Last updated: September 27, 2026
Melora Connect, Inc. (“Melora”, “we”, “us”)
Privacy questions: privacy@meloraconnect.com. Support: support@meloraconnect.com or (571) 290-2703.
1. Who this policy covers, and our role
1.1 Melora Connect is software that chambers of commerce, trade associations and professional societies (“Associations”) use to run their membership, events, payments and communications.
1.2 When we act for an Association. Most personal information in Melora Connect is member, event and payment information that an Association puts in or collects. For that information, the Association decides what is collected and why, and we process it on the Association’s behalf. If you are a member of an Association, its own privacy notice applies, and requests about your data should go to it first. We will help the Association answer them.
1.3 When we act for ourselves. We decide how to use information about the people who run Association accounts, Vendors and Vendor applicants, visitors to our websites, and people who contact us or sign up for our updates. This policy explains that use.
1.4 We do not sell personal information, and we do not share it for cross-context behavioural advertising.
2. Information we collect
- Account information: name, email address, organisation and role. Passwords are handled by our authentication provider and stored only as secure hashes.
- Member and event data that Associations import or collect: member records, contact details, membership status, dues, event registrations, forms and applications, documents and messages.
- Payment information: payments through MeloraPay are processed by Stripe on the Association’s own Stripe account. Card details are entered in Stripe’s payment forms and are not stored by Melora. We keep records of payments, such as amount, date, status and fees. For Associations and Vendors, Stripe collects identity and bank details directly; we never collect or store tax identification numbers, bank account or routing numbers, or dates of birth.
- Vendor applications: business name, contact name, email, phone, location, website, social media handle, service categories, description, price range, chosen plan, portfolio files and notes.
- Event landing page sign-ups: name, email and phone number of people who register interest on an Association’s public event page.
- Messages between Associations and Members sent through Melora Connect.
- Address searches: when you type an address into an address field, the text is sent to our mapping provider to suggest matches.
- Technical information: error reports and basic usage information needed to run and fix the Service. Error reports include an internal user ID and organisation ID, not your name, email or IP address.
- Support and feedback: what you send us when you contact support.
3. How we use information
- To provide, secure and support Melora Connect, including member portals, events, payments and messaging.
- To process payments and record fees through MeloraPay and Stripe.
- To review Vendor applications.
- To send service emails, such as receipts, invitations, reminders and account notices.
- To send marketing emails, only where the law allows, with an unsubscribe link in each one.
- To follow up on event landing page sign-ups, vendor applications and sales enquiries in our customer relationship system (HubSpot), as described in section 6.
- To prevent fraud and abuse, and to enforce our Terms of Service.
- To meet legal obligations.
3.1 AI-assisted features are not active yet. Before we turn one on, we will update this policy to name the provider, describe what data is sent, and state whether it may be used to train models.
4. Cookies and browser storage
4.1 We use only storage that the Service needs to work. We do not use advertising or cross-site tracking cookies, and we do not use analytics trackers.
- Sign-in session, stored in your browser so you stay signed in.
- Preferences, such as theme, sidebar state and the organisation you last worked in.
- Drafts of forms you have not submitted yet, kept on your device.
- Event page visitor ID, a random identifier on Association event landing pages used to count visits and sign-ups.
- Your cookie choice from our cookie banner.
4.2 Our pages load fonts from Google Fonts, so your browser sends its IP address to Google when a page loads.
5. Service providers we use
5.1 These providers process personal information for us under their data processing terms, which limit their use of it to providing their service to us:
| Provider | What they do | Data involved |
|---|---|---|
| Supabase | Database, sign-in and file storage | All data in the Service |
| Cloudflare | Hosting and delivery of the application; bot protection on sign-up and sign-in forms | Requests passing through the Service, including IP addresses |
| Stripe | Payment processing and connected accounts for MeloraPay | Payment, payer and account information |
| Resend | Sending email | Recipient email address and message content |
| Stream (GetStream) | In-app chat | Display name, profile photo and chat messages |
| Sentry | Error monitoring | Error details, internal user and organisation IDs |
| Mapbox | Address suggestions | Address text you type |
| HubSpot | Melora’s customer relationship system: sales and support follow-up of event landing page sign-ups, vendor applications and enquiries | Name, email, phone, company, the event or service involved |
| Google Fonts | Web fonts | IP address and browser information |
| Browser push services (Google, Mozilla, Apple) | Delivering push notifications you turn on | A device address for your browser and the notification text |
5.2 Some pages also load content directly from other companies, which receive your IP address and browser information when the page loads: videos embedded from YouTube or Vimeo, photographs from Unsplash, and the QR code on a member’s digital card, which the goQR.me service draws from the link to that card. Melora Connect does not send text messages yet; if it starts, we will add the provider here first.
