This Privacy Policy describes how Givable LLC (“Givable,” “we,” “us,” or “our”) collects, uses, stores, and protects information in connection with the use of our fundraising platform, websites, and related services (collectively, the “Services”). This Policy applies to nonprofit organizations, their staff and administrators, donors and supporters, and visitors who interact with the Services.
1. Roles Under Data Protection Laws
For purposes of applicable data protection laws, nonprofit organizations using Givable are the “data controllers” (or “businesses” under California law) responsible for determining the purposes and means of processing supporter data. Givable acts as a “data processor” (or “service provider”), processing personal data on behalf of organizations. Donors and supporters who wish to exercise their rights may do so through the organization they supported, though Givable will assist organizations in fulfilling such requests.
Where Givable collects information directly for its own purposes — for example, from visitors to our websites or from the staff of organizations that hold a Givable account — Givable acts as a controller for that information.
2. Information We Collect
We may collect the following categories of personal data:
- Donors and supporters: name, email address, phone number, mailing address, payment details, donation and giving history, recurring giving schedules, event registrations and ticket purchases, peer-to-peer fundraising activity, communication preferences, profile photos, supporter portal login credentials, and responses to custom questions created by organizations.
- Organization administrators and staff: name, email, phone number, login credentials (encrypted and stored using secure industry-standard algorithms), role and permission assignments, account activity logs, and login history.
- Content and media: images, video, documents, and written updates uploaded by organizations or their supporters — including media published through Stories and peer-to-peer fundraising pages — together with any personal data contained in that content.
- Technical information: IP addresses, approximate location derived from IP address, time and date of access, device and browser information, and cookies or similar technologies used to keep you signed in, remember preferences, secure the Services, and understand aggregate usage.
3. How We Use Information
We use personal data only as necessary to provide, secure, and improve the Services. This includes:
- Processing donations and delivering fundraising tools, including recurring giving, events, and peer-to-peer campaigns.
- Sending receipts, confirmations, and communications on behalf of organizations.
- Providing donors and supporters with access to giving history, recurring schedules, and account preferences.
- Authenticating users, including two-factor authentication, and supporting fraud prevention and security monitoring.
- Improving platform performance and features, using anonymized and aggregated data.
- Sending service, security, and product communications to organization administrators, with the ability to opt out of non-essential messages.
4. Communications
We send transactional messages (receipts, confirmations, security and account notices) that are necessary to provide the Services, and, where you have opted in, product and marketing updates. You may opt out of marketing email at any time using the unsubscribe link in the message. Transactional and security messages cannot be opted out of while your account is active.
Text messaging (SMS)
Messages we send you. We use SMS for security and account messages — most importantly one-time passcodes for two-factor authentication, and account or security alerts. You provide your mobile number when you enable two-factor authentication or add it to your profile, and doing so is your consent to receive these messages. Message frequency varies with your account activity. Message and data rates may apply. Reply STOP to opt out at any time, or HELP for help. Opting out will disable SMS-based two-factor authentication on your account.
We do not share your mobile information. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. This includes your mobile phone number and your opt-in or consent to receive text messages, which will not be shared, sold, rented, or otherwise provided to any third party, affiliate, or lead generator. Mobile numbers are disclosed only to the telecommunications providers strictly necessary to deliver messages you have requested, and those providers may not use that information for their own marketing.
Messages organizations send to their supporters. Organizations using Givable may send their own text messages to supporters through the platform. Those organizations are responsible for obtaining the required consent and for complying with applicable messaging laws; Givable processes those messages on the organization’s behalf.
5. Sharing Information with Third Parties
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
We share data only with service providers who assist in delivering the Services, and only to the extent necessary to do so. These providers fall into categories such as payment processing, email and text message delivery, hosting and infrastructure, security and fraud prevention, analytics, and customer support. All providers are contractually obligated to protect the confidentiality and security of the data and may not use it for their own purposes.
