Quiet pages
MemberCairn Privacy Policy
Effective Date: June 7, 2026 Last Updated: July 26, 2026
This Privacy Policy explains how MemberCairn LLC, an Idaho limited liability company (“MemberCairn,” “we,” “us,” or “our”), collects, uses, and shares information in connection with the MemberCairn platform, marketing website, and related services (the “Service”).
1. Our Two Roles
MemberCairn handles information in two different capacities, and which one applies affects your rights:
-
As a service provider to Organizations. When an Organization (such as a Scouting unit or club) uses MemberCairn to manage its members and prospects, the Organization decides what information to collect and what communications to send. We process that information on the Organization’s behalf and under its instructions. The Organization is the party responsible for that data. If you are a member, prospective member, parent, or guardian, requests about your information are usually best directed to your Organization first; you may also contact us and we will work with the Organization to address your request.
-
For our own users and visitors. When you create an account, administer an Organization, visit our marketing website, or request information about MemberCairn, we handle that information for our own purposes as described below.
2. Information We Collect
Depending on how you use the Service, we may collect:
- Account information — name, email address, and the Organization you are associated with. If you choose to Sign in with Google to access the platform, Google provides us your name, email address, and basic Google profile information (including your Google account identifier) so we can create and authenticate your account. We use this information only to sign you in and secure your account; we do not receive your Google password, contacts, calendar, files, or any other Google account data, and we do not use Sign in with Google for advertising. When you use Sign in with Google, your interaction with Google is also governed by Google’s own Privacy Policy.
- Contact information — names, email addresses, and phone numbers of members and prospects, as provided by Organizations or submitted through intake forms.
- Information about minors — Organizations serving youth may provide limited information about a child (for example, first name, grade, or program rank) supplied by a parent, guardian, or the Organization. See Section 5.
- Inquiry information — information you submit when you request a demo, contact us, or sign up for updates on our marketing website.
- Communications content and data — the content of emails and text messages sent to or from an Organization through the Service, along with delivery status, timestamps, and opt-in/opt-out preferences. Message content may be processed by automated systems and AI as described in “Automated Processing and Artificial Intelligence.”
- Usage and technical data — log data such as IP address, device and browser information, and how the Service is used, collected to operate and secure the Service.
- Advertising and measurement data (marketing website and signup pages only) — when you arrive at our marketing website or our signup pages from a search result, an ad, or a link we shared, we and our advertising providers record the identifiers that came with that link (an advertising click identifier and campaign tags), which pages you viewed, and whether you went on to start or finish a signup. This lets us tell which ads and which pages actually bring Organizations to MemberCairn. See Section 4. No advertising click identifier is ever recorded inside the signed-in app or on any page an Organization shows to its members and families.
We do not intentionally collect more than is needed to provide the Service.
3. How We Use Information
We use information to:
- provide, operate, and improve the Service;
- send the communications an Organization directs (recruiting, onboarding, and retention messages);
- respond to inquiries and, where you have asked to hear from us, send information about MemberCairn (see Section 7);
- authenticate users and secure the Service;
- comply with legal obligations, including telecommunications and anti-spam requirements;
- maintain records of consent and opt-out preferences; and
- measure and improve our own advertising and marketing for MemberCairn, using the website and signup information described in Section 4.
We do not sell personal information. We never use an Organization’s data for advertising of any kind, ours or anyone else’s: member, prospect, family, and message information is used only to provide the Service to that Organization.
3A. Automated Processing and Artificial Intelligence
The Service uses automated systems, including artificial-intelligence (AI) language models, to help Organizations communicate with their members and prospects. When you send a message to an Organization through the Service (for example, an email reply or a text message), the content of that message — together with related context such as earlier messages in the same conversation and notes the Organization has recorded — may be processed by an AI language model to summarize the message, classify it, suggest a reply, or draft a response for the Organization.
A drafted message is, by default, reviewed and sent by the Organization’s leaders; in some cases the Organization may configure the Service to send certain routine replies automatically, within limits it sets (such as quiet hours and daily sending caps). We do not use these systems to make decisions that produce legal or similarly significant effects about you.
We use Anthropic, PBC as our AI service provider for this processing (see “How We Share Information”). Message content processed for these purposes is used only to provide the Service. We do not sell it, and it is not used to train general-purpose AI models.
Where an Organization serves youth, this processing may include the limited information about a child described in “Children’s Information.”
4. Cookies, Analytics, and Advertising
We treat our surfaces differently depending on who is looking at them. Our public marketing and signup pages, aimed at leaders deciding whether to try MemberCairn, use ordinary web analytics and advertising measurement. The signed-in app and every page an Organization shows to its own members and families carry no advertising code at all, and never will; we measure those pages only in the limited, cookieless ways described below.
