1. Introduction
Givvent, Inc. (“Givvent,” “we,” “us,” or “our”) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information about you when you visit our website at givvent.com and use our fundraising platform (together, the “Platform”).
This policy is part of our Terms of Service. Please read it carefully. If you disagree with its terms, please discontinue use of the Platform. Questions or concerns may be sent to privacy@givvent.com or through the privacy topic on our contact page.
2. Information We Collect
We collect information in the following ways:
- Account information. When you register you provide your name, email address, and a password, which we store only as a secure hash. Your profile may also include a username, display name, photo, cover image, bio, headline, social links, and a recovery email address if you add one, along with preferences such as theme and accessibility settings.
- Google sign-in. If you sign in with Google, we receive basic profile information (your name and email address) from Google in accordance with its privacy policy and your permissions. Google is currently the only third-party sign-in we offer.
- Campaign and donation data. We collect the content of campaigns you create (including text and images), and records of donations you make or receive: the amount, the campaign, the date, whether you chose to cover fees, whether you gave anonymously, and any dedication or message you attach. Comments, campaign updates, and direct messages you send on the Platform are also stored.
- Support tickets and chat. If you contact support, we keep the ticket (your name, email, subject, and messages) and the transcript of any conversation with our support assistant or team, including a guest email address if you write to us while signed out, and any attachments you share with the team.
- Nonprofit registration data.If you register or claim a nonprofit, we collect the organization’s details, its EIN, contact information, and any authorization documents you upload for verification.
- Usage and device information. We automatically collect limited technical data when you use the Platform, including your IP address, browser type, timestamps, and request metadata, through server logs and our security systems. We do not use third-party analytics tools.
3. How We Use Information
We use the information we collect to:
- Create and manage your account, and authenticate your identity.
- Process donations and disburse funds to campaign organizers and nonprofits.
- Send transactional communications such as email verification, donation receipts, and password reset instructions.
- Personalize your experience, including remembering your preferences and accessibility settings.
- Provide support, including AI-assisted support as described in Section 4.
- Detect, investigate, and prevent fraud, abuse, and other illegal activity.
- Comply with legal obligations and respond to lawful requests from public authorities.
- Send activity notifications and, where you have signed up for them, newsletters and product updates, each with the controls described in Section 9.
If you are in the European Economic Area or the United Kingdom, our legal bases for this processing are: performance of our contract with you (operating your account and processing your donations), our legitimate interests (keeping the Platform secure and improving it), compliance with legal obligations, and your consent where we ask for it, which you may withdraw at any time.
4. AI-Assisted Support & Content Screening
Gigi, our support assistant.Support chat on Givvent is powered by Claude, an AI model provided by Anthropic. When you chat with Gigi, your messages and the recent conversation are sent to Anthropic’s API to generate responses. If you are signed in, the conversation also includes your first name and whether you organize campaigns, and when you ask about your own account, the information Gigi looks up for you (such as your donation history, your campaigns, your receipts, or your notification and settings status) is processed the same way to compose the answer. Gigi can read your account data but cannot change it.
Content screening.Free-text content you submit to the Platform, such as campaign text, comments, and messages, may be screened by an automated classifier running on Anthropic’s API to detect content that violates our Terms.
Anthropic acts as our service provider: it processes this data to provide these features and, under its commercial API terms, does not use it to train its models. Conversations can always be handed off to a human on our team, and images you attach in a support chat go to our support staff, not to the AI model.
5. Sharing & Service Providers
We do not sell your personal information. We share data only in the following circumstances:
- Service providers. We share data with third-party vendors who perform services on our behalf: Stripe (payments and payouts via Stripe Connect), Supabase (database and file storage), Vercel (hosting and content delivery), Resend (email delivery), Upstash (rate limiting), Cloudflare Turnstile (bot protection on sign-up and public support forms), Anthropic (AI support and content screening, see Section 4), and Pledge, operating with Pledgeling Foundation (recording, receipting, and disbursing donations to verified nonprofits; Pledge receives your name, email address, and gift amount so your tax receipt can be issued). These providers process data to provide their services to us and are not permitted to use it for their own purposes.
- Campaign organizers. When you donate to a personal campaign, the organizer sees your name and any message you attach, but not your email address. Teams of verified nonprofits may see supporter contact emails in their exports. If you donate anonymously, your identity is hidden from organizers and their exports in both cases.
- Legal compliance. We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Givvent, our users, or the public.
- Business transfers. In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred as part of that transaction. We will notify you via email and a prominent notice on the Platform before your data becomes subject to a different privacy policy.
