This Privacy Policy explains how DonorCharm collects, uses, discloses, and otherwise processes personal information through its websites, fundraising and engagement platform, administrative tools, donor-facing experiences, communications, and related services.
Scope and Roles
This Privacy Policy explains how DonorCharm collects, uses, discloses, and otherwise processes personal information through its websites, fundraising and engagement platform, administrative tools, donor-facing experiences, communications, and related services (the “Services”).
Organizations use DonorCharm to create and administer campaigns. Depending on the context, an organization may determine why and how donor or participant information is processed, while DonorCharm processes that information to provide the Services.
An organization’s own privacy notice may also apply to its campaign activities.
Information We Process
The information processed depends on the campaign, features, and interactions involved. It may include:
- Identity and contact information, such as name, telephone number, email address, postal address, organization, and affiliation information.
- Fundraising and transaction information, such as donation or purchase amount, campaign participation, recurring-pledge information, payment status, fees, refunds, and provider transaction identifiers.
- Campaign and event information, such as bids, raffle entries, votes, product selections, enrollment information, responses to campaign questions, tags, and fulfillment or shipping details.
- Communications information, such as SMS or email content, sender and recipient information, delivery details, timestamps, and opt-in or opt-out preferences.
- Content submitted through the Services, which may include dedication messages, images, or other files when a campaign enables those features.
- Account and administrative information, such as account profile details, roles, permissions, settings, and support communications.
- Technical and operational information, such as session information, IP address, browser or device information, logs, and information used to operate, troubleshoot, and protect the Services.
Sources of Information
DonorCharm may receive information directly from donors, participants, administrators, and other users; from customer organizations administering campaigns; automatically through use of the Services; and from payment, communications, hosting, and other service providers or integrations.
How We Use Information
DonorCharm may use personal information to:
- Provide, configure, maintain, support, and improve the Services.
- Process and record donations, purchases, pledges, campaign participation, and related fulfillment activity.
- Facilitate authorized SMS, email, and other campaign communications, including consent and opt-out handling.
- Authenticate users, administer accounts, and apply roles and permissions.
- Respond to support, security, privacy, and legal requests.
- Detect, investigate, and address misuse, fraud, operational failures, and security concerns.
- Maintain business, transaction, compliance, and audit records and enforce applicable agreements.
Payments
DonorCharm uses Stripe in connection with payment processing. Payment-card information is submitted to and processed by Stripe under Stripe’s terms and privacy practices.
DonorCharm’s application is designed to retain transaction information needed for platform workflows, such as payment-provider identifiers, payment status, amount, card brand, and the last four digits of a card.
DonorCharm does not intentionally store full payment-card numbers or card security codes in its application database.
SMS and Email Communications
DonorCharm uses communications providers, including Twilio for SMS and SendGrid for email.
Telephone numbers, email addresses, message content, delivery details, and communication preferences may be processed to provide these functions.
Recipients may use available opt-out methods, including recognized SMS opt-out keywords where supported.
Customer organizations are responsible for obtaining authority required for communications they initiate through their campaigns.
How We Disclose Information
DonorCharm may disclose personal information:
- To the customer organization responsible for the relevant campaign or account.
- To service providers and integrations that support payments, communications, hosting, storage, support, security, and other service operations.
- When required by law, legal process, or a valid governmental request.
- When reasonably necessary to protect rights, safety, security, or the integrity of the Services, or to investigate fraud or abuse.
- In connection with a merger, financing, acquisition, reorganization, or transfer of business assets, subject to applicable law and appropriate safeguards.
- With a person’s direction or consent.
DonorCharm will provide legally required notices or choices concerning particular disclosure practices when applicable.
Service Providers
Services identified in the current platform include Stripe for payments, Twilio for SMS, SendGrid for email, and hosting or infrastructure providers.
Stripe
Supports payment-processing functionality used by the DonorCharm platform.
Twilio
Supports SMS communications and related messaging workflows.
SendGrid
Supports email communications and related delivery workflows.
Additional providers may support storage, monitoring, support, backups, or other operations. These providers process information subject to their applicable agreements and privacy practices.
Data Retention
DonorCharm retains information for as long as reasonably necessary to provide the Services, support customer and donor transactions, maintain appropriate business and audit records, comply with legal obligations, resolve disputes, and enforce agreements.
Retention may vary by record type, customer instructions, legal requirements, and technical or operational needs.
Information may be retained in backups or archived records for a limited period after deletion from active systems.
Security
DonorCharm uses administrative, technical, and organizational measures intended to reduce the risk of unauthorized access, loss, misuse, or alteration.
Security measures are reviewed as the Services and technology evolve.
No system, transmission method, or storage method can be guaranteed to be completely secure.
Privacy Choices and Requests
Depending on applicable law and DonorCharm’s relationship with the individual, a person may be able to request access, correction, deletion, or other action concerning personal information.
Requests may be submitted to hello@donorcharm.org.
DonorCharm may verify identity and may direct a request to the customer organization responsible for the relevant campaign when that organization controls the information or the requested decision.
Certain information may be retained or a request may be limited where permitted or required by law, including for transaction records, fraud prevention, legal claims, security, or other legitimate purposes.
Submit a privacy request
Contact DonorCharm regarding access, correction, deletion, or other privacy-related requests.
Contact DonorCharm →Security questions
Review DonorCharm’s current technology, privacy, and security posture.
Trust Center →Cookies and Similar Technologies
DonorCharm uses cookies, sessions, and similar technologies that support sign-in, security, preferences, and operation of the Services.
Browsers may provide controls for cookies, although disabling necessary technologies may affect functionality.
Third-party services used through the platform may apply their own technologies and privacy practices.
Children’s Privacy
The Services are intended for use by organizations and adults administering or participating in fundraising and engagement activities, and are not directed to children under 13.
Customer organizations should not use the Services to collect personal information directly from a child under 13 unless they have determined that the activity is lawful and have coordinated appropriate requirements with DonorCharm.
If you believe information from a child under 13 has been provided improperly, contact hello@donorcharm.org.
Regional Privacy Disclosures
Privacy rights and required disclosures differ by jurisdiction and may depend on DonorCharm’s role, the customer organization’s role, and applicable thresholds or exemptions.
DonorCharm will respond to valid requests and provide additional notices or mechanisms where required by applicable law.
Individuals may contact DonorCharm to ask whether a particular right or disclosure applies to their information.
International Processing
DonorCharm and its service providers may process information in the United States and other locations where they operate.
Privacy and data-protection laws may differ between jurisdictions.
Where required, DonorCharm will use appropriate measures for applicable international transfers.
Changes to This Policy
DonorCharm may update this Privacy Policy to reflect changes in the Services, legal requirements, or information practices.
The current version will identify its effective date, and DonorCharm will provide additional notice of material changes where required.
Contact DonorCharm
Donor Charm, LLC
522 West San Francisco Avenue
El Paso, TX 79901