Meridian Group
Privacy Policy

One policy covering every Meridian Group software product. Product-specific technical detail is in Annex P-1 at the end.
Version 1.2  •  August 22, 2026  •  Revises version 1.1 of August 15, 2026  •  Effective date: August 22, 2026  •  Supersedes: Passage Privacy Policy (Aug 14, 2026). Meridian Voyager remains governed by the Privacy Policy accepted within the product (version 2026-08-22) until it adopts this policy

1. Who We Are

This Privacy Policy explains how Meridian Group, a company organized under the laws of the State of New Mexico with its address at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110 ("Meridian Group," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with its software products (each a "Service," together the "Services"). The Services covered are listed in Schedule A of our Terms of Service and currently comprise Meridian Voyager and Passage.

Meridian Group is the only entity that operates the Services. No affiliate, parent, subsidiary, trade name, brand name, or third-party account name under which our software or content may be developed, hosted, or published operates a Service, controls or processes personal information in connection with a Service, or carries any obligation under this policy. Meridian Group alone is responsible for the practices described here.

Our website is meridian-group.ai. You can reach us at privacy@meridian-group.ai.

2. Our Two Roles

Which rules apply depends on whose data is involved.

Whose dataOur roleWhat that means
Visitors to our websites Controller (or "business") We decide why and how it is processed. This policy is the notice.
Customer staff and other authorized Users of a workspace Controller for account administration and security; processor for anything the Customer directs We hold a small amount of account data to run the Service and keep it secure.
End Users: a nonprofit's donors and constituents, a museum's members, and anyone else whose record a Customer puts into a workspace Processor (or "service provider") The Customer organization is the controller. We process that data only on the Customer's documented instructions, to provide the Service. Our obligations are set out in our Data Processing Agreement.

If you are an End User, your relationship is with the organization that holds your record. See Section 12.

Data Processing Addendum. We will enter into a Data Processing Addendum with Customers that require one. To request it, write to legal@meridian-group.ai.

3. What We Collect and Why

3.1 Website visitors

Our product websites use Vercel Web Analytics and Vercel Speed Insights to count page views and measure performance. These tools do not set cookies, and we do not use them to build advertising profiles or to share data with advertising networks. We do not operate advertising or cross-site tracking on our sites. We process this measurement data on the basis of our legitimate interest in understanding how our sites perform.

Our hosting and infrastructure providers generate operational logs in the ordinary course of serving a request, which can include IP address, user agent, requested URL, and timestamp. Those logs are generated and retained by the providers under their own retention schedules. We use them, when we access them at all, for security, abuse investigation, and troubleshooting.

3.2 Customer staff and Users

When your organization creates a workspace and invites you, we collect the information needed to give you access and to keep the workspace secure. The exact fields differ by product and are listed in Annex P-1. In every case they include:

Where a product maintains an administrative activity log, the events it records are listed in Annex P-1. Not every product maintains one.

We process this data to perform our contract with your organization and to maintain the security and integrity of the Services (legitimate interests).

3.3 Customer Data and End Users

Customers use the Services to store records about the people their organization works with. The Customer decides what to put in, for what purpose, and for how long. Categories vary by product and are set out in Annex P-1 and in the Data Processing Agreement. Depending on the features a Customer enables, Customer Data can include telephony records (call metadata, voicemails, and call recordings), e-signature audit records (signer name, email address, IP address, and timestamps), and outreach records (messages sent, delivery events, and unsubscribe events); these categories are described in Annex P-1.

We use Customer Data solely to provide the Service to the Customer who submitted it. We do not combine one Customer's data with another's, we do not sell it, and we do not use it to market to a Customer's End Users.

3.4 Billing

Subscription billing is handled by Stripe. Card details are collected by Stripe and are subject to Stripe's own privacy policy. We store the Stripe customer and subscription identifiers, the current plan and status, and summary billing metadata. We do not store full payment card numbers or bank account details on our systems.

Where a Customer receives donations through a Voyager donation page, payment is processed through Stripe Connect. We store the amount, the gift record, and the fee actually imposed, so that the Customer can report on it. Donor payment instrument details remain with Stripe.

3.5 Integrations you choose to connect

Where a Customer enables an optional integration, we store the credentials or OAuth tokens needed to authenticate with that system and use them only for the function the Customer enabled. Current integrations and their scopes are listed in Annex P-1. A Customer can disconnect an integration at any time from workspace settings, and disconnecting deletes the stored tokens.

3.6 Visitors to Customer public pages

Customers can publish pages that are visible to the public through the Services, such as donation pages, booking pages, help centers, and e-signature signing pages. When a visitor submits information on one of those pages, for example by making a donation, booking an appointment, or signing a document, the information the visitor enters is collected into that Customer's workspace and we process it as the Customer's processor. Payment card details entered on a donation page go directly to Stripe and are never stored on our systems. The Customer organization is the controller of the information submitted on its public pages; see Section 12.

