
Posted: August 27, 2026
Author: Tim Stirrup
We were talking recently with the finance leader of a parish and school. We got onto their offertory, and pointed out that they were paying north of $20,000 a year in platform fees on their online giving. We expected him to be annoyed. Instead he waved it away. “ A rounding error”, he said, next to the real risk - moving their recurring donors to a new provider.
That sentence has stuck with us, because it's exactly backwards.
Twenty thousand dollars a year, forever, is not a rounding error. But he wasn't wrong to be scared. He'd been made scared on purpose. And that fear, not the fees, not the features, is the thing quietly propping up a lot of the digital giving industry.
When a supporter sets up a monthly gift, their card isn't stored on your donation form. It's stored by a payment gateway as a token - a stand-in reference that lets the next charge go through without anyone touching the raw card number. That tokenization is genuinely good security. The problem is who holds the token.
On most integrated donation platforms, the platform holds it, not you. So when you decide to leave, you can usually export the easy stuff. Names, emails, giving history, a nice CSV. What you often can't take is the one thing that keeps the money flowing: the payment credentials behind your recurring donors. Export the contact list, lose the income.
This isn't a fringe complaint. A 2025 review of 33 popular donation platforms by the agency Whole Whale found the market split roughly into two failure modes. There are "hard walls", platforms that simply won't let recurring payment tokens leave at all and "toll walls," where migration is technically allowed but gated behind high, opaque, or per-donor fees.
One large nonprofit was reportedly quoted around $30,000 to free its own donor base. Paying a flat fee plus a per-token charge across roughly 20,000 donors. A senior figure at another platform described seeing nonprofits literally "in tears" over ransoms like that.
And the reason it matters so much: if you can't migrate the credentials and instead have to ask every monthly donor to re-enter their card, the sector's own rule of thumb is that you lose 70–80% of them.
For an organization that spent years building that donor base, that's not simply a switching cost. That's a moat. It’s not your moat, and you're on the wrong side of it.
Ask why the tokens can't move and you'll hear the same words: PCI-DSS. Card-network rules. Tokens are gateway-specific. Security.
Every one of those things is real. Stored card data is heavily regulated, tokens genuinely are tied to the gateway that minted them, and nobody should want donor card numbers emailed around in a spreadsheet. If a platform said "we can't just hand you a file of raw card numbers," they'd be right.
But the question to be answered is actually whether there's a secure, compliant, provider-to-provider path to move recurring payment data when a customer wants to leave.
And we know the answer, because the for-profit payments world settled it sixteen years ago!
Back in 2010, the payment gateway Braintree launched a Credit Card Data Portability Standard which was deliberately modeled on telephone number portability and with the stated goal of "eliminating vendor lock-in for merchants" through a PCI-compliant, standards-based transfer.
Vault to vault, both sides PCI-compliant, the merchant never touching the raw data. Within about a year, they'd completed transfers from nearly every major provider in the industry. Braintree's own summary of the excuses they'd heard beforehand is worth remembering: they ranged from PCI and "security risk" all the way down to "we just can't get it."
Today a business switching payment processors treats it as routine. It’s often done in under an hour. The exact same category of data that a for-profit merchant moves in an afternoon is the data a nonprofit is told is impossible to move, or costs $30,000 to release. The barrier is actually the business model.
The striking thing about donor lock-in is how specific it is to the nonprofit world. Look at how other industries treat portability of important, sensitive data.
Your phone number. Under the FCC's number-portability rules, your number is yours. Your old carrier cannot refuse to release it even if you still owe them money, and a simple port completes in one business day, with the new carrier doing the work. Nobody thinks this is radical anymore.
Your bank's recurring payments. When you change banks, you expect your direct deposits and automatic payments to follow you and increasingly they do. Many US banks now offer switch tools (often powered by services like ClickSWITCH) that move your direct deposit and recurring ACH payments to the new account for you, because making it easy is how they win your business. The rest of the developed world has gone further and simply required it! The UK's Current Account Switch Service moves your entire account - every direct debit and standing order, the direct analogue of recurring donors - for free in seven working days under a guarantee, and since 2016 the EU has legally mandated a free switching service across every member state. Whether by competition here or by law abroad, the principle is settled. Your recurring payment relationships are yours, and leaving shouldn't cost you them.
Your passwords - the most sensitive data of all. This is the one that should end the "it's too sensitive to move" argument for good. Rival password managers including 1Password, Apple, Bitwarden, Dashlane, Google, Microsoft and others, have jointly built the Credential Exchange Protocol and Format through the FIDO Alliance, precisely so people can move passwords and passkeys between competitors, encrypted end to end, without the old insecure CSV dump.
Dashlane's own export documentation now offers it as a first-class option and calls it "part of a broader industry push for open standards." No regulator forced this.
Competitors chose to make leaving easy, with data far more sensitive than a tokenized donor card, because they were confident enough to compete on merit.
And that's before you get to the broader legal direction of travel. The EU's GDPR already grants individuals a right to receive their data in a machine-readable form and send it to another provider, and open-banking frameworks around the world are pushing the same principle into financial services.
Telecoms, banking, password management, general payments. Sensitive data, important relationships, real security constraints. But portability solved anyway, sometimes by regulation, sometimes by the industry deciding lock-in was beneath it.
Nonprofit donation processing is the conspicuous holdout, the one corner of the economy where "we're keeping your recurring donors" is still an accepted answer.
None of this is a demand that platforms do something unsafe. It's the opposite. The ask is that donation processing matures the way payments already did.
We want to see an open, PCI-compliant standard for recurring-donor portability. A shared, vault-to-vault path any two providers can use, so that moving your donation processor is a supported process and not a favor you beg for and pay for. Where card-network rules genuinely prevent a specific credential from transferring, the fallback should be standard too. Hand over the full recurring schedule and support a re-authorization campaign. There should never be silence, and never a $30,000 invoice.
The National Council of Nonprofits' Principles for Ethical Online Fundraising already name this. Their "partnership" principle is, in plain terms, that a platform shouldn't hold a nonprofit captive. Portability is how you prove you mean it.
At Better Giving we've endorsed the NCN fundraising principles, and we've tried to make the partnership one concrete rather than aspirational. Our Recurring-Donor Portability Guarantee is simple.
Your data and full giving history are yours to export anytime, free. We actively help move your recurring-donor payment records to your new processor and none of it is ever conditioned on a fee or a new contract.
If you'd rather not depend on us at all, the platform is open source - you can self-host it with your own gateway, and the tokens never leave your control in the first place.
Because here's the thing that finance leader's shrug made clear to us. We are never going to raise the ethical floor of this industry while incumbents can defend their revenue with lock-ins instead of earning it in honest competition.
If your nonprofit customers stay because leaving would cost them, that's not loyalty, it's a hostage situation with better branding. Make leaving easy, and you have to be worth staying for.
Nonprofit recurring donors were never the platform's to keep. Let's build an industry that acts like it.
Use our free, no-signup checklist to review your platform’s fees, consent practices, payout timing, transparency, and accountability.