
Tools
CRM
Plan contact fields and access using fictional records.
22 minute read · Reviewed September 3, 2026
What nonprofit CRM work includes
CRM commonly means customer or constituent relationship management. For a nonprofit, it is the people, definitions, practices, records, and technology used to support appropriate relationships with donors, participants, volunteers, members, partners, advocates, event attendees, and other stakeholders. The operating work includes purpose, field definitions, source and provenance, notice and consent where applicable, communication preferences, identity and duplicate handling, relationship stages, access, correction, retention, integrations, security, incident response, accessibility, migration, reporting, and system exit. A spreadsheet can be a CRM; purchasing software does not create a responsible practice.
Why it matters
- Relationship records shape real interactions. A stale preference, unsupported assumption, duplicate record, missing source, or open commitment can lead to confusing, inaccessible, repetitive, or harmful contact.
- Nonprofits often hold information across donation tools, email, event forms, program systems, volunteer files, spreadsheets, phones, paper, and personal memory. A CRM plan must trace those flows instead of treating one application as the whole system.
- More data is not automatically more useful. Each additional field creates collection, explanation, access, correction, security, integration, retention, migration, and deletion work.
- Different relationships create different purposes and boundaries. Fundraising, program service, volunteering, employment, education, health, advocacy, membership, and partnership records should not be combined or reused merely because the software allows it.
- Communication preferences are operational data. An opt-out, pause, language choice, accessible-format request, or preferred channel must reach every relevant sending path and responsible person.
- Narrative notes can quietly become unverified profiles. Separate facts, sources, quotations, assumptions, and staff judgments; avoid unnecessary sensitive detail and provide a correction process.
- Vendors, consultants, integrations, exports, backups, automations, and former users can all retain access or copies. Contracts and settings matter only when owners also test the real data flow and system exit.
- CRM activity is not community impact. Records created, emails sent, meetings held, and follow-ups completed can describe operations; they do not establish relationship quality, consent, service results, donor intent, or mission outcomes.
Stage-specific guidance
Build the CRM practice your stage needs
Inventory where relationship information lives and choose one real decision that a shared record should improve. Define the minimum generic fields, one owner, and one review rhythm before selecting a platform. Test the workflow with fictional records so the team can change it without exposing people.
- List current record locations, responsible people, repeated work, missed commitments, conflicting preferences, and the decision the first shared view should improve.
- Draft a generic field dictionary with purpose, source, sensitivity, access, correction, and retention questions for every proposed field.
- Run the full workflow with fictional data: collect, update, suppress, deduplicate, export, restore, correct, close, and remove a record.
Ready to move on when: Proceed when the team can explain one bounded use, the people affected, the minimum fields, excluded data, owner, access boundary, test evidence, and the next decision without naming a vendor.
Interactive CRM planning tool
Plan your relationship records
Plan contact fields and access using fictional records.
Fictional worked CRM plan
Willow Street Family Resource Network
This fictional forming nonprofit has donor contacts in a giving platform, volunteer names in a spreadsheet, event registrations in email, partner notes in personal documents, and program inquiries in a protected service system. Staff want one CRM before a fall campaign, but the records use different definitions and several contacts have conflicting email preferences.
Weak CRM plan
“Import every contact into the most popular nonprofit CRM, add as much information as possible, tag promising people, automate follow-ups, and let the whole team use the database so nothing gets lost.”
Stronger CRM operating plan
“Purpose: support appropriate follow-up, shared commitments, communication preferences, and named operating decisions; do not store service case details or rank people. People: a resident advisor, program, fundraising, volunteer, accessibility, operations, and executive owners review the design. Boundary: keep protected service records separate. Fields: approve only a record ID, relationship role, source, owner, current stage, next agreed action, review date, and channel-specific preference unless another field has a documented need. Migration: inventory sources, quarantine unknown records, preserve original exports, test with fictional data, reconcile counts and suppressions, then import in reviewed batches. Operations: individual accounts, minimum role access, correction and duplicate queues, quarterly access and field review, incident routing, tested export, and exit deletion. Campaigns use only records with an appropriate source and current channel status; uncertainty pauses outreach.”
