I'm concerned that the code base is open to SQL injection.
I'm not a Python developer, but it looks to me like you're taking input from the user and putting it into queries without filtering it.
That said, my nonprofit helps other nonprofits use technology, and ALL of them want a volunteer-tracking system. This is a very useful, worthwhile project.