FERPA-aligned by design
iManageVolunteers handles family and student data in alignment with Family Educational Rights and Privacy Act (FERPA) requirements. Student information is used only for the purpose it was collected — managing your school's volunteer and fundraising program. It is never shared with third parties, never used for advertising, and never commingled with data from other schools.
Your data stays with your school
Each school on iManageVolunteers operates in a dedicated database, accessed only by users authenticated to that school's account. We enforce tenant boundaries at every API request — your school's records are not visible to other schools, our staff, or anyone outside your authorized roster. You retain all rights to the data you and your families enter, per our Terms of Service.
Encryption & access controls
All data is encrypted at rest and in transit. Role-based access controls enforce visibility scoped to each user's role — families see their own family's information, coordinators see their organization's scope, teachers see their classroom roster, and administrators see school-wide. Every database query is scoped to the user's role and tenant before any data is read.
Built on enterprise-grade infrastructure
iManageVolunteers runs on enterprise-grade cloud infrastructure with SOC 2-aligned security practices, high availability, and automated backups. We don't cut corners on the foundation.
Service providers
iManageVolunteers uses a carefully selected set of service providers to operate the platform. Each provider processes information on our behalf under strict contractual controls.
- Clerk — authentication, session management, password storage
- Neon — PostgreSQL database hosting on AWS US East 1
- Vercel — application hosting and CDN
- Telnyx — SMS delivery for opt-in family alerts
- Anthropic — Volly AI assistant (Claude API)
- Replicate — AI image generation (Flux)
- Stripe — payment processing (Connect; school receives funds directly)
- Resend — transactional and broadcast email
- Ably — real-time messaging infrastructure (Org Chat, auction bidding)
- Sentry — error monitoring
- Cloudflare — DNS and DDoS protection
Audit trail
Every administrative action in iManageVolunteers — hour approvals, role changes, event lifecycle changes, configuration updates, broadcast sends, auction events, and bulk operations — is recorded with full context: who performed it, what changed (before and after), when, and from what IP address. Audit log entries are immutable from the application; no API exists to edit or delete them. School administrators can view and export their school's audit log.
Artificial Intelligence & Your Data
iManageVolunteers Intelligence (Volly) is built with the same data isolation principles as the rest of the platform. Volly only sees your school's data — never another school's. Your conversations with Volly and your family data are never used to train AI models. Your data stays yours, full stop.
Role-based access controls apply to Volly the same way they apply everywhere else in the platform. A family can ask Volly about their own hours and upcoming events — not another family's. A coordinator sees their organization's data. An administrator sees the full picture. Volly respects every boundary the platform enforces.
Two-administrator verification
Critical decisions — finalizing school years, approving rate changes — require confirmation from a second administrator. This design choice protects your school from both mistakes and unauthorized changes.