The stronger plan starts with decisions, people, boundaries, field definitions, source, preferences, access, maintenance, migration, and exit. It does not assume a vendor, import permission, relationship value, legal compliance, or appropriate secondary use.
A seven-part relationship-record lifecycle
- 01
1. Define the purpose, people, and decisions
Name the relationship work and specific decisions the system should support, who is affected, who shapes the practice, who owns it, and which uses are prohibited. Separate fundraising, programs, volunteers, members, partners, advocacy, and other contexts when their purposes or safeguards differ.
Prompt: Which decision becomes safer or more reliable because this record exists, and who should be able to challenge the design?
- 02
2. Collect the minimum useful record
Inventory existing sources before adding fields. For each proposed field, document purpose, source, notice or authority, sensitivity, less-invasive alternatives, owner, access, correction, and retention review. Test collection and migration with fictional records.
Prompt: What would stop working if this field did not exist, and can the same decision be made with less or no personal information?
- 03
3. Preserve preferences, participation, and access
Record communication choices by channel and purpose, including pauses and suppressions. Provide accessible, language-appropriate ways to understand collection, make a choice, request support, correct a record, or stop contact without requiring unnecessary disclosure.
Prompt: How can a person understand, change, correct, limit, or end this use through every connected path?
- 04
4. Maintain identity, provenance, and relationship work
Use stable internal identifiers and human review for uncertain duplicates. Keep source, date, owner, and status visible; distinguish facts, direct statements, assumptions, and staff notes. Define neutral relationship stages around agreed work, not human value or predicted generosity.
Prompt: How will the team resolve a conflict, duplicate, stale value, unsupported note, missed commitment, or correction request without guessing?
- 05
5. Use records for bounded decisions
Build views and reports around current work: open commitments, preferences, corrections, access needs, stale records, failed flows, and follow-up. Review segmentation, automation, enrichment, prediction, AI, research, and public reporting as new uses rather than harmless features.
Prompt: What action will this report change, what could it misrepresent, and which people or records should be excluded?
- 06
6. Protect access, flows, vendors, and incidents
Use individual accounts, minimum permissions, strong authentication, current administrators, limited exports, approved devices, vendor and integration review, tested backups, offboarding, incident ownership, evidence preservation, and qualified notification and communication review.
Prompt: Who can see, change, export, combine, restore, or delete each field today, and what happens when access or the system fails?
- 07
7. Retire fields, records, integrations, and systems
Create purpose- and source-aware retention reviews with qualified legal, tax, grant, contract, insurance, dispute, and sector input. Distinguish archive, suppression, preservation, deletion, backup expiry, vendor exit, and proof of completion.
Prompt: What ends the need for this information, what may require preservation, and how will the organization verify every copy or downstream flow was handled?
CRM data-stewardship checklist
- The CRM has a written purpose, named operating decisions, affected-person input, accountable owner, backup, prohibited uses, and a stated review interval.
- Current spreadsheets, forms, donation systems, email tools, event platforms, program systems, devices, paper, exports, backups, service providers, and personal files are inventoried.
- Every proposed field has a plain-language label, purpose, source, notice or authority, sensitivity review, minimum access role, correction path, retention review, and less-sensitive-alternative question.
- The CRM excludes passwords, payment credentials, identity documents, protected case files, health or education detail, and unnecessary sensitive narrative; approved purpose-specific systems hold information that must remain separate.
- Collection points explain relevant purpose and choices in accessible language and formats; imported or partner-supplied records retain source, terms, date, limits, and review status.
- Email, text, phone, mail, event, fundraising, program, language, format, pause, and do-not-contact preferences have definitions, owners, timestamps, sources, and propagation tests.
- Identity matching does not rely on name alone; uncertain duplicates are reviewed, source records remain traceable, merge decisions are recorded, and incorrect merges can be repaired.
