Privacy Policy

This privacy policy discloses the privacy practices for and any other web site operated by NumFOCUS, Inc., P.O. Box 90596, Austin, Texas, 78709 (“Provider”), and all related technologies, software, and services provided by Provider (collectively, the “Services”), including: (i) information you provide through your user account on the Services (your “Account”) if you register for the Services; (ii) your use of the Services; and (iii) from third-party websites, services, and partners. This privacy policy applies solely to information collected by the Services. It will notify you of the following:

  • What personal data is collected from you through the Services, how it is used and with whom it may be shared.
  • What choices are available to you regarding the use of your personal data.
  • The security procedures in place to protect the misuse of your personal data.
  • How you can correct any inaccuracies in your personal data.

If you have any questions about this Privacy Policy or NumFOCUS’s data collection, use, and disclosure practices, please contact us at

Information Collection, Use, and Sharing 

We have access to/collect information that you voluntarily provide to us via email, online forms or other direct contact from you, such as your name, email address, home address, telephone number, and credit card information.

We will use your information to deliver the services you have requested, respond to you regarding the reason you contacted us, maintain our records, customize the content and layout of the Services, and to contact you regarding information about the Services, including updates and, with your consent, new services.

As is true of most websites, we also gather certain information automatically and store it in log files based upon usage of our Services.  This information includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and click-stream data.  We use this information, which does not identify individual users, to analyze trends, to administer the Services, to track users’ movements around our sites and to gather demographic information about our user base as a whole.  We do not link this automatically-collected data to personal data. For detailed information on our use of cookies, see the Cookies section below.

We may share your personal data with third parties outside of our organization as necessary to provide the Services to you and to secure the Services.  Identifying and non-identifying user information and data may be disclosed or distributed to a third party with which we enter or reasonably may enter into a corporate transaction, such as credit card processing.  

We transmit your personal data to the third parties named below in order to provide the Services to you and to secure the Services. To the best of our knowledge, your personal data will be processed and stored in the United States, insofar as the named parties are based in the United States. Your data may be processed and stored in another country if the parties named below use non-U.S. facilities for data storage and processing.

  • Cloudflare (U.S.)
  • Eventbrite (U.S.)
  • Flipcause (U.S.)
  • Google (U.S.)
  • Little Green Light (U.S.)
  • Mailchimp (U.S.)
  • TypeForm (Spain)
  • WordPress (U.S.)
  • WP Engine (U.S.)
  • Zapier (U.S.)
  • NumFOCUS Staff (U.S.)
  • NumFOCUS Committee Members (U.S., U.K., Germany, Poland, The Netherlands, Italy, India, Argentina, France, Spain)
  • NumFOCUS Board Members (U.S., Belgium, Canada)

We will disclose information we maintain when required to do so by law or in the good faith belief that such action is necessary to: (a) conform to the edicts of the law or comply with legal process served on us; (b) protect and defend our rights or property; and, (c) act under exigent circumstances to protect the personal safety of our users or the public.

Aggregated demographic information may be shared with our partners and/or affiliates. This is not linked to any personal information that can identify any individual person.  


Our Services may contain links to other sites. Please be aware that we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.


The Services use cookies and other similar technologies, in accordance with industry standards.  A cookie is a piece of data stored on a site visitor’s hard drive to help us improve your access to the Services and identify repeat visitors to the Services. For instance, when we use a cookie to identify you, you would not have to enter a password more than once, thereby saving time. Cookies can also enable us to track and target the interests of our users to enhance the user experience. We store information that we collect through cookies, log files, and/or clear gifs to record your preferences. We may also automatically collect information about your use of features of the Services, about the functionality of the Services, frequency of visits, and other information related to your interactions with the Services. We may track your use across different websites and services. In some countries, including countries in the European Economic Area (“EEA”), the information referenced above in this paragraph may be considered personal information under applicable data protection laws. Usage of a cookie is in no way linked to any personally identifiable information on our sites.

As stated above in the section on Information Collection, Use, and Sharing, we use this information, which does not identify individual users, to analyze trends, to administer the Services, to track users’ movements around our sites and to gather demographic information about our user base as a whole.

