Classy
United States · www.classy.org · 28 vendors
Classy is a B Corp Certified social enterprise that provides an online fundraising platform for nonprofit organizations. It offers a suite of tools for peer-to-peer fundraising, crowdfunding, events, and donation management to help nonprofits raise money and engage their communities. Classy was acquired by GoFundMe in 2022.
Resilience scores
- Digital Sovereignty: 79
- Digital Resilience: 7
Disruption prediction
Classy has an estimated 21% probability of disruption in the next 6 months.
15 of Classy's 28 vendors monitored for disruptions.
Technology vendors
- Double the Donation — United States
- PLAID, Inc. — Technology — Japan
- Stripe, Inc. — Financial Services — United States
- and 26 more
Services catalogue
2 services in catalogue across 2 categories; runs on 28 sub-vendors.
- Donation Platform
- Personal Data Processing
Insights
Last updated 2026-07-30 · revision 2
28 direct vendors, 290 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- United States: 22
- Sweden: 1
Subvendors by controlling owner country (sample)
- Germany: 6
- Netherlands: 3
- Italy: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Classy exhibits a strong foundation for migration readiness due to its heavy reliance on cloud-based services and SaaS platforms. Its internal tech stack includes Amazon Web Services (AWS), Salesforce, Snowflake, Stripe, PayPal, and Coinbase Commerce, indicating a modern, distributed, and API-driven architecture. The presence of a 'RESTful Open API' suggests good interoperability and ease of integration, which are beneficial for migration. Adherence to 'PCI DSS Level 1 Compliance' implies robust security practices that would need to be maintained during any migration. The absence of specified 'Data Residency Requirements' offers flexibility in choosing new infrastructure locations. However, the assessment is hampered by the 'Vendor Lock-in Risk' being unknown, which is a critical factor in migration complexity. While the diversity of vendors (AWS, Stripe, Salesforce, etc.) reduces single-vendor lock-in, the reported 'Total Services: 29' suggests a potentially large number of integrations that would need to be managed and reconfigured during a migration, increasing complexity and effort. The use of 'WordPress (WP Rocket)' could represent a legacy component if not managed in a containerized or highly modular fashion, potentially adding friction to a full-scale migration. Missing financial data also prevents an assessment of the company's ability to fund a significant migration effort.
Compliance
6 in-scope frameworks identified; showing 3.
CCPA — Partially Compliant
Classy/GoFundMe Pro explicitly addresses CCPA and multiple US state privacy laws in its Privacy Notice, including California, Colorado, Virginia, Utah, Connecticut, Nevada, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Tennessee, Kentucky, Indiana, and Rhode Island. The company provides opt-out mechanisms, data subject request forms, and a dedicated CCPA notice. The risk is Medium because: (1) the regulatory landscape is rapidly evolving with new state laws taking effect; (2) the company processes data of residents across all US states; (3) AI/ML use for donor profiling and personalized ask amounts may trigger additional obligations under some state laws; (4) 'Partially Compliant' reflects that while infrastructure exists, the rapidly expanding state law landscape creates ongoing compliance gaps.
Evidence: https://pro.gofundme.com/c/legal/privacy-notice/, https://pro.gofundme.com/c/legal/privacy-choices/
ISO 27001 (source) — Assessment Required
ISO 27001 certification is increasingly expected for enterprise SaaS platforms handling sensitive financial and personal data. Classy/GoFundMe Pro's security page describes an Information Security Management System (ISMS)-consistent approach including 24/7 monitoring, vulnerability scanning, IDS/WAF/DDoS protection, role-based access control, encryption, and key management. However, no ISO 27001 certification is mentioned in any publicly available documentation. The risk is Medium because: (1) the absence of ISO 27001 certification may be a gap for enterprise clients requiring it; (2) the company's security practices appear mature but are not independently certified under this standard; (3) PCI DSS Level 1 compliance (which is independently audited) provides some assurance of security controls, but ISO 27001 covers a broader ISMS scope.
Evidence: https://pro.gofundme.com/c/platform/security/
GDPR (source) — Partially Compliant
Classy (now GoFundMe Pro) is a US-headquartered company that explicitly acknowledges processing personal data of EEA and UK residents. The privacy notice confirms GoFundMe Ireland Limited acts as the EU data controller and GoFundMe International Services UK Ltd acts as the UK data controller, with a named Data Protection Officer (dpo@gofundme.com) and Standard Contractual Clauses (SCCs) in place for cross-border transfers. These are strong indicators of active GDPR compliance efforts. However, the status is 'Partially Compliant' rather than 'Compliant' because no independent GDPR audit or certification has been publicly disclosed, and the company processes sensitive personal data (health information, political opinions, religious beliefs) in fundraiser contexts, which carries elevated GDPR risk under Article 9. The risk level is Medium rather than High because the company has clearly invested in GDPR infrastructure (DPO, SCCs, EU entity, regional disclosures), but the absence of a third-party audit and the handling of special category data introduces residual risk.
Evidence: https://pro.gofundme.com/c/legal/privacy-notice/, https://pro.gofundme.com/c/platform/security/
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.