6. Payment Information
Givvent uses Stripe to process all payments. When you make a donation or save a payment method, your card details are transmitted directly to Stripe and are governed by Stripe’s Privacy Policy. Givvent does not store full payment card numbers on its own servers. We retain only a tokenized reference, the card brand, the last four digits, and the expiry date to display saved payment methods in your account settings. We also keep a record of each donation (amount, campaign, date, fee coverage, and whether you chose to give anonymously) to issue receipts and operate the Platform.
Guest donations. If you donate without an account, we keep the name and email address you provide with the donation record so we can send your receipt. If you later create an account with the same email address, your past donations are linked to that account.
For organizers (payouts via Stripe Connect).To receive funds, organizers connect a Stripe account and complete Stripe’s onboarding. Stripe collects the information it needs to verify identity and enable payouts, which may include legal name, date of birth, address, and bank details, directly from the organizer; that information is held by Stripe under its own privacy policy, not by Givvent. We store only the resulting Stripe account identifier and its payout-eligibility status.
7. Cookies & Similar Technologies
We use a small set of cookies and browser storage, all in service of running the Platform:
- Strictly necessary. A session cookie keeps you signed in, and related cookies protect against request forgery. These are required for core functionality and cannot be disabled while using your account.
- Preferences. We use browser storage on your device to remember settings such as your theme and dismissed prompts.
- Bot protection. Cloudflare Turnstile may set cookies or similar state on pages where it runs, to distinguish people from bots.
We do not use third-party analytics cookies, advertising cookies, or cross-site trackers. You can control cookies through your browser settings; disabling the strictly necessary ones will prevent signing in.
8. Data Retention & Deletion
We retain your personal data for as long as your account is active. You may delete your account at any time from your account settings (see how account deletion works). When you do, your account is deactivated immediately and you have a 10 day grace period during which you can restore it by signing back in.
After the grace period, deletion is permanent and complete on Givvent’s side: your profile, your campaigns, your donation records and receipts held by Givvent, your saved payment references, your support tickets, and your notifications are all deleted. Conversations you had with our support chat are disconnected from the deleted account; the text of messages you sent may persist in our support system without a link to you.
Records held by our payment and donation processors, including Stripe and Pledgeling Foundation, continue to exist under their own retention policies, as financial regulations require of them. Aggregated statistics that no longer identify you may be retained.
9. Your Rights & Choices
You can view and correct most of your information directly in your account settings, and you can delete your account as described in Section 8. Depending on your location, you may also have the right to request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, a portable copy of your data, and to object to processing based on legitimate interests. California residents have the right to know what personal information we collect, to request deletion, and to opt out of any sale of personal information; we do not sell personal information.
Your communication choices:
- Transactional email such as receipts, security alerts, and account notices is always sent; it is how the Platform works.
- Activity notifications (campaign updates, milestones, replies, and similar) are controlled per type in your notification preferences, where you can choose instant email, in-app only, or a weekly digest. Every notification email also carries a link to turn off just that type.
- Newsletters and announcements include a one-click unsubscribe link in every message. See managing emails from Givvent.
To exercise any of these rights, contact us at privacy@givvent.com. We respond as promptly as we can, and within any timeframe the law requires. You may also lodge a complaint with your local data protection authority.
10. Security
We implement technical and organizational measures to protect your personal information against accidental loss, unauthorized access, disclosure, alteration, and destruction. These include TLS encryption in transit, bcrypt password hashing, role-based access controls, rate limiting across sign-in, donation, and other sensitive endpoints, account lockout after repeated failed sign-in attempts, and Cloudflare Turnstile bot protection on account creation. To run these controls we process limited technical data such as your IP address and request metadata. Payment card data is handled entirely by Stripe, a PCI-DSS Level 1 certified processor.
Your account settings offer additional protections we encourage you to enable: two-factor authentication with an authenticator app, backup codes, passkeys, a recovery email address, and a view of your active sessions with the ability to sign out any of them. See setting up two-factor authentication.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affects your rights and freedoms, we will notify affected users and the relevant authorities as required by law, without undue delay. Security researchers can reach us at security@givvent.com; see the responsible disclosure note on our Safety page.
11. Children
The Platform is not directed at or intended for use by children under the age of 18, consistent with the eligibility requirement in our Terms. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@givvent.com and we will take steps to delete that information promptly.
12. International Data Transfers
Givvent is based in the United States, and your information is transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. Where the law of your country requires safeguards for such transfers, we take appropriate measures consistent with those requirements.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will notify you by email or by displaying a prominent notice on the Platform. The “Last updated” date at the top of this page indicates when the policy was most recently revised. We encourage you to review this policy periodically.
14. Contact
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our privacy team:
- Email: privacy@givvent.com
- Contact form: the privacy topic on our contact page.
If you are in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu. See also our Terms of Service.