We use analytics providers such as Google Analytics. Google Analytics uses cookies to collect non-identifying information. Google provides some additional privacy options regarding its Analytics cookies at

If you are uncomfortable with the idea of your information being used in this way, most computer systems and web browsers offer privacy settings and options, such as disabling cookies or opting for “Do Not Track” features. We do not override these settings or options, and encourage you to use them to enhance your choices and personalize your experiences.

Many browsers have an option for disabling cookies, which may prevent your browser from accepting new cookies or enable selective use of cookies.


We use physical, electronic, and procedural safeguards to protect your information.  Our infrastructure is hosted and managed within WP Engine. WP Engine manages risk and undergoes recurring assessments to comply with industry standards.

Wherever we collect financially sensitive information (such as credit card data), that information is encrypted and transmitted to us in a secure way. You can verify this by looking for a closed lock icon at the bottom of your web browser, or looking for “https” at the beginning of the address of the web page.

We also protect your personal data offline. Only employees or NumFOCUS representatives who need the information to perform a specific job (for example, billing or customer service) are granted access to personal data. The computers/servers in which we store personal data are kept in a secure environment.

Please be advised that the security and confidentiality of any communication or material transmitted through the Internet or any wireless network, including via the Services, email or text messages, cannot be and is not guaranteed.

Legal Basis for Processing Personal Information

Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.

However, we will normally collect personal information from you only (i) where we need the personal information to perform a contract with you; (ii) where the processing is in our legitimate interests and not overridden by your rights; or (iii) where we have your consent to do so.  We have a legitimate interest in operating our Services and communicating with you as necessary to provide these Services, for example when responding to your queries, improving our platform, undertaking marketing, or for the purposes of detecting or preventing illegal activities.

In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.

If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).

Data Retention

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements).

We retain personal data collected by Google Analytics for a period of 38 months. For NumFOCUS members, donors, event attendees, contractors, and mailing list subscribers, personal data is retained for the lifetime of the NumFOCUS organization. Please see the next section, Your Data Protection Rights Under the General Data Protection Regulation (GDPR), for information on how to access, correct, update, or request deletion of your personal data.  

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

The information you provide us may be archived or stored periodically by us according to backup processes conducted in the ordinary course of business for disaster recovery purposes.

Your Data Protection Rights Under the General Data Protection Regulation (GDPR)

You can do the following at any time by contacting us via email at

  • See what data we have about you, if any.
  • Change/correct any data we have about you.
  • Have us delete any data we have about you.
  • Express any concern you have about our use of your data.

To protect your privacy and security, we may also take reasonable steps to verify your identity before updating or removing your information.

If you are a registered user, you may access certain information associated with your Account by logging into our Services or emailing If you terminate your Account, any public activity on your Account prior to deletion may remain stored on our servers and may remain accessible to the public.

If you are a resident of the EEA, you have the following data protection rights:

  • If you wish to access, correct, update, or request deletion of your personal data, you can do so at any time by emailing . Such requests may or may not be honored, depending upon the specific circumstances of the request, as enumerated in the GDPR.
  • In addition, you can object to the processing of your personal information, ask us to restrict the processing of your personal information, or request portability of your personal information. Again, you can exercise these rights by emailing . Such requests may or may not be honored, depending upon the specific circumstances of the request, as enumerated in the GDPR.
  • You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” link in the marketing emails we send you or by emailing
  • Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time.  Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Your Choices

You can use some of the features of the Services without registering, thereby limiting the type of information that we collect.

You may unsubscribe from receiving certain promotional emails from us. If you wish to do so, simply follow the instructions found at the end of the email. Even if you unsubscribe, we may still contact you for informational, transactional, account-related, or similar purposes.


Our Privacy Policy may change from time to time and all updates will be posted on this page.

If you have any questions or concerns about this privacy policy, please contact us via email at

The data controller of your personal information is:

NumFOCUS, Inc.
P.O. Box 90596
Austin, TX, USA 78709
+1 ​(512) 222-5449

For the purposes of GDPR, our NumFOCUS representative in the EU is Didrik Pinte, NumFOCUS Treasurer, (Belgium).

July 17, 2018

A history of updates to this privacy policy can be found on GitHub at


I’ve learned so much through the use of your software, and the tools and have really helped many of my ideas come to fruition.

Santiago Gonzalez, Community Member