Privacy
Version 2026-09-15-screening
This page describes what Causly collects, why we collect it, who else handles it, and how to get it out or get it deleted. It describes our practices; it is not a guarantee.
Who we are
Causly is operated by dbb1.dev LLC.
2108 N ST, Suite # 8984, Sacramento, CA 95816
Questions about anything on this page: doug@dbb1.dev.
Two kinds of people
Organizations use Causly to run sign-up sheets and to send text alerts. So there are two kinds of people in the system:
- Organizers — the volunteers who create an account and run the sheets.
- Volunteers and subscribers — the people who sign up for a slot or join a text list.
The organization decides who to collect and what to send them. We provide the software and hold the data on their behalf.
What we collect
From organizers, when you create an account:
- A username, an email address, and a password (we store a hashed form of the password, not the password).
- Your organization's name, timezone and settings, and who else you invite to it.
From volunteers, when someone signs up for a slot on a public sheet:
- Their name, email address and US mobile number, and which slot they took.
- Whether they ticked the box agreeing to receive texts — and, as the record that they agreed, the date and time, the IP address the form was submitted from, the browser's user-agent string, and the version of the consent wording in force.
From subscribers on a text list:
- The mobile number, which lists it belongs to, and the times it opted in, confirmed, or opted out.
- A log of messages sent to it: the text, when it went, and what our messaging provider returned when we handed it over.
- If someone replies STOP, we record the opt-out on that number's entry in every roster it appears in anywhere on Causly — not only the organization that sent the message — and keep it for as long as the entry exists, including while the entry is in the organization's Trash. The organization cannot undo it from the admin screens, the API or the Assistant; only a START from that phone clears it. If an organization permanently deletes the entry and then enters the number again, the record goes with the entry.
When someone pays an organization through Causly:
- Name, email, the amount, and the answers to any questions the organization added to its form.
- Card details are entered on Stripe's own checkout pages. We do not receive or store card numbers.
From anyone who visits the site:
- Ordinary server logs (IP address, the page requested, the time, the browser user-agent).
- Cookies: one to keep you signed in — which is also what stops another site submitting our forms as you — a short-lived one that carries a status message across a redirect once you are signed in, and one named causly_src, set for 30 days when you arrive from a link or an advertisement carrying a ?src= tag, so we can tell which of our own channels a sign-up came from.
- The advertising data described under “Advertising” below — none of which is collected today.
Why we collect it
- To run the sheet — showing slots, holding a spot, and emailing a confirmation.
- To send the texts an organization asks us to send, and to record who agreed to receive them.
- To honor STOP, HELP and the confirm-by-reply step.
- To take payments on an organization's behalf and pay them out.
- To bill for the plan.
- To keep the service working, investigate abuse, and comply with carrier rules and the law.
- To measure which of our own channels brings people to Causly.
Reading your messages: we can read the messages an organization sends — they are rows in the database we run — and we do when we are looking into a report, a carrier complaint or suspected abuse. An automated screen also checks message content: each time an organization saves the text of a message, or the welcome text a list sends to a new subscriber, we send that text — together with the organization's name and the names of the lists it is addressed to — to Anthropic (see below), which answers whether it fits the rules the US mobile carriers hold our shared sending number to, such as no phishing and no unrelated advertising. We keep the text we sent, the answer and its one-line reason with the message, for as long as we keep the organization's data. A message the screen holds is not sent until a person reads it — the organization's owner, for an established paying organization, otherwise us — and releases it, or the organization changes the text. The other place a message reaches an AI service is the in-app Assistant, and only when someone in your organization uses it.
Who else handles it
We use these companies to operate Causly. Each receives only what it needs to do its part.
- Twilio — sends and receives text messages, and passes them to the phone carriers. It receives mobile numbers and message content.
- Resend — sends our email (confirmations, notices, password resets). It receives email addresses and message content.
- Stripe — plan payments, and payments and payouts for organizations that collect money. It receives payer and organizer billing details.
- Fly.io — hosts the application and its database in the United States.
- Bunny.net — stores the product images an organization uploads to its storefront. No personal information is stored there.
- jsDelivr — a public content delivery network that serves the open-source stylesheets and scripts our pages are built with. Your browser requests those files from it directly, so it receives your IP address and browser details each time a page loads.
