is one (such as the median returned, its confidence label, the number of observations behind it, or the number of filing rows returned), and the key or grant that made it. Lookups (matching role, sector, state, or metro names, finding an organization by name, or reading the methodology) are not recorded in this log. We use this log to meter your daily request quota, detect abuse, secure the Service, and support you.
What we don’t collect: we don’t ask for or store compensation data about your individual employees, and we don’t collect sensitive personal information. Our benchmarks are built entirely from public government data (IRS Form 990 filings and BLS/O*NET datasets), not from data our users provide.
2. How We Use Your Information
We use the information above to:
- Provide, secure, and maintain the Service and your account;
- Process subscriptions and payments (via Stripe);
- Send transactional email — receipts, renewal notices, password resets, and important service announcements (via Resend);
- Respond to support requests;
- Understand how the Service is used so we can improve it;
- Send occasional product updates or marketing to leads and users, which you can opt out of at any time via the unsubscribe link;
- Comply with legal obligations.
3. What We Don’t Do With Your Information
- We do not sell your personal information.
- We do not share your personal information with third parties for their own marketing.
- We do not use your search history to build products for anyone else, and we don’t disclose which organizations use CauseComp, except with your permission.
4. Cookies and Sessions
We use a small number of cookies, and they’re the boring kind:
- Essential cookies — keep you logged in and keep your session secure. The Service doesn’t work without them.
- Optional analytics cookies — Google Analytics 4 sets first-party cookies (
_gaand_ga_*) to measure how the site is used. These are optional: you can opt out of them (see below), and CauseComp works fully without them. - Advertising attribution — if you arrive from a Google ad, our server records that ad's click identifier and keeps it in the same cookie that signs you in, and on your account if you register — so a signup or purchase you make later, including on another device, can be matched to the ad that first brought you here. We use it to see which ads bring people to CauseComp. We don't use it to show you ads or to follow you around other websites, and we never sell or share it. We keep it for as long as your account exists, and delete it when the account is deleted.
- Conversion measurement cookies — if you arrive from a Google ad, Google Ads conversion tracking sets first-party cookies on causecomp.org (
_gcl_*) and, when you complete a purchase, reports that purchase and its amount to Google Ads so we can tell which ads led to paid subscriptions. Ad personalization and Google Signals are turned off for this too, so it measures our own ads' results and is not used to build advertising profiles, show you ads elsewhere, or track you across other websites. Free signups are not reported as purchases.
Analytics — we use Google Analytics 4 (Google LLC), a third-party analytics service, to understand how visitors use CauseComp: which pages are viewed, how features are used, and how people find us. Google Analytics sets first-party cookies on causecomp.org and processes this usage data on Google's servers as our processor.
Session replay — we use Microsoft Clarity (Microsoft Corporation) to see how visitors actually use the site: where people click and scroll, and where they get stuck. Clarity records your interactions with the page and replays them for us as an anonymized session. We have configured it to mask what you type into the benchmark and contact forms, so the values you enter are not captured. Clarity sets Microsoft cookies, including _clck, _clsk, CLID, ANONCHK, MR, MUID and SM. MUID is a Microsoft identifier that can be read across other sites that use Microsoft services, so unlike our analytics cookies it is not confined to causecomp.org. We use Clarity to improve the site, not to advertise to you.
We use Google Analytics for measurement only. Google's advertising features are turned off — no Google Signals, no ad personalization, and none of Google's cross-site or cross-device ad tracking. Apart from the ad-click identifier and the conversion measurement cookies described above, we run no retargeting pixels and no advertising cookies of our own, and we never sell your data. The one exception we want to state plainly is the Microsoft Clarity cookie MUID described above, which is cross-site by nature.
Analytics cookies are optional: you can opt out anytime with Google's opt-out add-on (tools.google.com/dlpage/gaoptout) or your browser's cookie controls, and CauseComp works fully without them. Because there's still no agreed standard for honoring "Do Not Track" signals, we don't rely on them — use the opt-out above instead. That opt-out applies to the analytics cookies; the ad-click identifier above is recorded by our own server and is not affected by it.
5. Service Providers (Our Processors)
We use a small set of well-known providers to run CauseComp. Each receives only the data it needs to do its job, and each is bound by its own contractual and legal obligations:
| Provider | What it does | What it handles |
|---|---|---|
| Microsoft | Session replay and heatmaps (Microsoft Clarity) | Anonymized recordings of how you interact with pages — clicks, scrolling and navigation — plus the cookies listed in Section 4. Form inputs are masked |
| Sentry | Error monitoring (active only when configured) | Technical details of application errors: the page and request that failed, a stack trace, and browser and IP information. It may incidentally include the account email associated with the failing request |
| Stripe | Payment processing | Payment and billing details (we never store card numbers), and — for purchases that came from an ad — the ad click identifier described in Section 4 |
| Resend | Transactional email delivery | Your email address and the content of service emails |
| Render | Application and database hosting (US region) | All Service data, hosted in the United States |
| Cloudflare | DNS and network security | Standard network traffic data (such as IP addresses) |
| Make.com | Lead-intake automation | Name, email, organization, and message from contact and demo-request forms |
| Google (Google Analytics 4) | Website usage analytics — measurement only; advertising features disabled | Usage data (pages viewed, feature usage, referrer, device/browser type, approximate location). In GA4, IP addresses are used only momentarily to derive coarse location and are not logged or stored. |
| Google (Google Ads) | Conversion measurement for our own ads — ad personalization and Google Signals disabled | The ad click identifier, and the fact, amount, and currency of a completed purchase. No name, email, or organization is sent. |
We don’t share your personal information with anyone else, except: (a) if required by law, subpoena, or court order; (b) to protect the rights, safety, or property of our users or the public; or (c) in connection with a merger, acquisition, or sale of the business — in which case this Privacy Policy would continue to apply to your data and we would notify you of any material change.