- Relationship stages describe current agreed work, next action, owner, date, commitment, pause, decline, or closure without scoring worth, generosity, trust, need, eligibility, or risk.
- Individual accounts, least-necessary roles, administrator coverage, multifactor authentication where supported, approved devices, export limits, shared-account prohibition, and offboarding are reviewed.
- Corrections, bounces, returned mail, stale records, conflicting preferences, unsupported notes, failed integrations, and open commitments enter named queues with completion evidence.
- Retention distinguishes operational need, tax and grant records, contracts, disputes, legal holds, sector duties, suppression, archive, deletion, backup expiry, and vendor copies through qualified review.
- Every integration and export documents fields, purpose, direction, frequency, access, owner, failure alert, preference behavior, service provider, contract, backup, and exit path.
- The incident plan names internal and external contacts, immediate containment, evidence, insurer and counsel routing, current jurisdiction review, affected-person communication, recovery, and lessons learned.
- Reports name definitions, missingness, duplicates, exclusions, time window, source, access, limitations, owner, and decision; operational activity is not labeled relationship quality or impact.
- Migration and vendor selection test accessibility, permissions, security, exports, integrations, support, cost, capacity, reconciliation, rollback, training, deletion, and system exit with fictional records first.
Common nonprofit CRM mistakes
- Choosing software before defining the work.
- Define decisions, people, fields, access, maintenance, integrations, retention, capacity, and exit first; compare vendors against those requirements.
- Importing every contact because the organization already has it.
- Inventory source, relationship, notice, permission, purpose, age, preferences, restrictions, and quality; quarantine uncertainty and exclude records that lack a responsible use.
- Treating one unsubscribe as an email-only cleanup task.
- Define channel- and purpose-specific preferences, preserve necessary suppression evidence, and test propagation across every relevant sending system and owner.
- Giving the whole team full access for convenience.
- Map tasks to minimum roles, use individual accounts and strong authentication, constrain exports, review administrators and former users, and document exceptions.
- Writing subjective personal judgments in open notes.
- Use bounded factual notes with source, date, purpose, access, correction, and retention; keep sensitive detail out and prohibit labels that rank human value or infer protected traits.
- Merging duplicates automatically on a weak match.
- Use stable identifiers, preserve source records, review uncertain matches, record the merge decision, and maintain a repair path.
- Calling an integration complete when data moves once.
- Test direction, field mapping, preferences, updates, deletions, errors, retries, ownership, access, reconciliation, backup, and vendor exit.
- Reporting contact count or pipeline size as relationship strength.
- Report the operational fact accurately and use direct feedback, fulfilled commitments, process evidence, and appropriate program or fundraising measures for other questions.
Evidence for CRM operating decisions
Use measures that help the team maintain a useful, bounded, and accountable system. CRM measures describe records and operations; they do not establish consent, trust, relationship quality, donor intent, service eligibility, causality, or community impact.
- 01Purpose and field discipline: active fields have current definitions, owners, uses, source expectations, access roles, retention reviews, and evidence of actual use in named decisions.
- 02Preference integrity: channel choices, pauses, suppressions, language and format needs, corrections, and source dates propagate accurately across connected systems within the reviewed process.
- 03Data quality: duplicate candidates, confirmed merges, repaired merges, missing sources, stale records, bounces, returned mail, unsupported notes, correction requests, and time to resolution remain visible.
- 04Relationship operations: open and completed commitments, follow-up age, responsible owner, voluntary pauses, declines, closures, and unresolved handoffs are reviewed without scoring people.
- 05Access and security: active users, administrators, role changes, former-user removals, multifactor-authentication coverage where supported, exports, shared-account exceptions, incidents, recovery tests, and unresolved risks are tracked.
- 06Data flows and vendors: integrations, failed runs, reconciliation differences, service-provider access, contract reviews, backups, exit tests, and verified deletion or return actions are current.
- 07Retention work: records and fields reviewed, archived, preserved, suppressed, deleted, awaiting qualified review, or found in downstream copies are counted by defined category and source.
