Shared Hosting
The plan type nearly every nonprofit site belongs on, and what the higher tiers actually change.
Read about shared hostingA nonprofit website has one page that carries the organisation. It is the donate page, and a large share of the year's giving arrives through it in the final days of December. Almost every decision about web hosting for nonprofits should be judged against whether it helps that page work on 31 December.
Look at when the money arrives and the shape is the same at almost every organisation. Giving trickles along all year, lifts in the autumn appeal, and then a large block of it lands in the last week of December. Some of it lands on 31 December itself, in the evening, from people making a decision before a deadline.
That concentration is the whole story. It means the donate page is not one page among thirty. It is the page. It also means the cost of a failure is not spread evenly. A donate page that breaks in March costs you a few gifts. The same failure on 31 December costs you a meaningful part of the year, and there is no second chance at it, because the reason people are giving that day is that the year is ending.
Rarely the server. In practice the failures we see are boring and preventable, and most of them were introduced by somebody trying to improve the page.
None of those are solved by a bigger plan. They are solved by somebody clicking the donate button in early November, on a phone, and following it all the way through to a real charge.
Send us your site and we will follow the donate path the way a supporter does, on a phone, and tell you what breaks before December. Often the answer is that your hosting is fine and one link is wrong.
This is the single most useful thing to understand about nonprofit hosting, and it removes a lot of anxiety once it lands.
Your website should not collect, process or store card numbers. It should hand the donor to a payment processor or a donation platform, which does that work under its own compliance obligations, and receive back a confirmation. The card number never arrives on your hosting at all. Whether that happens on the processor's own page or inside an embedded form on yours, the sensitive part is handled by them.
The consequences are worth spelling out. You are not storing anything that would be catastrophic to lose. Your compliance burden is far smaller than it feels. And the hosting requirement for a donate page is, honestly, close to the requirement for an ordinary contact page. It needs to load, it needs a valid certificate, and it needs the link to be correct.
If anyone has built you a form that takes a card number into your own website and emails it, or stores it in the site's database, stop and get that changed. That is a real problem and it is not a hosting setting. Ask your processor how they expect the handoff to be done.
The certificate part is not optional. A browser warning on a donate page ends the donation. Your SSL certificate should be in place, valid, and covering both the www and non-www version of your domain, and you should know when it renews rather than finding out from a supporter.
The other quiet failure is the domain itself. A charity domain registered years ago by a board member who has since moved on, on an email address nobody monitors, will eventually lapse without warning. That takes the donate page down along with everything else. The domain expiration page covers how to stop that, and it is worth an hour of somebody's time this month rather than in December.
This is a short annual routine rather than a project. Do it in early November, while there is still time to fix what you find.
Not a test mode transaction. A small real gift, on a phone, on mobile data rather than the office wifi, following the exact path a supporter takes from your appeal email. Then check that it arrived in the account, produced a receipt, and appeared wherever you track donors.
Open the donate page cold and count how long until the giving form is usable. If a video, a slideshow or a bank of tracking scripts loads first, move them off that page. The donate page can be the plainest page on the site and it will perform better for being plain.
The button in the main navigation, the button in the footer, the link in last year's appeal email, the link in your email signature, the link in your social profiles. Old links outlive the pages they pointed at. Click all of them.
Both should be well clear of the end of the year. If either renews in December, move the renewal or make certain the payment card on file has not expired.
A backup nobody has tested is a hope, not a plan. Confirm you can get the site back, and know who to call at eight in the evening on a Sunday. The website backups page explains what a usable backup looks like.
From roughly mid-December, stop making changes. No plugin updates, no redesigns, no new landing pages built in a hurry. Almost every December outage we have seen started with a well-meant edit made during the busiest week.
Six steps, one afternoon, once a year. It is the highest-return hour of work available to a small organisation with a website.
Two audiences read your site differently from everyone else. A grantmaker doing due diligence, and a careful donor deciding whether you are real. Both go looking for the same handful of documents, and both draw a conclusion from how hard they are to find.
Make it easy. A single page, linked from the footer, holding your annual report, your audited financials or equivalent, your public filings, your board list and your leadership. Put the year on each document in the link text so nobody has to open a file to find out it is four years old.
Hosting-wise this asks for almost nothing beyond somewhere to put files and a way for a staff member to update them without calling a developer. That last part matters more than it sounds. Documents go stale because updating them is somebody else's job, and the site quietly starts telling people you last reported in 2023.
Rules about what a charity must publish and how vary by where you are registered and what kind of organisation you are. Treat this page as a description of what supporters look for, not as a compliance checklist, and check your own obligations with your accountant or counsel.