6. Other sharing
- Within an Association. Association staff can see member information according to the roles the Association sets.
- Melora staff. Authorised Melora staff can access an Association’s data, mainly to provide support, and also to operate and secure the Service and to meet legal requirements. Access to an Association’s member, payment or other records must be approved by one of a small number of designated approvers at Melora, is limited to that one Association for a set time of no more than one week, and every approval and view is logged. Help requests sent to Melora are handled by our support team without this approval.
- Public pages. Association public pages, such as event pages, are visible to anyone.
- Melora’s customer relationship system. When someone signs up through an Association’s public event page, applies to work with Melora as a vendor, or contacts Melora through a form, we record their name, email, phone and the event or service involved in HubSpot, which Melora uses to follow up with them. Sign-ups from demo accounts are never sent. You can ask us to stop contacting you or to delete this record at any time at support@meloraconnect.com, and every marketing email includes an unsubscribe link.
- Legal reasons. When the law requires it, or to protect people, the Service or our rights.
- Business transfers. If we are involved in a merger, acquisition or sale of assets, information may transfer to the new owner under this policy. We will tell affected customers.
7. Storage, security and transfers
7.1 Our database and files are stored in Canada, with Supabase on Amazon Web Services in Montreal. Cloudflare serves the application from its global network, and other providers, including Stripe, Resend and HubSpot, process data in the United States. If you are outside these countries, your information is transferred to them. Where the law requires, these transfers rely on appropriate safeguards, such as the Standard Contractual Clauses in our providers’ data processing terms.
7.2 Our Security page describes how we protect data.
8. Data retention
8.1 We keep information while the account it belongs to is active. Associations decide how long their member data is kept, within the settings the Service offers.:
- When an Association’s plan ends, its data stays available for export for 30 days and is then deleted within a further 30 days, as set out in the Terms of Service.
- When you delete your own account, your sign-in account is deleted straight away and personal information in your profile is removed within 30 days.
- Payment and tax records are kept as long as the law requires.
- Rejected Vendor applications are deleted 12 months after the decision.
- Backups are overwritten on their normal rotation.
9. Your rights and choices
9.1 Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict some processing, and to withdraw consent.
9.2 What you can do yourself. Members can download a copy of their data from the member portal. Members and Vendors can delete their own account from their account settings. Anyone can unsubscribe from marketing emails using the link in the email.
9.3 Requests. If you are a member, contact your Association first, because it controls your member data. You can also email privacy@meloraconnect.com and we will pass your request to the Association or answer it ourselves where we control the data. We answer within 30 days. We may need to verify your identity.
9.4 If you are in the EU, the UK or another place with a data protection authority, you can complain to it.
10. Children
10.1 Melora Connect is not directed to children under 13, and we do not knowingly collect their information for our own purposes. If an Association’s programmes involve minors, the Association is responsible for any consent the law requires. If you believe we hold a child’s information in error, contact us and we will delete it.
11. US state privacy rights
11.1 Residents of California and other US states with privacy laws have rights to know what personal information we collect and why, to request deletion or correction, and not to be treated differently for using these rights. We do not sell personal information or share it for targeted advertising. To use these rights, follow Section 9.
12. Changes to this policy
12.1 Minor changes take effect when published with a new “Last updated” date. For material changes, such as new kinds of data, new uses or new providers that receive personal data, we will email account owners at least 30 days before the change takes effect.
13. Contact
- Privacy requests: privacy@meloraconnect.com
- Support: support@meloraconnect.com or (571) 290-2703