Skip to main content
Trust

What an institutional buyer needs to know, in one place.

Golbi is used by clubs, nonprofits, schools, and public agencies that handle families, children, dues, and private records. This page gathers our security, accessibility, privacy, and data-handling posture so a reviewer can evaluate us honestly — including what we do not claim.

Security

Each group's private data stays separate.

Golbi is built so one group can never see another group's records, access follows a person's role, and important admin actions leave a history. We describe this in plain language rather than marketing shorthand.

Accessibility

We target WCAG 2.1 AA and check our work.

Accessibility is a hard requirement for many public agencies. Our accessibility statement sets out our conformance target, how we enforce it (automated checks that run across our apps plus manual review), the limitations we know about, and how to report a barrier. We publish a conformance statement; we do not claim to be certified.

Privacy & youth safety

Private by default, with extra care for minors.

Private by default

Member, family, dues, file, and checklist records are private and shown only to the right people. They are never part of the public site, search index, or AI-readable index.

Youth safety

Accounts for minors are guardian-controlled by default. Chat protects minors, and admins never read private direct messages.

COPPA approach

For children under 13 we use a verifiable guardian-consent step before an account is active, and guardians stay in control of their child's data.

Data handling

Where your data lives, and how to get it back.

We use a short, published list of infrastructure subprocessors, with the data and region for each.
You can request access to, export of, or correction of the personal data we hold.
When an account is deleted, we anonymize the person's records in place rather than erasing rows outright — this removes the personal details while keeping the financial and audit history an organization is required to retain.
We update our subprocessor list with reasonable notice before a change takes effect.

Plain-language deletion

"Anonymize in place" means we strip the personal information from a record but keep the record itself where the law or an organization's books require it — for example, a past payment stays on the group's ledger, but it is no longer tied to a named person.

Reliability

An honest word on reliability.

Golbi runs on established cloud infrastructure with routine backups. We do not publish a contractual uptime figure or service-level agreement, and we will not imply one we cannot stand behind. If your procurement needs specific availability or support terms, contact us and we will tell you plainly what we can commit to today.

Public agencies

How we work with public agencies.

Tell us about your requirements and timeline, and we will map them to what Golbi does today — honestly, including gaps.
Security, accessibility, privacy, and data-handling details are available for review on request.
We keep this trust page current so a reviewer can start from published facts, not a sales call.

Procurement contact

For RFP, security-questionnaire, or accessibility-review requests, reach us through the contact page and note that you are evaluating Golbi for an agency or institution. We will route you to the right documents.

What we do not claim

No overpromising.

Certifications we do not hold

Golbi does not hold a SOC 2 report, is not FedRAMP or StateRAMP authorized, and is not HIPAA-covered. We say so plainly. If we complete a formal review in the future, we will publish it here — not before.

Why we spell this out

A trust page is only useful if it is honest about limits as well as strengths. We would rather a reviewer know exactly where we stand than discover an overstated claim later.

Evaluating Golbi for an agency or institution?

Start from these published facts, then contact us for the security, accessibility, and data-handling detail your review needs.