Your data, exports and closing your account
Your choir's members, donors and ticket buyers are your choir's information, and it is yours to take with you. This page is for the account holder, and for anyone asked "what happens to our data?". The words below follow our Privacy Policy; if the two ever differ, the policy is the one that counts.
Ask for an export or close your account
There is no button for either. The Your data card at the foot of your account page says:
To have all of your account's data exported, or to close your account and have it deleted, write to support@choirmastercms.com from the address you sign in with. How we handle your information is in our Privacy Policy.
- Write to support@choirmastercms.com from the email address you sign in with, so that we know the request comes from the account holder.
- Say whether you want an export, to close the account, or both. If you want both, ask for the export first and keep it somewhere safe.
- Name the site (its web address).
Cancelling a paid plan does not close your account. See Invoices, changing plan and cancelling.
What an export contains
An export is a copy of your site's whole database, as a single text file with one record to a line. It holds everything you have entered: settings, pages, concerts, members, donors, gifts, orders, announcements, messages, and so on.
It holds the database only. Uploaded files, such as photos, documents and recordings, are kept separately and are not inside it. It leaves out two things on purpose: sessions (who is signed in at the moment) and login links. Putting one back would let an old sign-in work again. If you saved a mail-server password under Email, it is in the export still encrypted, and it is useless without a key that only we hold. After a restore you would simply enter it again.
The file is meant for a technician or for moving to another system. If you need your members, donors or orders as spreadsheets, you can download those yourself: see Spreadsheet columns for imports and downloads.
How long we keep things
These periods are from the Privacy Policy (section 8).
| Information | How long we keep it |
|---|---|
| Your site's content, while your account is open | As long as the account is open, then up to 30 days after you close it |
| Paid-plan data (members, donors, tickets) after your site goes back to Free | At least 90 days; we may delete it after that. Paying or subscribing again within that time restores it. |
| Billing and tax records | 6 years after the end of the tax year they relate to, as Canadian tax law requires |
| Technical and security logs | Up to 90 days, unless needed to investigate a security incident |
| Backups | Deleted data may remain in backups for up to 365 more days before it is deleted |
| Licence key records (self-hosted) | For the life of the licence, then up to 1 year |
The terms add that, after you close your account, "we may delete your content after 30 days; export anything you want to keep before closing."
Backups
We keep encrypted backups of the hosted service. They are stored with Google Cloud in Toronto, Canada. This is for our recovery, not a service you can restore from yourself: if you need something back, get help. The policy gives no schedule for backups, so this guide does not either.
Who handles your data
On a hosted site we host and process your members' and donors' information on your behalf. These outside services are named in the policy:
| Service | What it does for the hosted service |
|---|---|
| Cloudflare | Hosting, delivery, data storage and security |
| Amazon (Simple Email Service) | Sending email, from Canada |
| Stripe | Taking payment for plans, and card payments for tickets and gifts on a site that connects Stripe |
| Google Cloud | Encrypted backups, and the uploaded files being backed up |
| Google Fonts | The fonts on your site: a visitor's browser asks Google for them directly, so Google sees the visitor's IP address |
| Anthropic | The writing assistant, which receives the text and choir details an administrator submits when using it |
Information may be stored and processed outside Canada, including in the United States. The policy lists where for each service.
Your choir's responsibilities
The policy is clear on who is responsible for what. For a hosted site, the choir is responsible for its members', donors' and ticket buyers' information, and for having its own privacy policy. A visitor or member who writes to us about their information is sent on to the choir, and we help the choir respond.
If you add young members, you must follow the laws on minors' personal information where you live, including any parent or guardian consent. See Terms, privacy and your responsibilities.
Questions about personal information
The person in charge of the protection of personal information is reached at legal@choirmastercms.com. Write there to see, correct or delete the personal information we hold about you as an account holder, or to withdraw consent. We reply within 30 days, and may need to confirm who you are first.