We will run the whole routine on your nonprofit site: the routes in, the certificate, the domain renewal, a backup you can restore from, and the form notifications that stopped reaching anybody.
The other thing a nonprofit site does all year is collect people. Volunteer signups, event registrations, mailing list subscriptions, contact from someone who needs your help. These are quieter than donations and they are where most sites leak.
The leak is almost always the same one. A form submission is emailed to a single address, that address is a personal account belonging to whoever set the site up, and when they leave, the emails go into a mailbox nobody opens. Weeks of volunteer signups vanish and nobody notices because nothing looks broken.
The fix is to send form notifications to an address on your own domain that more than one person can read, and to keep a record on the site itself rather than relying only on email. If you are still running the organisation from personal addresses, the business email page covers what changing that involves, and moving existing mail across is on the email migration page.
Event registration is worth one specific warning. If you run one large event a year and you sell tickets through your own site, that is the one day when traffic genuinely spikes, because everyone hears about it at once. If you use an external ticketing platform, the spike happens on their servers and not yours. Either is fine. Just know which one you have chosen before the day.
If you are an all-volunteer group that does not take money online, none of the payment infrastructure above applies to you, and you should not pay for a single piece of it.
That describes a lot of real organisations. A neighbourhood association, a small booster club, a volunteer rescue group, a church committee. You need people to find you, know what you do, see when you meet, and be able to get in touch. That is a handful of pages of text, and it is one of the lightest things anybody can put on a server.
What you probably do need is the boring part done properly: the domain in the organisation's name rather than a volunteer's, renewals on a card that is not going to expire, and one other person who knows how to get in. Read taking over a website before your current volunteer webmaster steps down, not after.
Where spending more genuinely earns its place: you take recurring gifts online, you run a members area or a client portal, you hold supporter or client records in the site, or you run a large ticketed event through your own pages. Those are real reasons. Being an important organisation with a large mission is not one. The server does not know that.
AldoMedia has built and looked after websites for Western New York organisations since 1999, and nonprofit sites with a donate button nobody has tested since last winter are familiar work. We are an independent authorised reseller rather than the operator of the underlying platform, which means we will tell you plainly when the plan you already pay for is the right one and the problem is somewhere else.
If you have inherited a site from a departed volunteer and are not sure what you are even holding, start there. Call 716-771-2536 or tell us what your site runs on, and if it needs moving, the website migration page explains the order of operations that keeps your email working through the change.
Almost never. A donate page hands the donor to a payment processor, so the heavy work happens on the processor's systems rather than your hosting. What fails in December is usually a dead link, an expired certificate, or a page loading a video before the giving form. Test the whole path with a real gift on a phone in early November and stop editing the site from mid-December.
Not if your site is set up correctly, because the card number should never reach your hosting at all. Your processor or donation platform handles it under their own obligations and sends you back a confirmation. If someone has built you a form that takes a card number into your own site or emails it, get that changed. Your own obligations depend on how you collect gifts, so confirm them with your processor and your accountant.
On one page, linked from the footer, with the year in each link so nobody opens a file to learn it is four years old. Write a plain summary in web text above each download, because search engines and screen readers read a paragraph far better than they read the inside of a PDF. Grantmakers and careful donors both go looking for that page, and how quickly they find it is part of what they are judging.
Change the notification address to one on your own domain that more than one person can read, and keep a copy of submissions on the site rather than trusting email alone. This is the most common quiet failure on nonprofit sites, because nothing looks broken while weeks of signups pile up in an unwatched mailbox. Moving your mail onto your own domain is covered on the business email page.
Yes, and it is worth fixing before December. Renewal notices go to an address nobody monitors, a card eventually expires, and the domain lapses without warning, which takes the donate page down with everything else. Get the registration into the organisation's name with a shared contact address and a renewal date you know. See taking over a website and domain expiration.
Very little. A handful of pages saying who you are, what you do, when you meet and how to reach you, on an entry shared plan. Skip the donation platform subscription until supporters ask to give online, and skip the security products priced for ecommerce risk. Spend the effort instead on owning your own domain and making sure a second person knows how to get into everything.
The plan type nearly every nonprofit site belongs on, and what the higher tiers actually change.
Read about shared hostingWhat to gather before your volunteer webmaster steps down, and how to get back in if they already have.
How to take over a siteWhat a backup you can actually restore from looks like, and how to test one before you need it.
Read about backupsEvery trade we cover is listed on hosting by industry.
Tell us what your nonprofit site runs on and we will tell you whether the plan you are paying for is the right one. If it already is, we will say so and point you at the thing that actually needs fixing.
Get Your Web Hosting Plan Get help choosing
Or call 716-771-2536 and tell us what the site has to do. If the plan you are already on is the right one, we will say so.