The questions your board will ask — answered.
Development directors, finance committees, and boards need more than a demo. This page describes how Mission Control handles your data, your donors, and your money.
Your donor data is yours
Every supporter, donation, order, member, and pledge record belongs to your organization. Export the full record set to CSV at any time from the dashboard. We do not sell, rent, or share your donor list, and we do not market to your donors on our own behalf.
- Full CSV export of supporters, donations, orders, and members
- No donor list sold, rented, or cross-marketed
- Records stay yours if you leave the platform
Organization-level isolation
Each organization's data is separated at the database layer, not just in the interface. Every read and write is checked against your organization and the signed-in user's role before it returns a row — including the records our own campaign managers touch.
- Row-level access rules on every data table
- No cross-organization visibility for org users
- In Play staff access is scoped and logged
Roles, seats, and approvals
Staff, board members, and volunteers get the access their job requires and nothing more. Reviewers can approve messaging without touching donor records. Viewers can read reports without editing anything.
- Org Admin, Reviewer, and Viewer roles
- Invite-based seats with revocable access
- Communication approvals before anything sends
Receipting and acknowledgment
Gift receipts include your legal name, EIN, signatory, gift date, and amount, with goods-and-services value separated from the deductible portion where an item was received. Year-end statements can be generated for every donor in bulk.
- EIN and authorized signatory stored per organization
- Deductible amount separated from purchase value
- Bulk year-end donor statements
Payments and card data
Card payments are processed by Stripe. Card numbers are entered on Stripe-hosted fields and never pass through or get stored in Mission Control. Payouts settle directly to your organization's bank account.
- Stripe-hosted card entry — no card data stored by us
- Payouts to your organization's account
- Refunds and reconciliation from your dashboard
Consent and communications
Email and SMS consent is recorded per contact with its source. Unsubscribes and bounces are honored automatically and suppressed on future sends, and every send is logged with delivery outcome.
- Per-contact consent with recorded source
- Automatic unsubscribe and bounce suppression
- Delivery, open, and click logs per message
What we actually do, in plain terms.
No certification badges here — just the controls that are in place today, so your IT or finance reviewer can check them off.
Access and authentication
- Individual accounts — no shared logins between staff or volunteers
- Role-based permissions checked on every request, not just hidden in the UI
- Invite-based seats that an Org Admin can revoke at any time
- In Play staff access to an organization is scoped and recorded
Data protection
- Traffic encrypted in transit over HTTPS/TLS
- Database storage encrypted at rest by our cloud infrastructure provider
- Managed, automated database backups
- Organization data separated at the database layer with row-level rules
Data lifecycle
- Full CSV export of your records, self-serve from the dashboard
- Deletion of your organization's data on written request
- Contact-level unsubscribe and suppression honored across all future sends
- Donor and supporter records retained while your account is active
Reporting an issue
- Email marshall@inplaysportswear.com with "Security" in the subject line
- We acknowledge reports within two business days
- Please do not publicly disclose an issue before we've had a chance to respond
- We do not pursue legal action against good-faith researchers
Two things worth being direct about.
Card data never touches us
Every card payment is entered directly into Stripe-hosted payment fields. Card numbers, CVCs, and expiration dates are never transmitted to, processed by, or stored on Mission Control servers — we only ever see a Stripe reference and the amount. This is the arrangement Stripe describes as the lightest card-handling scope for a merchant, and it means your organization is not storing card data either.
Stripe is a PCI DSS Level 1 certified service provider. That certification is Stripe's, not ours — we are not making a PCI certification claim on our own behalf.
Not intended for health information
Mission Control is a fundraising platform. It is not designed, configured, or offered as a HIPAA-compliant system, and we do not sign Business Associate Agreements. Please do not upload protected health information — patient lists, diagnoses, treatment details, or any records derived from a clinical relationship — into supporter notes, imports, or custom fields.
Hospital foundations and health charities are welcome on the platform for ordinary donor and development work. If your use case would require PHI, talk to us first so we can tell you honestly whether we're the right fit.
Built for organizations that answer to a board.
Everything a development committee asks for at the quarterly meeting is already a report, not a spreadsheet project.
- Board-ready campaign and revenue reporting, exportable for meeting packets
- Mission Score history so leadership can see trend, not just a snapshot
- Attribution reporting showing which channels produced revenue
- Pledge, grant, and major gift pipelines with owner and next step on every record
What we do, and what stays with you.
- Running the platform, hosting, and backups
- Building and sending the campaign creative and messaging
- Payment processing through Stripe and order fulfillment
- Access controls, roles, and staff access logging
- Approving messaging and creative before it goes out
- Who you invite into your account and at what role
- The accuracy of your EIN, signatory, and receipting details
- Your own privacy policy, gift acceptance policy, and donor commitments
This page is maintained by In Play Fundraiser to answer common security, data, and privacy questions about Mission Control. It describes product capabilities and current practices — it is not a certification, audit report, or legal advice. If your organization requires specific contractual terms, a data processing agreement, or documentation for a funder or procurement review, contact us and we will work through it directly.
Ready to take this to your board?
We'll walk your team through data handling, roles, and reporting before anything goes live.