4. How We Use Information

Legal bases where GDPR or UK GDPR applies

For End User data we act on the Customer's instructions; the Customer is responsible for establishing the legal basis for that processing.

5. Artificial Intelligence Features

Some Services include features that use a third-party large language model to draft or interpret text and images at a User's request, for example drafting a grant application, drafting a donor acknowledgment, or reading an uploaded photo or document to pre-fill a form. These features are listed in Annex P-1.

When a User invokes one of these features, the relevant portions of Customer Data needed for that request are transmitted to our AI subprocessor (currently Anthropic, PBC) and the generated output is returned to the User's workspace. AI features run only when a User invokes them: we do not run background, scheduled, or automatic AI processing over Customer Data. We do not use Customer Data to train models, and our agreement with the AI subprocessor does not permit it to use the data we send to train its models. AI output is generated probabilistically and may be inaccurate; it is the User's responsibility to review it before use.

We do not use automated decision-making that produces legal or similarly significant effects on any individual.

6. Cookies

We use cookies only where they are necessary for a Service to function. The exact cookies set by each product, with their names, attributes, and lifetimes, are listed in Annex P-1.

We do not set advertising cookies, cross-site tracking cookies, or third-party analytics cookies. Our website analytics do not use cookies at all. Some interface preferences are stored either on the workspace record in our database or in your browser's local storage rather than in a cookie.

Disabling strictly necessary cookies will prevent you from staying signed in.

7. Sharing and Subprocessors

We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.

We disclose personal information only to the subprocessors below, and only as needed to provide the Services. Each is engaged under terms requiring it to protect the data and to process it only on our instructions. The list is maintained here and in our Data Processing Agreement, and we give notice before adding or replacing a subprocessor for a Service a Customer uses, as described in the DPA.

SubprocessorPurposeUsed byLocation
Vercel, Inc.Application hosting, edge infrastructure, cookieless web analytics and speed measurement, and (Voyager) file and blob storageAll ServicesUSA
Neon, Inc.Managed PostgreSQL database hostingAll ServicesUSA
Stripe, Inc.Payment processing and subscription management; donation processing via Stripe ConnectAll ServicesUSA
ResendTransactional email deliveryPassageUSA
ImprovMXSMTP transactional email deliveryVoyagerUSA
AppleApple Wallet pass delivery to membersPassageUSA
Google LLCGoogle Wallet pass delivery (Passage); Google Calendar API and Google sign-in (Voyager)Passage, VoyagerUSA
BlackbaudRaiser's Edge NXT CRM integration, engaged only where the Customer enables itPassageUSA
Anthropic, PBCLarge language model processing for the AI features listed in Annex P-1, invoked only on a User's requestVoyagerUSA
Functional Software, Inc. (Sentry)Application error and performance monitoring. Error reports can incidentally include request context.VoyagerUSA
Twilio, Inc.Telephony: workspace phone numbers, call routing, voicemail, and call recordings, where the Customer enables the communications featuresVoyagerUSA
ShopifyStore and order synchronization, engaged only where the Customer connects a Shopify storeVoyagerUSA

Other disclosures

8. International Data Transfers

All Meridian Group infrastructure and all of our subprocessors listed above are located in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.

Where such a transfer is a restricted transfer under applicable law, we will implement appropriate transfer mechanisms where required, including the EU Standard Contractual Clauses (Module 2, Controller to Processor, adopted June 2021) and, for UK transfers, the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs. Our Data Processing Agreement provides for these mechanisms where they are required.

9. How Long We Keep Data

Website measurementAggregate metrics only, retained by the analytics provider under its own schedule. We retain no personal data from website visits.
Workspace and account dataFor the life of the workspace, then deleted within 60 days of termination, or sooner on the Customer's written request.
Customer Data, including End User recordsAccording to the Customer's instructions while the workspace is active. On termination it is available for export for 60 days, after which we delete it from active production systems within a reasonable period.
BackupsResidual copies can persist in routine backups after deletion from production and expire in the ordinary course as those backups are rotated.
Integration tokensDeleted when the Customer disconnects the integration.
Billing and gift recordsRetained as long as required by applicable tax, accounting, and charitable-reporting law.
Error monitoring recordsRetained by the monitoring provider under its own retention schedule.

10. Security

We apply administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. They include:

What security means here, said plainly

These are the safeguards we apply. They are a description of our efforts, not a guarantee. No online service can be made completely secure, threats change continuously, and reasonable industry-standard measures cannot guarantee that a service or its data will never be subject to unauthorized access.