- 08Decision use and burden: the team records which operating decision changed, supporting evidence, limitations, staff time, training needs, manual work, user feedback, and whether a field, flow, report, or tool should be maintained, revised, replaced, or stopped.
Primary references
Sources and review
- Coach House Accelerator
Coach House
The internal learning sequence behind this guide: current-system inventory, relationship mapping, donor journey stages, next-action ownership, follow-up cadence, and tools-and-systems planning.
- Protecting Personal Information: A Guide for Business
Federal Trade Commission
Federal guidance to inventory personal information, keep only what is needed, protect it, dispose of it securely, and prepare for incidents.
- Start with Security: A Guide for Business
Federal Trade Commission
Federal security guidance on necessary collection, retention, access, authentication, service providers, secure storage, disposal, and current practices.
- Data Breach Response: A Guide for Business
Federal Trade Commission
Federal incident-response guidance covering containment, evidence, affected systems and people, qualified notification review, communication, and remediation.
- Using Privacy Framework 1.1
National Institute of Standards and Technology
A voluntary federal framework for identifying and managing privacy risk across organizational roles and the wider data-processing ecosystem.
- Secure Our World
Cybersecurity and Infrastructure Security Agency
Federal public guidance on multifactor authentication, strong passwords and password managers, software updates, and recognizing and reporting phishing.
- Recordkeeping Requirements for Exempt Organizations
Internal Revenue Service
Federal tax guidance on records needed to support activities, income, expenses, credits, returns, and tax compliance; CRM retention must align with the actual record and purpose.
- CAN-SPAM Act: A Compliance Guide for Business
Federal Trade Commission
Federal guidance for reviewing commercial-email classification, sender information, subject lines, disclosures, opt-out handling, vendors, and monitoring.
- Targeting and Eliminating Unlawful Text Messages
Federal Communications Commission
Small-entity guidance for businesses, nonprofits, and small governments on FCC text-message rules; confirm current classification and requirements for each proposed use.
- Covered Entities and Business Associates
U.S. Department of Health and Human Services
Federal guidance on which defined entities and business associates are covered by HIPAA; nonprofit status alone does not answer applicability.
- Frequently Asked Questions about FERPA
U.S. Department of Education
Federal guidance on FERPA applicability and education records; applicability depends on the educational institution, funding, record, disclosure, and facts.
- ADA Requirements: Effective Communication
U.S. Department of Justice
Federal guidance on effective communication and auxiliary aids and services for covered public entities and businesses or nonprofits serving the public.
- How to Meet WCAG 2.2
World Wide Web Consortium
A filterable reference for web accessibility criteria, techniques, and failures relevant to CRM forms, notices, preference centers, tables, and connected tools.
- State Attorneys General
USAGov
Official directory for state and territorial attorneys general, whose offices may publish current privacy, breach, consumer-protection, and charitable guidance.
This educational guide and planning tool do not collect, import, identify, enrich, merge, deduplicate, segment, rank, score, contact, message, solicit, disclose, export, synchronize, back up, preserve, archive, delete, or verify constituent records; connect to a CRM, spreadsheet, email, text, donation, event, volunteer, program, health, education, employment, accounting, identity, analytics, AI, or other system; create a privacy notice, consent, suppression, retention schedule, legal hold, security program, incident response, contract, business associate agreement, policy, filing, or legal opinion; determine whether a field is necessary, accurate, accessible, safe, authorized, permitted, protected, retained, or fit for use; determine whether HIPAA, FERPA, CAN-SPAM, FCC rules, state privacy or breach law, tax records, fundraising rules, grant terms, contracts, insurance, or other requirements apply; approve a vendor or migration; predict relationship quality, donations, participation, eligibility, risk, or impact; or replace affected-person, accessibility, program, fundraising, records, privacy, security, vendor, insurer, board, legal, tax, or other qualified review. Requirements vary by organization, tax status, sponsor, relationship, activity, data, promise, source, use, channel, system, contract, funding, sector, person, location, jurisdiction, and facts.