1. Introduction
Welcome to GivingHeartCo ("we," "our," or "us"). We are committed to protecting your privacy and handling your personal information with transparency and care. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://givingheartco.com (the "Site"), make donations, sign up for newsletters, volunteer, or interact with our services.
By using our Site or providing us with your personal information, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our Site or services.
2. Information We Collect
We collect several types of information to provide and improve our services to you:
2.1 Personal Information You Provide
When you interact with our Site, we may ask you to provide personal information including but not limited to:
- Contact Information: Name, email address, mailing address, phone number
- Donation Information: Payment method details, donation amount, recurring donation preferences, and donor history
- Communication Preferences: Your preferences for receiving communications from us
- Volunteer Information: Skills, availability, areas of interest, emergency contact information
- Employment Information: Resume, work history, qualifications (if you apply for a position)
2.2 Financial Information
When you make a donation, we collect payment information such as credit/debit card numbers, billing addresses, and other financial data. All payment transactions are encrypted and processed through secure, PCI-compliant payment processors. We do not store complete credit card information on our servers.
2.3 Technical Data Automatically Collected
When you visit our Site, we automatically collect certain information about your device and browsing activity, including:
- Device Information: IP address, browser type and version, operating system, device type
- Usage Data: Pages visited, time and date of visit, time spent on pages, clickstream data, referring URLs
- Location Information: General geographic location based on IP address
3. How We Use Information
We use the information we collect for legitimate nonprofit purposes, including:
- Process Donations: To process and acknowledge your donations, issue tax receipts, and maintain accurate donor records
- Communicate With You: To send newsletters, updates about our programs, fundraising campaigns, event invitations, and respond to your inquiries
- Improve Our Services: To analyze website usage, enhance user experience, and optimize our fundraising strategies
- Legal Compliance: To comply with applicable laws, regulations, and reporting requirements (including IRS regulations for nonprofits)
- Fraud Prevention: To detect, prevent, and investigate fraudulent transactions or unauthorized activities
- Volunteer Coordination: To manage volunteer applications, schedules, and communications
- Program Reporting: To measure the impact of our programs and report to grantors and stakeholders (using anonymized data)
4. Donor Privacy Commitment
At GivingHeartCo, we deeply value our donors and are committed to protecting donor privacy. Our pledge to you:
- No Selling or Sharing: We will never sell, trade, or share your personal information with third parties for their own marketing or fundraising purposes.
- Limited Use: Donor information is used only for internal purposes, including processing donations, issuing tax receipts, sending updates about our work, and complying with legal requirements.
- Honoring Preferences: We respect your communication preferences. You may opt out of emails or request to be removed from mailing lists at any time.
- Public Recognition: We will not publicly acknowledge your donation without your explicit consent.
- Confidentiality: Donor records are treated as confidential and accessible only to authorized personnel with a legitimate need to access them.
If you have questions about how we handle donor information, please contact us at givingheartco4@gmail.com.
5. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our Site. Cookies are small text files stored on your device that help us remember your preferences and understand how you interact with our Site.
5.1 Types of Cookies We Use
- Essential Cookies: Required for basic Site functionality (e.g., donation form processing)
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how visitors use our Site (see Section 5.2)
- Marketing Cookies: Used to deliver relevant advertisements to you (you can opt out)
5.2 Google Analytics
We use Google Analytics to collect information about how visitors use our Site. Google Analytics uses cookies to generate reports on website traffic, user behavior, and demographics. The information collected (including your IP address) is transmitted to and stored by Google on servers in the United States.
You can learn more about Google Analytics data practices at Google Privacy Policy. To opt out of Google Analytics, you can install the Google Analytics Opt-out Browser Add-on.
5.3 Managing Cookies
Most browsers allow you to control cookies through their settings preferences. You can set your browser to refuse cookies or alert you when cookies are being sent. However, please note that disabling cookies may affect the functionality of certain parts of our Site, including donation processing.