Security is also shared. Section 5 of our Terms of Service sets out exactly which parts each side owns: we own the application, the infrastructure, and our subprocessors; the Customer owns its credentials, its people, its devices, its email accounts, its networks, the integrations it authorizes, and the lawfulness of the data it uploads. Where an incident originates on the Customer's side of that line, the consequences are allocated under Sections 16 and 17 of the Terms. Our obligation to tell a Customer about an incident affecting its data, within 72 hours, applies either way and is set out in the Data Processing Agreement.

Security incident notification. If a security incident affects personal information we process, we will notify affected Customers without undue delay, and in any event within the 72-hour window in our Data Processing Agreement. We will notify regulators where Meridian Group is itself required to do so by applicable law, and we will give affected Customers the information they reasonably need to meet their own notification obligations to individuals and to regulators. Section 14 of our Terms of Service and the Data Processing Agreement set out these obligations in full.

11. Your Rights

The rights below apply to personal information for which we are the controller, meaning website visitors and Customer account data. If your information is in a Customer's workspace, see Section 12.

11.1 GDPR and UK GDPR

If you are in the EEA or the UK you have the rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests, and the right to withdraw consent where processing is based on consent. You may also lodge a complaint with your national supervisory authority at any time.

11.2 California (CCPA and CPRA)

If you are a California resident you have the right to know what personal information we collect, use, disclose, and (if applicable) sell or share; the right to delete; the right to correct; the right to opt out of sale or sharing for cross-context behavioral advertising; the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising these rights.

We do not sell or share personal information as those terms are defined under the CCPA and CPRA, so there is nothing to opt out of.

Do Not Track and Global Privacy Control. Our sites do not respond to browser "Do Not Track" signals, because we do not track visitors across third-party sites, so there is nothing for the signal to switch off. Likewise, because we do not sell or share personal information, a Global Privacy Control (GPC) signal has no sale or sharing to opt out of; where applicable law requires such a signal to be honored, we honor it.

11.3 Other US state privacy laws

If you are a resident of Virginia, Colorado, Connecticut, Utah, or Texas, or of another US state with a comprehensive privacy law, you have the rights of access, correction, deletion, and portability of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in targeted advertising, we do not sell personal data, and we do not profile in that manner, so there is nothing to opt out of. You also have the right to appeal if we decline to act on a request: reply to our decision at privacy@meridian-group.ai and we will respond to your appeal within the timeframe the applicable law requires.

11.4 How to exercise them

Write to privacy@meridian-group.ai. We may need to verify your identity, and certain requests are subject to exceptions under applicable law. We respond within the timeframes the applicable law requires. You may use an authorized agent where the law permits.

12. If Your Record Is Held by One of Our Customers

If you are a donor, constituent, member, or other individual whose record a Customer organization keeps in one of our Services, that organization is the controller of your data, not us. We process it only on their instructions.

To exercise any right over that record, contact the organization directly. They can access, correct, export, or delete it themselves, and they will coordinate with us where they need our help. We assist Customers with verified data subject requests as required by our Data Processing Agreement.

If you cannot reach the organization, write to privacy@meridian-group.ai and we will route your request to them. We will not disclose, modify, or delete a Customer's records on the instruction of an individual we cannot verify as authorized by that Customer.

13. Children's Data

The Services are business software and are not directed at children. We do not knowingly collect personal data, for our own purposes as a controller, from anyone under 13 in the United States or under 16 in the EEA and UK.

A Customer's records may include minors, for example household memberships, youth program participants, or student volunteers. The Customer organization is responsible for ensuring that any processing of a child's personal data in its workspace has an appropriate legal basis, including any parental consent applicable law requires. If you believe we hold a child's data in our capacity as a controller and in violation of this policy, contact privacy@meridian-group.ai.

14. Changes to This Policy

We may update this policy. We will revise the version and date at the top when we do. For material changes affecting Customers or their End Users we will notify the Customer organization at least 30 days before the change takes effect, by email to the workspace account holder or by a prominent notice in the Service. Continued use after the effective date constitutes acceptance.

15. Contact

Meridian Group
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110
privacy@meridian-group.ai

Annex P-1: Product-Specific Detail

This Annex states, for each Service, the facts that genuinely differ between products. It is part of this policy and is updated when a product changes.

