Skip to content
MissionOSBack to MissionOS

Data processing addendum

How MissionOS processes the personal information campaigns keep in their workspaces.

This version applies to real MissionOS accounts. This preview has no accounts, so the demo terms and privacy notice apply here.

Version 2, effective October 1, 2026

Roles

This addendum is part of the Terms of service between MissionOS and the customer. For personal information the customer puts into or collects through MissionOS (“customer personal data”), the customer is the controller (or business), and MissionOS is its processor (or service provider).

Processing only on instructions

MissionOS processes customer personal data only to provide, secure and support MissionOS, following the customer’s documented instructions. Those instructions are these terms, the customer’s settings and its requests to support. If an instruction appears to break the law, we’ll say so.

MissionOS won’t sell or share customer personal data, won’t keep, use or disclose it for any other purpose, won’t combine it with information from other sources except as allowed for providing the service, and won’t use it outside the direct business relationship with the customer.

Details of the processing

  • Subject matter and duration: providing MissionOS for the length of the subscription, plus the export and deletion periods below.
  • Nature and purpose: storage, organization, search, messaging, publishing, import and export, and reporting, as the customer directs.
  • People concerned: the customer’s supporters, volunteers, donors, event guests, website visitors who submit forms, contacts, and team members.
  • Types of data: names and contact details, addresses, tags and notes, support levels and political preferences the customer records, contribution records (including employer and occupation), event and volunteer history, messages and delivery results, files, and form submissions.
  • Sensitive data: records may reveal political opinions or affiliations. The customer decides whether to record them and must have a lawful basis to do so.

Our people

Everyone at MissionOS who can access customer personal data is bound by confidentiality and trained on these obligations. Support staff can access a workspace only through a request on a support ticket that an owner or administrator approves. The access is time-limited and logged in the workspace.

Security measures

MissionOS maintains at least these measures:

  • Encryption in transit (TLS) and at rest.
  • Separate data for each workspace, enforced on every request, with role- and scope-based permissions.
  • Two-step verification for owners, billing managers and MissionOS staff, and a fresh confirmation before sensitive actions.
  • Audit logs of sensitive actions and of all support access.
  • Uploaded files checked for malware before they can be opened or shared. Share links expire.
  • Backups with tested restores. Least-privilege access to production. Prompt security updates.

Subprocessors

The customer authorizes the subprocessors listed below. We have written contracts with each that protect customer personal data at least as well as this addendum. We’ll give at least 30 days’ notice before adding or replacing a subprocessor. If the customer objects on reasonable data-protection grounds and we can’t resolve it, the customer may cancel the affected service and receive a prorated refund.

  • Vercel: hosting the website, the app and campaign websites, and private file storage with a separate private backup store (Vercel Blob).
  • Neon: database hosting.
  • Cloudflare: bot checks on public forms (Turnstile).
  • Clerk: sign-in, email verification and two-step verification.
  • Stripe: subscription billing, payment processing and sales tax calculation.
  • Resend: sending email.

Helping the customer

MissionOS gives customers tools to find, correct, export and delete supporter records. If someone asks us directly about a campaign’s records, we’ll send them to the campaign and won’t respond ourselves unless the customer asks us to. We’ll reasonably help with data protection assessments and regulator requests about MissionOS.

Security incidents

We’ll notify the customer without undue delay, and within 72 hours, after confirming a security incident affecting customer personal data. We’ll share what we know about what happened, the data affected and the steps taken, and update the customer as we learn more.

Information and audits

On request, once a year, we’ll answer reasonable security questionnaires and share summaries of our security practices and any independent assessments. Where the law requires more, we’ll cooperate with an audit on reasonable notice, at the customer’s cost, in a way that protects other customers’ information.

Returning and deleting data

Owners can export customer personal data at any time while the workspace is active, and for 30 days after it closes. We keep it for three years after the workspace closes and then delete it, except where the law requires us to keep it longer. While we keep it, we protect it under this addendum.

Where data is processed

Our primary application database and private file store are configured in United States regions. Service providers may process information in other locations to provide the service.

Contact us

Send questions and notices about this addendum to:

  • Mail: MissionOS LLC, 4480 Sheldon Rd, Rochester, MI 48306
  • Email: help@missionos.us