If you connect CauseComp to an AI assistant, your queries and our responses also pass through that provider’s systems at your direction — see “AI Assistants and the CauseComp Connector” below.
6. AI Assistants and the CauseComp Connector
CauseComp offers a connector that lets eligible paid subscribers run benchmark queries from inside third-party AI assistants (currently Anthropic’s Claude) after signing in and granting access through OAuth. If you choose to connect:
- You authenticate on our site and consent to the assistant running benchmark queries on your behalf. You can end this access at any time by disconnecting the connector inside the AI assistant or by contacting us at support@causecomp.org, and we will revoke the grant on our side.
- Your benchmark queries and our responses pass through the AI provider’s systems (for Claude, Anthropic PBC). The AI provider handles that data under its own terms and privacy policy; we don’t control what the assistant retains or how it presents our data. The connector sends us only the benchmark request itself — never your surrounding conversation with the assistant.
- We log connector requests the same way we log API requests (Section 1), and for the same purposes: quota metering, abuse detection, security, and support. The lookups the connector makes to match your wording to our lists of roles, sectors, states, and metro areas, to find an organization by name, or to read our methodology are not recorded in that log and do not count against your quota.
The AI provider is not our service provider. It acts at your direction when you connect your account, and nothing in Section 5 limits what you choose to send through it.
7. Data Storage and Security
- All data is hosted in the United States (on Render, US region).
- Data is encrypted in transit (HTTPS/TLS). Passwords are stored only as hashes.
- API keys are stored only as hashes, like passwords.
- We limit access to personal information to what’s needed to operate and support the Service.
No system is perfectly secure, and we can’t guarantee absolute security — but if we learn of a breach affecting your personal information, we’ll notify you as required by applicable law.
8. Data Retention and Deletion
- We keep your account information while your account is active. Your search history is part of the query log described below and is kept for 12 months from each search.
- You can request deletion of your account and personal data at any time by emailing us (Section 13). We’ll complete the deletion within 30 days, except for three kinds of records: records we’re legally required to keep (like billing records for tax purposes); query log entries, from which your email address is removed when your account is closed and which are deleted when they reach 12 months old (see below); and residual copies in routine encrypted backups, which age out on a fixed schedule.
- If you cancel a paid plan but keep your free account, we retain your account data as described above until you request deletion.
Query logs (Section 1) are kept for 12 months for quota metering, abuse detection, security, and support, and are then deleted. The deletion runs once a week, so an entry may remain for up to a week past 12 months. When you close your account, we remove your email address from its query log entries; the rest of each entry stays until it reaches 12 months old. When an API key or connector grant is revoked, including when you close your account, we keep the record that it existed for 12 months after the revocation, and then delete it in the same weekly run. Routine encrypted backups age out within 35 days.
9. Your Rights and Choices
You can, at any time:
- Access and update your account information in your settings;
- Export your reports (Excel/PDF) while your subscription is active;
- Opt out of marketing email via the unsubscribe link (transactional email, like receipts, will still be sent);
- Request a copy or deletion of your personal data by emailing us.
Depending on where you live, you may have additional rights under state privacy laws. We honor access and deletion requests from all users regardless of location — so in practice, you don’t need to figure out which law applies to you. Just ask, and we won’t discriminate against you for exercising these rights.
U.S. state privacy rights. Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, and others), you may have the right to: know and access the personal information we hold about you; correct inaccurate information; delete it; receive a portable copy; and opt out of the sale or sharing of personal information, targeted advertising, and profiling. CauseComp doesn’t sell personal information, doesn’t “share” it for cross-context behavioral advertising, and doesn’t use it for targeted advertising or profiling — so there is nothing to opt out of; the other rights work as described in this section. We honor these requests for all users regardless of state, you may use an authorized agent to submit them, and we won’t discriminate against you for exercising them. If we decline a request, we’ll tell you why, and you may appeal by replying to our response; we’ll answer your appeal within 45 days. We treat Global Privacy Control signals the same way we treat Do Not Track (Section 4).
10. Children
CauseComp is a professional tool for organizations. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we’ll delete it.
11. International Users
CauseComp is operated from the United States, and our benchmarks cover U.S. compensation data. If you use the Service from outside the U.S., you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your location.
12. Changes to This Policy
If we make material changes to this Privacy Policy, we’ll notify you by email or in-app notice before the changes take effect, and we’ll update the effective date at the top. Minor clarifications may be posted without separate notice.
13. Contact Us
For privacy questions, data access requests, or deletion requests, email us at support@causecomp.org with the subject line “Privacy Request” and we’ll respond within 30 days.
RB Consulting Services, LLC · Florida, USA