Where we do use analytics and advertising: the marketing website and signup pages
On our marketing website (membercairn.com) and our public signup pages (signup.membercairn.app), we use third-party advertising and analytics providers, including Google (Google Analytics and Google Ads) and Meta (the advertising tools behind Facebook and Instagram), to understand how people find MemberCairn and which pages and ads lead to a signup. These tools set cookies or similar identifiers in your browser and share with those providers your IP address, browser and device information, the pages you view, and any advertising click identifier that came with the link you followed.
If you complete a signup, we may also send an advertising provider a one-way hashed version of the email address you entered, so the signup can be matched back to the ad click that produced it, and we may report later milestones (such as starting a paid subscription) the same way. Hashing means we send a scrambled form of the address rather than the address itself. These providers may use this information to measure our ads and, depending on the settings we choose, to show you MemberCairn ads again on their own services and on partner sites. Your interactions with each provider are also governed by that company’s own privacy policy.
Two limits apply, and we hold ourselves to them:
- United States only. These analytics and advertising tools load only for visitors we detect in the United States, which is where MemberCairn is offered. If you are visiting from elsewhere, including the European Economic Area, the United Kingdom, or Switzerland, we set no analytics or advertising cookies at all. That is why you will not see a cookie-consent banner on our site.
- Nothing from an Organization. Member, prospect, family, and message information never reaches any advertising or analytics provider. Only prospective-customer website activity does.
Two other things also happen on these pages, unchanged: web fonts are served by Google (Google Fonts), which means Google receives your IP address and browser User-Agent in order to deliver the fonts; and the site is hosted on Cloudflare, which routes traffic and may process standard, aggregated network and security data as our hosting provider. If you submit a contact or interest form, we store what you typed along with limited technical details (such as a country code and a one-way hash of your IP address used to detect abuse) — see Sections 2 and 7.
Where we do not: advertising, anywhere but the marketing and signup pages
Once you sign in to MemberCairn, and on every page an Organization publishes for its own members and families (its public front door, inquiry and RSVP forms, and payment pages), we load no advertising code of any kind. There are no ad pixels and no cross-site tracking cookies on those pages. Google and Meta receive nothing from them.
We do measure those pages, in two ways that are deliberately limited:
- Our own first-party, server-side analytics. We record product events (such as sign-ins and feature usage) on our own systems, to operate and improve the Service.
- Privacy-preserving traffic measurement by Cloudflare, our hosting provider and an approved subprocessor (Section 8). It records the address of the page, how quickly it loaded, and general browser and device type. It sets no cookies, writes nothing to your browser’s storage, uses no cross-site or cross-session identifier, and does not retain your IP address. It receives no names, contact details, or message content, and it is never enabled on any page whose address contains a personal access link, such as an RSVP, payment, or onboarding link.
The app sets a single, essential cookie that keeps you signed in and protects your session (it is marked Secure and HttpOnly and is restricted to same-site requests). It is required for the app to work and is not used for advertising or cross-site tracking. As on the marketing site, web fonts are served by Google, and one internal admin dashboard loads a charting library from a public software CDN to render graphs.
Your choices
- Browser settings. You can block or delete cookies through your browser, though blocking the app’s sign-in cookie will prevent you from logging in.
- Global Privacy Control. Where your browser or an extension sends the Global Privacy Control (GPC) signal, we treat it as a request to turn off analytics and advertising identifiers on our marketing and signup pages, and we honor it automatically.
- Each provider’s own controls. Advertising platforms offer their own opt-outs and ad-preference settings. Google publishes an Analytics opt-out browser add-on and ad settings in your Google account; Meta offers ad preferences in your Facebook or Instagram settings, including controls for activity that businesses share with it from outside its apps.
- Ask us. Write to [email protected] and we will honor your request, whichever providers are involved.
A note on state privacy laws
We do not sell personal information for money. Some state privacy laws, including those in California and Colorado, define “selling,” “sharing,” and “targeted advertising” broadly enough that our use of advertising cookies on the marketing website and signup pages may fall within them. If you live in a state that grants those rights, you can exercise them through any of the choices above or by contacting us. We will honor the request and will not treat you differently for making it.
5. Children’s Information
The Service is directed to Organizations and to adults — leaders, parents, and guardians — and is not directed to children. We do not knowingly collect personal information directly from children, and children do not interact with the Service on their own.
When an Organization serves youth, information about a child is provided by the child’s parent or legal guardian, or by the Organization with the parent’s or guardian’s authorization, for the purpose of managing that child’s participation in the Organization. We rely on the Organization to obtain any parental consent required by law before that information is provided to us, and the Organization is responsible for that consent.