P-1.1 Passage

What it is Digital membership cards for museums, botanical gardens, zoos, and historical societies.
Staff and User data Email address, role (owner or staff), and account creation date. Nothing else. Passage does not record sign-in timestamps and does not maintain an administrative activity log.
Authentication Passwordless for both staff and members. A secure, time-limited sign-in link is emailed to a verified address and is consumed on use. No password is created or stored anywhere in the system.
Member (End User) data Name, email address, postal address, and phone number; membership level, status, expiration date, and member-since date; household grouping; a card identifier and barcode number unique to each card; optionally a CRM constituent identifier supplied by the Customer; and visit records consisting of the venue or event, the date and time, and the admission result.
Cookies Exactly one: passage_session. Signed, httpOnly, sameSite=lax, secure in production, path /, seven-day lifetime. Its only purpose is to keep you signed in. No other cookie is set by the application.
Emails sent Three: a staff sign-in link, a member sign-in link, and a welcome message on workspace creation. Passage does not send renewal reminders, marketing, or any other automated message.
Integrations Apple Wallet and Google Wallet pass delivery. Optional Blackbaud Raiser's Edge NXT: we store the OAuth access and refresh tokens needed to authenticate to the Customer's own Blackbaud account, and use them only to read constituent and membership data and to write visit records and contact updates back to that Customer's CRM. Revocable at any time from workspace settings.
Tenant isolation Enforced in the application layer: every query is scoped to the signed-in User's organization. Passage does not currently use database row-level security policies.
AI features None. Passage does not send any data to an AI provider.

P-1.2 Meridian Voyager

What it is Multi-tenant CRM and operations platform for nonprofits and small organizations.
Staff and User data Name, email address, a salted cryptographic hash of the password (or a Google account identifier where Google sign-in is used), workspace role, and account creation date. Voyager maintains an administrative activity log recording actions such as sign-in, sign-out, and changes to records, with the acting User, the affected record, and the time.
Authentication Email and password, or Google sign-in. Passwords are stored only as bcrypt hashes and cannot be recovered by us.
End User data What a Customer chooses to store, which can include: name, salutation and title, spouse name, one or more email addresses, phone numbers and mailing addresses, date of birth, household and relationship links, donor number and source, giving history including gifts, pledges, recurring gifts and tributes, grant and funder records, event and program participation, volunteer records including tracked requirements and clearances and any documents uploaded against them, communications history, notes, and uploaded files. Free-text notes and uploaded documents can contain whatever a Customer's staff put in them, including sensitive information, and the Customer is responsible for that choice.
Cookies A session cookie that keeps a signed-in User authenticated, and a separate limited-scope donor_portal cookie (14-day lifetime) for donors using a Customer's donor portal. Interface preferences such as theme are stored on the workspace record in our database or in the browser's local storage, not in a cookie.
Emails sent Sign-in and workspace invitation messages, password reset links, booking confirmations, donation receipts and acknowledgments, and any outreach or campaign message a Customer composes and chooses to send to its own contacts.
Integrations Google Calendar via OAuth, requesting the scopes calendar.events, calendar.freebusy, and calendar.calendarlist.readonly, used to read free/busy so open appointment slots can be shown and to write confirmed bookings to the calendar the User selects. Tokens are stored encrypted and are deleted when the connection is removed. Stripe and Stripe Connect for subscription and donation payments. Twilio for workspace telephony and voicemail where enabled. Shopify where a Customer connects a store.
Tenant isolation Two layers: PostgreSQL row-level security policies scoped to the workspace on workspace-scoped tables, and workspace filtering in the application queries.
AI features Grant application drafting, donor acknowledgment and gift-receipt drafting, in-kind donation intake from an uploaded photo or document, in-kind donor communications drafting, and review-response drafting. Each runs only when a User invokes it; there is no background or scheduled AI processing. The content needed for the request is sent to Anthropic and the output is returned to the Service. Our AI subprocessor is not permitted to train on that content.
Donation processing Where a Customer runs donation pages, we store donor name and contact details supplied on the donation form, the gift amount and designation, and the platform fee actually imposed on that gift. Card details are handled by Stripe and are never stored by us.
Telephony records Where a Customer enables the telephony features, we store call metadata (the numbers involved, direction, start time, and duration), voicemails left by callers, and call recordings where the Customer's use of the feature produces them, processed through Twilio. These records belong to the Customer's workspace and are Customer Data.
E-signature records Where a Customer uses the e-signature features, we store the documents sent for signature and an audit record of each signing event: the signer's name, email address, IP address, and the timestamps of the signing events. These records exist so the Customer can evidence its signatures and are Customer Data.
Outreach records Where a Customer uses the outreach and campaign features, we store the messages sent, delivery events, and unsubscribe events, so that the Customer can honor opt-outs and report on its own sending.
Public pages Information submitted by visitors on a Customer's public pages (donation pages, booking pages, help centers, and signing pages): the details the visitor enters, such as name and contact details, gift amount and designation, booking details, or signature data. Payment card details are entered directly with Stripe and never touch our systems. See Section 3.6.
Google API limited use Meridian Voyager's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data solely to power scheduling and booking. We do not use it for advertising, do not sell it, and do not transfer it except as necessary to provide that feature, with your consent, or as required by law. No Meridian person reads your calendar data except with your consent, for a security or abuse investigation, to comply with law, or in aggregated form that does not identify you.