6. How We Share Information
We do not sell your personal information. However, we may share your information in the following limited circumstances:
- Service Providers: We share information with trusted third-party vendors who help us operate our Site, process donations, send emails, and manage donor databases. These providers are contractually obligated to protect your information and use it only for the services they provide to us.
- Payment Processors: We use secure, PCI-compliant payment processors (e.g., Stripe, PayPal, Authorize.net) to handle donation transactions. Your financial information is shared directly with these processors and is not stored on our servers.
- Legal Obligations: We may disclose information if required by law, subpoena, court order, or government regulation (e.g., IRS audit).
- Protection of Rights: We may share information to protect our rights, property, safety, or the rights of others.
- Corporate Changes: In the event of a merger, acquisition, or reorganization, your information may be transferred as part of the transaction (with continued protection).
- With Your Consent: We may share information for other purposes with your explicit consent.
7. Data Security Measures
We take data security seriously and implement industry-standard measures to protect your information:
- Encryption: We use SSL/TLS encryption to protect data transmitted between your browser and our servers. Donation transactions are encrypted using 256-bit encryption.
- Access Controls: Access to personal information is restricted to authorized employees, volunteers, and contractors who need it to perform their job duties.
- Secure Storage: Personal information is stored on secure servers with firewall protection and regular security monitoring.
- PCI Compliance: Our payment processing systems are PCI DSS (Payment Card Industry Data Security Standard) compliant.
- Regular Audits: We conduct regular security assessments and vulnerability scans.
- Employee Training: Our staff receives training on data protection and privacy practices.
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law (e.g., IRS requires donor records to be kept for 7 years).
- Donor Records: Retained for 7 years to comply with tax regulations and audit requirements
- Email Subscriptions: Retained until you unsubscribe or request deletion
- Volunteer Applications: Retained for 2 years after last contact
- Website Analytics: Anonymized data retained for 26 months (Google Analytics default)
When information is no longer needed, we securely delete or anonymize it.
9. Your Rights
Depending on your location, you may have certain rights regarding your personal information:
9.1 CCPA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
- Delete: Request deletion of your personal information (subject to exceptions)
- Opt-Out: Opt out of the sale of your personal information (we do not sell your information)
- Non-Discrimination: Exercise your rights without receiving discriminatory treatment
9.2 GDPR Rights (European Residents)
Under the General Data Protection Regulation (GDPR), individuals in the European Economic Area (EEA) have the right to:
- Access: Request access to your personal data
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Receive your data in a structured, commonly used format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw previously given consent at any time
9.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at givingheartco4@gmail.com with the subject line "Privacy Request." We will respond within 30 days (or as required by law). We may need to verify your identity before processing your request.
10. Data Breach Response
In the event of a data breach that compromises your personal information:
- Internal Response: We will immediately activate our incident response plan, contain the breach, and investigate the cause.
- Notification: We will notify affected individuals, regulatory authorities, and other required parties as mandated by applicable laws (generally within 72 hours for GDPR, without unreasonable delay for CCPA).
- Remediation: We will take steps to remediate the vulnerability and prevent future breaches.
- Transparency: We will provide clear information about the breach, what data was affected, and steps you can take to protect yourself.
If you believe your information has been compromised, please contact us immediately at givingheartco4@gmail.com.
11. Children's Privacy
Protecting children's privacy is especially important to us. Our Site and services are not directed to children under the age of 13 (or under 16 for GDPR/EEA residents). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we discover we have collected personal information from a child without verification of parental consent, we will delete that information promptly.
For children under 13 (COPPA compliance), we require verifiable parental consent before collecting any personal information.
12. Third-Party Links
Our Site may contain links to third-party websites (e.g., social media platforms, partner organizations, payment processors). We are not responsible for the privacy practices or content of these external sites. We encourage you to read the privacy policies of any third-party websites you visit.
For your reference, here are links to privacy policies of some third-party services we may use:
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Post the revised policy on this page
- Notify users of material changes via email (if we have your email address) or through a prominent notice on our Site
- Obtain your consent for significant changes where required by law
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.