Legal

Privacy Policy

Last updated: July 4, 2026

Conduit is a payment operations platform operated by MPQ Solutions (“Conduit,” “we,” “us”). We help organizations collect payments and donations through embeddable forms and automatically sync that activity to the CRM and accounting systems they already use. This policy explains what personal information we handle, why, who we share it with, and the choices you have.

Conduit plays two different roles depending on whose data is involved. For the organizations that subscribe to Conduit (their admins and account data), we act as a controller. For the payers and donors who submit an organization’s form, we act as a service provider / processor on that organization’s behalf — the organization decides why the data is collected and is the primary point of contact for those individuals.

1. Information we collect

Depending on how you interact with Conduit, we may collect:

  • Account information for organization admins: name, work email, organization name, role, and authentication data (we use a third-party auth provider; passwords are never stored in plaintext by us).
  • Payment form submissions from payers and donors: name, email, postal address, phone (where the form requests it), the amount, the fund or designation selected, whether fees were covered, and payment-method type (e.g. “card” or “bank”).
  • Transaction and sync records: amounts, fees, status, refunds, subscription state, and the status of syncing each record to your connected systems.
  • Technical and usage data: IP address, browser/device information, and log data used for security, rate-limiting, and troubleshooting.

We never collect or store raw card or bank account numbers. Payment details are entered directly into fields hosted by our payment processor, Stripe, so that sensitive cardholder data stays within Stripe’s PCI-DSS-compliant environment and never touches Conduit’s servers.

2. How we use information

  • To provide the service: render forms, calculate fees, create charges through Stripe, and sync records to your connected CRM and accounting systems.
  • To operate our own billing (subscription tiers and the per-transaction application fee).
  • To secure the platform: authentication, fraud and abuse prevention, rate-limiting, and audit logging.
  • To support you: respond to requests and troubleshoot issues.
  • To meet legal, tax, and accounting obligations.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

3. Payment processing and Stripe

Payments are processed by Stripe, Inc. When a payer submits a form, their payment details go directly to Stripe, and Stripe shares transaction data back with us and with the organization as needed to complete and reconcile the payment. Stripe processes personal data under its own agreements and privacy policy — please review the Stripe Privacy Policy and, for organizations connecting a Stripe account, the Stripe Connected Account Agreement.

4. How we share information

We share personal information only as needed to run the service:

  • With the organization whose form collected the data — they are the controller of their payers’ and donors’ information.
  • With the organization’s connected systems that they configure — their CRM (e.g. Salesforce) and accounting platform — so records post automatically. The organization controls which systems are connected.
  • With our subprocessors (below), who process data on our behalf under contract.
  • For legal reasons: to comply with law, enforce our terms, or protect rights, safety, and security.
  • In a business transfer: if Conduit or MPQ Solutions is involved in a merger, acquisition, or sale of assets, subject to this policy.

5. Subprocessors

We rely on a small set of infrastructure providers to run Conduit. Each processes data only to provide their service to us:

  • Stripe — payment processing.
  • Supabase — application database and authentication.
  • Vercel — dashboard hosting.
  • Railway — background sync worker hosting.
  • Cloudflare — embedded-form delivery and content delivery.
  • Resend — transactional email.
  • Sentry — error monitoring.

We’ll keep this list current and update it when our subprocessors change.

6. How we protect information

  • Data is isolated per organization at the database level (row-level security), so one organization can never read another’s records.
  • Connected-system credentials are stored using envelope encryption, not in plaintext.
  • Traffic is encrypted in transit (TLS). Sensitive payment data is handled entirely by Stripe.
  • Access is authenticated and privileged actions are audit-logged.

No system is perfectly secure, but we work to protect your information and to limit what we collect in the first place.

7. Data retention

We keep transaction and account records for as long as your organization maintains its Conduit account and as required for tax, accounting, and legal purposes, after which we delete or de-identify them. Organizations may request deletion of records subject to those legal retention requirements.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to be free from discrimination for exercising those rights. Because we do not sell personal information or use it for cross-context behavioral advertising, there is nothing to opt out of in that respect.

If you are a payer or donor, the organization whose form you used is the controller of your information — please direct requests to that organization, and we will assist them in fulfilling your request.

If you are an organization admin, contact us at the address below to exercise your rights over your account data.

9. Where we operate and children

Conduit is offered in the United States and is intended for use by organizations located there. The service is not directed to children, and we do not knowingly collect personal information from children.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify organizations through the dashboard or by email.

11. Contact us

Questions about this policy or your information? Email privacy@mpqsolutions.com.