Security & data handling
What we hold, and what we don't.
Your roster is member records, dues history, and decades of institutional memory. Here is exactly what a fellos site stores, who handles the money, and what your officers control — written plainly, with no claims we can't back.
First, the honest part
fellos does not hold a third-party security certification today.
No SOC 2 report, no ISO certificate, no auditor's letter. We'd rather say that on the page than let you find out during a vendor review. What we can give you is a specific, verifiable account of how the product handles your data — that's the rest of this page.
If your grand lodge, department, or board has a vendor-approval form or a security questionnaire, send it over and we'll answer it directly, in writing, including the questions where the answer is "not yet."
Send us your vendor questionnaireWhat we store
Everything a fellos site keeps
Your organization's data lives in your own fellos site. This is the whole shape of it.
Member records
Names, contact details, member type, which chapter or org they belong to, officer positions held, and any extra-info fields or attachment types your admins choose to configure. Nicknames and road names too, if your organization uses them.
Community content
Feed posts, group posts, comments, and the files in your document library — including every revision, when the folder has revision history turned on.
Events and tickets
Event details, RSVPs, ticket purchases, attendee and guest counts, and check-in scans.
Commerce records
What was sold and to whom: order line items, order status, the shipping address on the order, tracking you enter, and dues charges. Payment status comes back from Stripe by webhook.
Administrative history
An append-only audit log of who did what and when — logins, creates, updates, deletes, approvals, declines — with the actor and a timestamp on every entry.
Sign-in credentials
Email and password. If your Site Admin enables it, members can also sign in with Google, GitHub, or Apple; those logins are matched by email address and never create accounts on their own.
What we don't
Three things fellos never touches
Card numbers never touch fellos
Dues, event tickets, and store purchases all check out through Stripe. Card numbers, CVCs, and bank details are entered on Stripe and stay with Stripe. fellos records the order and the payment status Stripe sends back.
We don't sell member data
Your roster is not a product. fellos does not sell, rent, or hand member records to data brokers, advertisers, or list resellers, and does not use your members to advertise to other organizations.
Your money does not route through us
Payments go directly to your organization's own Stripe account using your own Stripe keys. fellos takes 0% on top — the only fees are Stripe's standard processing fees, paid to Stripe.
Payments
Stripe processes the money, not fellos
Every payment path in the product — dues, event tickets, store orders — runs through Stripe Checkout on your organization's own Stripe account.
Your Site Admin connects your own Stripe keys — test keys first, then live — and Stripe tells fellos when a payment succeeds or fails through a signed webhook. Funds settle into your Stripe account and pay out to your bank on your Stripe schedule. Refunds are issued in Stripe.
That split is also the practical answer for your books: fellos is the record of what was sold and to whom, and Stripe is the authoritative record of the money, fees, and payouts.
Your controls
Most of this is yours to set, not ours
A fellos site is configured by your own officers. These are decisions your organization makes and can change at any time.
- Who can see which profile fields, and which members are visible to whom.
- Which admin levels can request and which must approve onboarding, transitions, transfers, and deactivations.
- Who can curate a document folder and who can see its revision history.
- Your own Terms of Service and Privacy Policy, published at /terms and /privacy on your site and linked from every page. fellos ships default text you are expected to replace with your own.
- Your cookie banner: whether it shows, which consent mode applies (auto by region, opt-in everywhere, opt-out everywhere, or notice only), the wording, and the description of each cookie category.
- Whether social sign-in is available at all, and which providers.
- Who holds site-admin and Comptroller access, with every change recorded in the audit log.
Nothing here is legal advice. Your Privacy Policy and Terms of Service describe your organization's own handling of member data — have them reviewed by someone who knows your jurisdiction and your organization type.
Retention & export
Records are kept on purpose
These organizations need history. The product is built to preserve it rather than quietly discard it.
Deactivation is not deletion
When a member is deactivated their login access is revoked and they come off active rosters, but their profile, posts, event attendance, attachments, and workflow history are kept — that's what governance, historical, and legal record-keeping require. A deactivated member can be reinstated with their history intact.
The audit log can't be rewritten
Administrative actions are append-only. Entries cannot be edited or deleted by anyone, including site admins, so the record a board reviews is the record of what actually happened.
Getting your data out
fellos does not ship a self-serve bulk CSV export today — the Comptroller guide says so plainly. Order and attendee detail is readable in the product, and Stripe exports the transaction-level reports for anything touching your bank account. If your organization needs a copy of its records, or needs specific data removed, write to hello@fellos.app and we'll work it out with you.
Cookies & analytics
Denied by default, on this site and yours
On this marketing site
Two things measure this site: HeyCatch, which counts page views and clicks so we know which pages earn their keep, and — when ads measurement is switched on for a build — a Google tag. Neither sets an analytics or advertising cookie until you press Accept on the banner: Google's tag starts with ad storage, ad user data, ad personalization, and analytics storage all set to denied, and HeyCatch is not started at all.
Accept, and HeyCatch stores a random visitor id — in a first-party cookie and in your browser's local storage, for up to a year — so a repeat visit counts as one person and not two. It is never your name or your email, because we don't have them: you don't need an account to read this site, and we don't ask you for one.
Your choice is stored in your own browser, and you can change it any time with the Cookie settings link in the footer. Rejecting after you have accepted deletes what HeyCatch stored.
Inside your fellos site
Your Site Admin owns the banner: whether it appears, the consent mode, the wording, and the description of each category. The default mode picks opt-in for the EU, UK, and Brazil, opt-out for the US, and notice-only elsewhere.
Strictly necessary cookies — session, security, cart — can't be switched off, because they're what keeps the site working. Everything else your members can toggle from a Cookies link in your footer.
Last reviewed September 2026.
Security questions?
Write to hello@fellos.app. Vendor reviews, security questionnaires, and data-handling questions from a grand lodge, department, or board all go to the same place, and get a straight answer.