- Google Fonts — serves the typefaces our pages are set in. Your browser fetches the stylesheet from fonts.googleapis.com and the font files from fonts.gstatic.com directly, so Google receives your IP address and browser details each time a page loads.
- Anthropic — powers the in-app Assistant and the content screen described under “Why we collect it”. If you use the Assistant, what you type and the organization data it reads to answer are sent to Anthropic to produce the reply. Separately, each time an organization saves a message or a list's welcome text, that text, the organization's name and the names of its lists are sent to Anthropic to be checked against carrier rules; nothing else about the organization or its subscribers goes with it.
- Meta — advertising. Nothing is sent to Meta today; the next section describes what would be, and when.
Text messages and opting out
When a number joins through Causly — someone signs up on a public sheet, or texts an organization's keyword — it does not receive announcements until the person holding it confirms. The number is pending: we send it one message asking it to reply YES, and only a YES subscribes it.
An organization can also enter a number it collected another way, such as on a paper sign-up sheet at a meeting. We record those as added by the organization rather than confirmed by reply, and it is the organization's responsibility to have the person's agreement before entering them. Everything else on this page applies to those numbers identically — STOP, HELP, and the opt-out record described above.
Anyone can reply STOP (or STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT) to any message to stop the texts immediately. A STOP is not limited to the organization that sent the message: we record it against every entry that number has anywhere on Causly at that moment, so any other organization here holding the same number stops texting it too. Reply HELP for instructions, or START to begin again.
Advertising, and the Meta pixel
We intend to advertise Causly on Facebook and Instagram. Our pages load no advertising or analytics code of any kind, no Meta pixel runs on this site, and the only thing we will learn about an advertisement is what Meta reports to us about the advertisement itself.
We intend to add the Meta pixel — a small piece of code from Meta Platforms, Inc. — to our public pages, and this section says what it will do before it does it.
What it will do: when you load one of our public pages it will tell Meta that a browser visited that page, and — if you complete a sign-up — that a sign-up was completed. It will send your IP address, browser details, the page address, and cookie identifiers Meta uses to recognise a browser across sites. It will not send us or Meta the contents of any sheet.
Where it will run: on our public pages only. It will not be loaded on any page under /admin, and it will not be loaded on a public sign-up sheet page — the pages that carry volunteers' names and phone numbers.
Why this section exists: California's privacy law defines “sale” and “share” more broadly than an exchange of money, and sending data to Meta for cross-context behavioral advertising falls inside that definition. We do not sell personal information for money, and we do not share sheet rosters, phone numbers or message content with any advertiser. We disclose the pixel here ahead of adding it, and we offer an opt-out.
How to opt out of that sharing
- Turn on Global Privacy Control in your browser or extension. Nothing on this site loads advertising code today; when the pixel described above is added, a request carrying that signal will not load it.
- Email doug@dbb1.dev and ask us to opt you out.
Opting out does not change anything about your account, your sheets, or what we charge.
Your choices
Depending on where you live you may have the right to see what we hold about you, correct it, get a copy of it, have it deleted, and opt out of the sharing described above. You may exercise these rights without being treated differently for it.
- Organizers: email doug@dbb1.dev from the address on your account. You can also download your rosters as CSV from the sheet hub at any time.
- Volunteers and subscribers: the organization that ran the sheet holds your details, so contacting them is usually fastest. You can also email us and we will act on it. To stop texts, reply STOP — that works immediately and needs no email.
How long we keep it
We keep an organization's data while its account exists, because that is the roster it is using. Deleting a row in Causly puts it in the organization's Trash, where it can be restored until it is purged. When an organization asks us to delete its data we do it by hand and tell them when it is done. We keep payment records for as long as we are required to. The opt-out record for a number that replied STOP lives on that number's entry in every roster it appears in anywhere on Causly, so on each of them it lasts exactly as long as that entry does: it survives the entry being put in the Trash and restored, and it is removed if that entry is permanently deleted.
Children
Causly is for adults organising activities. Accounts, sign-up sheets and text lists are meant for parents, coordinators and adult volunteers, and organizations should not enter a child's phone number or email address. We do not knowingly collect personal information from children under 13. If you believe a child's information was entered, email doug@dbb1.dev and we will remove it.
Changes
When this page changes we update the version at the top. Material changes will be announced in the application.
Contact: dbb1.dev LLC · doug@dbb1.dev