Privacy Policy

Givefinity Privacy Policy

Effective Date: September 14, 2026

Givefinity, Inc. (“Givefinity,” “we,” “us,” or “our”) provides a platform that helps volunteers track service, verify activities, build skills and impact records, connect with organizations, and manage service and volunteer programs. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information.

1. Scope and roles

This Policy applies to Givefinity websites, web applications, mobile applications, and related services. Depending on the context, Givefinity may act as an independent business/controller for volunteer-owned account information and as a service provider/contractor acting on behalf of a school or organization for organization-managed data.

When a school or district uses Givefinity for an institutional educational purpose, a separate Student Data Privacy Addendum or Data Privacy Agreement may apply and controls for covered student data if it conflicts with this Policy.

Volunteers may connect with multiple organizations. An organization does not automatically receive a volunteer’s complete profile or history; access depends on the relationship, applicable authorization, and product privacy controls.

2. Information we collect

Account and identity information: first name, last name, optional display name, email address, password credential data, authentication provider identifiers, role, and account status.

Age and youth-protection information: age-screening result or age category; where necessary, date-of-birth information or other evidence used to apply the correct privacy protections. Givefinity will minimize retention of exact birthdate when it is not required for a disclosed purpose or legal obligation.

Service and impact information: volunteer activities, dates, hours, organizations, locations, categories, reflections, goals, skills, verification evidence, impact measurements, notes, photos or attachments when enabled.

Organization information: organization identity, type, EIN where collected, administrators, invitations, groups, programs, opportunities, student/privacy agreement metadata, license quantities, billing contacts and entitlement status.

Technical and security information: IP address, device/browser information, authentication/session data, security events, audit logs, request metadata, and operational diagnostics.

Communications and support: messages sent to support, feedback, privacy requests, and service communications.

Billing information for organizations: subscription status, invoices, payment status, and processor/customer identifiers. Givefinity does not store full payment card numbers; payment processing is handled by third-party payment processors.

AI-related content: prompts or user content submitted to approved AI features and generated outputs, subject to youth/privacy restrictions and disclosed subprocessors.

3. How we use information

Provide, secure, troubleshoot, and improve the platform and requested services.

Create and maintain accounts, authenticate users, and enforce roles, privacy settings, age protections, and organization relationships.

Record, verify, summarize, and report volunteer service and impact.

Enable organizations to administer programs and view information they are authorized to access.

Operate school-authorized educational workflows and comply with applicable student-data agreements.

Provide support, service notices, security alerts, renewal/billing notices to organizations, and requested communications.

Prevent fraud, abuse, unauthorized access, and violations of our terms.

Comply with legal obligations and protect the rights and safety of users, organizations, Givefinity, and others.

4. Children, minors, and school-managed accounts

Givefinity applies age-appropriate protections. Public self-service users under 13 may not create a general account. Under-13 users may use Givefinity only through an approved school-authorized or other legally compliant pathway. At launch, Givefinity does not offer a general direct-parent-consent signup pathway for under-13 users.

School authorization is limited to the educational context and does not authorize Givefinity to use a child’s information for unrelated commercial purposes.

Google sign-in or a school-domain email does not by itself establish age, parental consent, or school authorization.

For under-13 and school-managed users, Givefinity disables public profiles and public sharing and may restrict sponsor attribution, broad discovery, direct messaging, unapproved third-party integrations, nonessential tracking, and AI uses not necessary for the approved educational purpose. For non-school users ages 13–17, accounts are private by default, and Givefinity may offer only specifically designed, age-appropriate sharing features.

Parents, guardians, schools, and eligible students may have rights to review, correct, restrict, export, or delete information depending on the applicable law and agreement.

5. How information is shared

With organizations a volunteer joins or authorizes, limited to the information the volunteer or applicable school workflow permits the organization to access.

With service providers/subprocessors that support hosting, email, authentication, payments, security, AI, storage, support, and other platform operations under contractual and security controls.

With schools or districts as required to provide institutionally authorized services and meet contractual obligations.

For legal, safety, fraud-prevention, or security reasons when reasonably necessary or legally required.

In a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and legal protections. Where required by law or applicable student-data agreements, Givefinity will provide advance notice before transferring personal information to a successor entity.

Givefinity does not sell student data or use school-authorized student information for targeted advertising.

6. Public profiles and sharing

Certain adult users may choose to make limited information public or create sharing links. Public visibility is optional and subject to privacy settings, age restrictions, and organization/school policies. Givefinity does not expose a user’s full legal identity publicly by default. Under-13 and school-managed users have public profiles and public sharing disabled. Non-school users ages 13–17 are private by default and may use only specifically designed, age-appropriate sharing features that Givefinity makes available.

7. AI and automated features

Givefinity may provide AI-assisted summaries, reflections, recommendations, or other features. AI features must follow Givefinity’s privacy and minor-capability policies. Student content will not be used to train general-purpose AI models. Givefinity will contractually require that its AI subprocessors do not use student content for model training.

8. Data retention and deletion

Givefinity retains personal information only as long as reasonably necessary for the purpose for which it was collected, to provide the service, comply with school/customer instructions, preserve legitimate audit/security records, meet legal obligations, and resolve disputes. Student-data agreements may impose shorter or specific deletion timelines. Backups may retain encrypted copies for a limited documented period before automatic expiration.

Account deactivation, organization disconnection, and data deletion are different actions and may have different effects.

Volunteer-owned historical service records will not be deleted merely because an organization subscription ends, except where deletion is required by an applicable student-data agreement or law governing student or child data.

Where deletion is required, Givefinity will delete or de-identify covered data within a reasonable period, unless retention is legally required and documented.

9. Security

Givefinity uses administrative, technical, and organizational safeguards designed to protect confidentiality, integrity, and availability. These may include encryption in transit and at rest, access controls, role-based permissions, audit logging, monitoring, backups, incident response, and vendor management. In the event of a security breach involving personal information, Givefinity will provide notification to affected individuals and authorities as required by applicable law. No security measure is perfect, and Givefinity cannot guarantee absolute security.

10. Your choices and rights

Access and update account information

Control organization relationships and sharing where the product permits

Request export, correction, deletion, or restriction

Manage public visibility and sharing

Object to certain optional communications

Use available parent/school rights for student data

Requests may be submitted through the platform or to compliance@givefinity.com. Givefinity may verify identity and authority before acting on a request. Requests involving school-controlled Student Data may be coordinated with the school where appropriate.

11. Service providers and international transfers

Givefinity’s current production design is U.S.-hosted. If personal information is transferred internationally, Givefinity will use legally appropriate safeguards.

12. Changes to this Policy

Givefinity may update this Policy. Givefinity will provide reasonable advance notice of material changes where appropriate or required by law, including through the platform, email, or other reasonable means. A shorter notice period may apply where required by law, security, or urgent compliance needs. Versioned acceptance may be required where legally or contractually necessary.

13. Contact

Givefinity, Inc.
3434 Kildaire Farm Rd., Suite 135 PMB 542, Cary, NC 27518
compliance@givefinity.com

‪(919) 335-6816‬