Your data is yours. We don't extract it, sell it, or train on it.

CHNGMKR is built on a single principle: the dignity of the people in our field, and the people who read it. This page lists, in plain terms, how we protect both.

Where your data lives

Member accounts, favourites and subscription state are stored in a hosted Postgres database (Supabase). The site and its static assets are served by Netlify's global CDN. Payments are processed by Stripe within the EU. We never see your card details. Two flows involve providers established in the United States, covered by standard contractual clauses and/or the Data Privacy Framework: AI search queries transit through Anthropic, and, only with your consent, audience measurement through Google Analytics. The details are in our Privacy Policy.

What we never do

  • We never sell user data. No data broker has ever received a row from us. We do not have a partnership pipeline that would allow it.
  • We never train models on member behaviour. Your hearts, your views, your reading patterns are yours. They power your personal recommendations and nothing else.
  • We never share email lists. Even with curators, even with co-founders. The membership table is a closed system.
  • We never scrape changemakers. No LinkedIn harvest. No Crunchbase pull. No automated indexing. Every entry was written by a human who knew the person.

What we do

  • TLS everywhere. HTTPS-only, automatic certificate renewal.
  • Encrypted at rest. Database, backups and payment data are encrypted at rest by our providers (Supabase, Stripe).
  • Contact details stay private. The public data feed is stripped of every contact field at the source: emails and phone numbers of changemakers never leave the server.
  • Server-side moderation. Every curator submission goes through a server-side moderation queue before it appears on the map.
  • Right-to-delete honoured within 30 days, by email to hello@chngmkr.com.

Compliance posture

To be precise about what the SOC 2 line means: CHNGMKR itself has not undergone a SOC 2 audit. Our infrastructure providers (Netlify, Supabase and Stripe) each hold their own SOC 2 (and, for some, ISO 27001) attestations covering the systems where your data actually lives.

Sub-processors

We use a small, deliberately short list of third parties. Each processes data under a data-processing agreement (art. 28 GDPR) incorporated in its terms.

  • Hosting & CDN: Netlify.
  • Database & accounts: Supabase.
  • Payments: Stripe Payments Europe Ltd. We never see your card details.
  • AI search: Anthropic (United States), receives search queries and profile data only.
  • Audience measurement: Google Analytics (United States), only after your consent.

Disclosure & vulnerability reporting

If you find a vulnerability, write to hello@chngmkr.com. We acknowledge quickly, validate in good faith, and credit responsible reporters publicly if they wish. We do not pursue good-faith researchers.

Last reviewed: July 2026. This page is updated whenever our sub-processors, posture or controls change.

Directory of every changemaker · The cartography · Places · Constitution · CHNGMKR home

CHNGMKR
0%