Keeping your account secure 🔒
Account takeovers usually start small – a reused password, a shared login nobody's paying close attention to, or an old teammate's access that never got revoked. Take a few minutes to learn about account security, eliminate common weak points and keep your Givebutter account as secure as possible.
Enable 2FA 📱
Two-factor authentication (2FA) adds a second login step after you enter your password, so your account stays protected even if your password is ever exposed. Givebutter requires 2FA when logging in from a new location, and we recommend enabling it as a best practice.
Go to your personal profile and locate the Security section.
Enable 2FA and save a phone number or email to receive your codes.
Use a unique password 🔑
Don't reuse your Givebutter password anywhere else! If a password is exposed in a breach on another site, scammers will try to access other platforms using the same email/password combination. Using a unique password keeps a breach elsewhere on the internet from becoming a breach on Givebutter.
To change your password, go to your personal profile and click Change password, located to the right of your profile picture.
If you don't remember your current password, use the password reset page instead.
Skip shared logins 👤
All accounts should give each staff member their own login. Shared logins (like one team account for [email protected]) make it difficult to tell who took an action. It also makes it impossible to revoke one specific person's account access. Givebutter doesn't charge per account user, so there's no cost to setting everyone up individually! Additionally, preset roles (Admin, Finance, Campaign Editor, CRM Manager, Mobile Access) let you control exactly what each person can see and do.
Go to Settings page, then click on the Users tab.
Click Invite user.
Enter their name and email, and check the role(s) that fit what they need to do. Access can also be limited to specific campaigns.
Review account access 🕵️
Old logins that aren't actively being used are an easy entry point if their login credentials are ever compromised. Make it a habit to check who still has access, and only keep active logins for people who currently need them.
Go to Settings page, then click on the Users tab.
Take a look at each user's last login time. Anyone inactive for 6+ months is flagged with a warning indicator.
Remove anyone who no longer needs access by clicking the [...] menu next to their name and selecting Delete.
End old user sessions ❌
If you've ever logged into Givebutter from a public computer, a lost device, or a browser you no longer use, forgetting to securely log out can put your account at risk. Reviewing and ending sessions you don't recognize (or aren't actively using) helps keep your login secure.
On your own profile, check the Active Sessions section and click End Session on any login you don't recognize.
Check payout information 🏦
Confirm the correct bank account or debit card is connected to Givebutter so your funds always reach the right place. This is especially worth checking after any change in staff or finance leadership, or if anything about a payout looks suspicious.
Go to your Payouts or Finance page and open the Settings tab to review your connected bank account or card.
You'll be asked to verify with 2FA before viewing or editing this information.
Watch for phishing scams 🐟
Phishing emails may try to trick you into clicking a harmful link or handing over sensitive information, like passwords or bank details, often by impersonating a trusted source (such as a grant funder, sponsor, or Givebutter itself).
⚠️ Nonprofits have recently seen a rise in fraudulent grant offers, donation match offers, and sponsorships targeting admin and finance staff.
Don't click links in unexpected emails from senders you don't recognize.
Keep an eye out for terms like "undisclosed recipients", "shared document", or "invitation to apply".
Don't provide banking details or account logins in response to an unsolicited email. A legitimate funder won't ask for this through an emailed link.
What if a message looks legitimate? Watch out for:
Lookalike names and domains: Swapped or added letters, a real name added to a longer domain, or a variation of a name or website URL you may be familiar with. Examples include: Give Butter, givebutter‑support.com, and givebutter.account-verify.net. Independently verify an email sender or website URL before clicking anything in an email.
Display name spoofing: The email sender shows up as Givebutter Support or a person's real name, but the actual email address doesn't match. Always check the full email address, not just the name shown.
Mismatched reply-to: The visible sender information looks correct, but replying (or checking the "reply-to" field) routes to a totally different address.
Character substitutions in links: A "0" instead of an "o", a "1" for an "l", or "rn" standing in for "m". Easy to miss at a quick glance in a URL.
Branding that doesn't look quite right: A logo may be stretched or low-resolution, colors are a shade off, or a footer could be missing standard legal/unsubscribe text.
Pressure to move off email: Asking you to continue over text or a messaging app instead, which sidesteps spam filters and leaves a request harder to verify.
Our built-in protections 💛
The steps above are things you can do to keep your account secure, but Givebutter also builds several layers of protection into the platform itself:
Encrypted processing – Every transaction and payout is processed through Stripe, our PCI-compliant payment processor, using bank-level encryption. This means your organization's bank account details and your donors' card numbers are never stored on Givebutter servers. This means if a Givebutter login is ever compromised, no financial information can be exposed.
Limited internal access – Givebutter staff are only given access to the account information they need for their specific job, and anyone with access to sensitive data completes security training.
Real-time monitoring for fraud and unusual activity – Our Trust & Safety team monitors account and payout activity for signs of fraud or unauthorized changes, like a sudden switch to new bank information. If something looks off with your account, our team may flag it for review before funds move. This is also why you may occasionally be asked to verify a payout or provide additional information. This is a routine check to make sure your accounts are secure.
Secured systems and data – We restrict who and what can connect to our servers and databases, encrypt data in transit and at rest, and keep detailed records of system access. We also back up data regularly and run internal audits. (Think of this as Givebutter locking each door in our system, keeping a log of who goes through the doors, and regularly checking that the locks work as expected.
Bot and scraping protection – We block automated bots from scraping contact information off campaign pages or submitting fraudulent forms. This keeps organization and donor contact details harder for scammers to find and misuse.
If you suspect your account has been compromised 🚨
End all active user sessions and reset your password immediately.
Confirm 2FA is enabled and review your user list for any logins you don't recognize.
Contact Givebutter support so our Trust & Safety team can investigate.