Bot and spam protection. Our public websites use Cloudflare Turnstile, a bot-detection service from Cloudflare, Inc., to protect our forms from spam and automated abuse. Turnstile runs invisibly in the background and processes limited technical information — such as your IP address and browser and device signals — to distinguish real visitors from bots. According to Cloudflare, Turnstile does not use this information for advertising and does not use cookies to collect or store information. Cloudflare processes this data as our service provider; for details, see Cloudflare’s Turnstile Privacy Addendum.
The categories above exclude text messaging originator opt-in data and consent; this information is not shared with any third parties.
We may also disclose information where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will provide notice before personal data becomes subject to a different privacy policy.
6. Integrations You Enable
Organizations may connect Givable to other systems they use, such as CRM, accounting, marketing, or analytics platforms. When an organization enables an integration, data flows between Givable and that system at the organization’s direction and configuration. Once data reaches a connected system, it is governed by that provider’s terms and privacy policy, and the organization is responsible for its use there. Organizations may disconnect an integration at any time.
7. Content and Media
Organizations and their supporters may upload images, video, and written updates — for example, through Stories or peer-to-peer fundraising pages. Organizations control whether that content is published and who can see it, and are responsible for obtaining any releases or permissions required from people appearing in it, including where a media release is collected through the Services.
We store and process this content to provide the Services. We do not share, sell, or license uploaded media to third parties, and we do not use it for advertising.
8. Givable AI
Givable AI lets authorized users ask questions about their organization’s data and generate reports. It respects each user’s existing roles and permissions, so it can only work with data that user is already allowed to see.
Before data is sent to the AI provider that powers these features, we remove personal identifiers such as names, email addresses, phone numbers, and postal addresses. Your personal data is not used to train AI models. Organizations can control which team members may use AI features and set usage limits.
9. Data Retention
We retain personal data for as long as an organization’s account is active and as necessary to provide the Services. Upon account closure, Givable may retain personal and transaction data for as long as necessary to comply with legal, regulatory, and tax obligations — generally up to seven years for financial and receipting records. Organizations may request deletion of supporter personal data, subject to applicable law and to those retention obligations. Anonymized and aggregated data may be retained indefinitely for analytics and product improvement.
10. International Data Transfers
Givable operates in the United States. If you are located outside of the United States or Canada and interact with the Services, your data may be transferred to and processed in the United States. Where required, we implement safeguards such as Standard Contractual Clauses to ensure appropriate protection for cross-border transfers.
11. Security
We take reasonable and appropriate measures to protect personal data from unauthorized access, use, or disclosure. This includes encryption of data at rest and in transit (AES-256, TLS), secure password hashing, role-based access controls, and continuous monitoring of our systems.
Card payments are processed by a PCI-DSS Level 1 certified payment processor. Full card numbers are never stored on Givable’s systems.
Givable is built to SOC 2 standards and our SOC 2 audit is in progress; we are also working toward ISO 27001 as our security program matures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your Rights
Depending on your location, you may have rights under the GDPR, California law (CCPA/CPRA), Canadian privacy law including PIPEDA, or other applicable laws, including:
- Right to access, correct, or update your personal information.
- Right to request deletion of your personal information.
- Right to restrict or object to the processing of your data.
- Right to data portability.
- Right to opt out of marketing communications.
- Right to know what categories of personal information we collect and how they are used.
Because Givable does not sell personal information or share it for cross-context behavioral advertising, there is no such activity to opt out of. We honor recognized opt-out preference signals, including Global Privacy Control, where required.
Donors and supporters should direct requests to the organization they supported, and Givable will support organizations in fulfilling those requests. You may also contact Givable directly at privacy@givable.com. We will not discriminate against you for exercising any of these rights.
13. Children’s Privacy
The Services are not intended for children under 13 years of age, and we do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13 without appropriate consent, we will delete it promptly.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on our website with an updated effective date. We encourage you to review this Policy periodically to stay informed about how we protect your information.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at privacy@givable.com.