The information we hold about a child is limited to what an Organization needs to manage participation — typically the child’s first and last name and program details such as grade, rank or level, and den or group, and, for enrolled members, a membership identifier issued by the Organization’s national body (for example, a BSA Member ID). We do not collect a child’s date of birth, home address, or contact information, and we do not request information directly from a child.
If you are a parent or guardian and wish to review, correct, or delete information about your child, contact your Organization or contact us at the address below; we will act on or coordinate your request. If we learn we have inadvertently collected personal information directly from a child in a manner not permitted by law, we will delete it.
6. Communications: Email and SMS (Sent for Organizations)
- Consent. We send messages based on consent captured by the Organization (for example, through an intake form) or your direct opt-in.
- SMS. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help. We honor opt-out requests promptly and retain a record of them to avoid contacting you again.
- Email. Each email includes an unsubscribe link and the sender’s physical mailing address, as required by the CAN-SPAM Act.
- Carrier compliance. Text messaging is sent in accordance with applicable carrier and industry requirements (including A2P/10DLC registration). Consent information is used only to send the messages you or your Organization authorized.
7. Marketing Communications from MemberCairn
If you contact us, request a demo, or sign up for updates through our marketing website, we may use your contact information to respond and to send you information about MemberCairn’s products and services. You can opt out of these marketing emails at any time using the unsubscribe link in them. These messages come from MemberCairn directly and are separate from the communications we send on behalf of Organizations described in Section 6.
8. How We Share Information
We share information only as needed to run the Service:
- With service providers (subprocessors) — we use a small set of vendors that process data on our behalf, under contractual confidentiality and security obligations, only to provide the Service: Anthropic, PBC (AI language-model processing — summarizing inbound messages and drafting replies, as described in “Automated Processing and Artificial Intelligence”); Postmark (an ActiveCampaign company) (transactional and bulk email delivery); Twilio Inc. (SMS text-message delivery, where an Organization enables texting); Fly.io, Inc. (application hosting and compute); and Cloudflare, Inc. (DNS, network security and bot protection, and encrypted backup storage). These providers process information in the United States. We may add or change providers as the Service evolves and will keep this list current.
- With advertising providers, for our own marketing measurement — as described in Section 4, our marketing website and public signup pages share website-visit and signup information with third-party advertising and analytics providers, including Google and Meta. That information covers advertising click identifiers and, at signup, a one-way hashed email address, so we can measure and improve our own advertising. These providers receive it only from those public pages. None of them ever receives an Organization’s member, prospect, family, or message data; none is one of the subprocessors listed above; and none is on the approved subprocessor list in our Data Processing Addendum. No advertising provider receives anything from the signed-in app or from any page an Organization publishes for its members and families.
- With Cloudflare, for traffic and performance measurement — as described in Section 4, Cloudflare provides privacy-preserving measurement across our surfaces, including the signed-in app. It is an approved subprocessor, already listed above, and this is measurement rather than advertising: no cookies, no browser storage, no cross-site identifier, no retained IP address, and no names, contact details, or message content. Pages whose address contains a personal access link are excluded from it entirely.
- With the relevant Organization — so it can manage its members and communications.
- For legal and safety reasons — to comply with law, respond to lawful requests, or protect the rights, safety, and property of MemberCairn, Organizations, or others.
- In a business transfer — if MemberCairn is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy.
We do not sell personal information.
9. Data Retention and De-Identification
We keep personal information only as long as needed to provide the Service to the relevant Organization and to meet legal, accounting, and recordkeeping obligations. When information is no longer needed, we delete it or de-identify it so it can no longer reasonably be linked to an individual. Opt-out records are retained as needed to honor your preferences.
10. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information, including access controls, passwordless sign-in links and, where you choose it, Sign in with Google, separation of each Organization’s data, encryption of data in transit, and regular encrypted backups. No system is completely secure, and we cannot guarantee absolute security.
11. Your Choices and Rights
You may:
- opt out of texts (reply STOP) and emails (use the unsubscribe link) at any time;
- turn off the analytics and advertising cookies on our marketing website and signup pages, and exercise any state-law right to opt out of “sharing” or targeted advertising, using the choices in Section 4;
- request access to, correction of, or deletion of your information by contacting us (for member data, we may coordinate with your Organization, which controls that data); and
- where applicable law grants additional rights, exercise those rights by contacting us.
12. Data Location
Information is processed and stored in the United States. By using the Service, you understand that information may be processed in the United States.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new effective date and, where appropriate, provide notice.
14. Contact Us
MemberCairn LLC 3822 N Sandpoint Way, Boise, ID 83702 [email protected]