Privacy Policy
Givelayer Technologies Inc. is committed to protecting the privacy of donors, charities, and visitors to our platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Givelayer Service.
Table of Contents
- 1.Our Privacy Principles
- 2.Roles and Responsibilities
- 3.Information We Collect
- 4.How We Use Information
- 5.How We Share Information
- 6.International Data Transfers
- 7.Data Retention
- 8.Cookies and Tracking Technologies
- 9.Your Privacy Rights
- 10.Security
- 11.Children's Privacy
- 12.Third-Party Links
- 13.Changes to This Policy
- 14.Contact Us
Our Privacy Principles
Givelayer is built on five privacy commitments:
- 1.Minimal collection. We collect only the data necessary to provide the Service.
- 2.No data sales. We never sell donor or charity information to third parties.
- 3.Charity ownership. Donor data belongs to the receiving charity, not to Givelayer.
- 4.Transparency. We tell you what we collect, why, and who has access.
- 5.Control. Donors can request access, correction, or deletion of their data at any time.
Roles and Responsibilities
2.1 Givelayer as Data Processor
When charities use our Service to collect donations, Givelayer acts as a data processor on behalf of the charity (the data controller). This means:
- •The receiving charity determines how donor data is used and retained;
- •Givelayer processes donor data only as instructed by the charity and as required to provide the Service;
- •Donors should contact the receiving charity for questions about how their data is used by that charity.
2.2 Givelayer as Data Controller
When Givelayer collects information directly from website visitors, charity administrators, or job applicants, Givelayer acts as a data controller for that information.
Information We Collect
3.1 Information from Donors
When a donor contributes through the Service, we collect:
- •Identity information: Full name (required for tax receipts in the United States)
- •Contact information: Email address (required for digital receipts and communication)
- •Mailing address: Required for charitable receipts under IRS Publication 1771
- •Donation details: Amount, date, currency, recipient charity, optional tip amount
- •Payment information: Processed directly by Stripe; Givelayer does not receive or store credit card numbers, CVV codes, or full bank account details
- •Communications: Messages, refund requests, or inquiries sent to support@givelayer.com or to the receiving charity through the Service
- •Optional information: Donor-provided messages, dedications, or anonymity preferences
3.2 Information from Charities
When a charity registers for the Service, we collect:
- •Charity identification: Legal name, operating name, registration number (IRS EIN), incorporation date, registered office address
- •Authorized representative information: Name, email, phone, role, government-issued identification (collected by Stripe for KYC)
- •Banking information: Collected and stored by Stripe; Givelayer does not store full bank account numbers
- •Account activity: Login times, IP addresses, dashboard usage, campaigns created, content uploaded
- •Communications: Messages sent to Givelayer support or privacy teams
3.3 Information from Website Visitors
When you visit givelayer.com or gvy.to without making a donation or creating an account, we may collect:
- •Technical information: IP address, browser type, device type, operating system, referring URL, pages visited, time on site
- •Cookies and similar technologies: See Section 8 (Cookies and Tracking)
- •Form submissions: Name and email if you join our waitlist or contact us
3.4 Information We Do Not Collect
Givelayer does not collect:
- •Credit card numbers, CVV codes, or full bank account numbers (these are handled by Stripe)
- •Social Security Numbers (US) from donors
- •Health information, biometric information, or other special categories of personal data unless voluntarily provided
- •Information from children under 18; the Service is not directed at minors
How We Use Information
4.1 To Provide the Service
We use information to:
- •Process donations and route funds to charities through Stripe Connect
- •Generate receipts on behalf of charities (charity is the legal issuer)
- •Send transactional emails (donation confirmations, receipts, refund notifications) via Resend
- •Display donation history to donors and charity administrators
- •Power the analytics dashboard for charity insights
- •Enable thank-you video features and donor communications
- •Generate QR codes, embed buttons, and flyers for charity campaigns
4.2 To Operate Our Business
We use information to:
- •Verify charity registration through IRS databases
- •Verify identity and beneficial ownership through Stripe KYC
- •Detect and prevent fraud, money laundering, and abuse
- •Comply with legal obligations including FINTRAC (Canada) and FinCEN (US) reporting
- •Respond to support inquiries and resolve disputes
- •Improve the Service through aggregated analytics
- •Communicate platform updates, policy changes, and account notifications
4.3 To Communicate
We use contact information to send:
- •Transactional emails: Required for the Service (receipts, payment confirmations, account changes)
- •Service announcements: Important updates affecting your account or the Service
- •Marketing communications: Only with your consent and only when legally permitted
You can opt out of marketing communications at any time using the unsubscribe link in any marketing email or by contacting privacy@givelayer.com.
4.4 Legal Basis for Processing (GDPR and PIPEDA)
We process personal information based on:
- •Contract performance: To provide the Service to charities and donors
- •Legal obligation: To comply with tax, AML, and other regulatory requirements
- •Legitimate interest: To improve the Service, prevent fraud, and operate our business
- •Consent: For marketing communications and optional features
International Data Transfers
Givelayer's service providers may process data in Canada, the United States, the European Union, and other jurisdictions. By using the Service, you consent to such cross-border processing.
For Canadian users, we comply with PIPEDA's accountability requirements when transferring data outside Canada. For users in the European Economic Area, we rely on Standard Contractual Clauses or equivalent safeguards for transfers outside the EEA.
Data Retention
7.1 Donation Records
Donation records (including donor name, address, amount, date, and receipt details) are retained for a minimum of 7 years following the donation date to comply with:
- •IRS record-keeping requirements
- •Internal Revenue Service (IRS) record-keeping requirements
- •Other applicable tax and regulatory frameworks
7.2 Account Closure
If a charity closes its Givelayer account, donor records associated with that charity are retained for 7 years post-account-closure in compliance with regulatory requirements, then permanently deleted.
7.3 Marketing and Analytics Data
Marketing communication preferences and aggregated analytics data are retained until you opt out or request deletion, whichever is sooner, subject to legitimate business needs.
7.4 Other Data
Other personal information is retained only as long as necessary for the purposes described in this Policy or as required by law.
Your Privacy Rights
9.1 Rights Under PIPEDA (Canada)
Canadian users have the right to:
- •Access their personal information
- •Correct inaccurate or incomplete information
- •Withdraw consent (subject to legal and contractual restrictions)
- •File a complaint with the Office of the Privacy Commissioner of Canada
9.2 Rights Under State Privacy Laws (United States)
Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have the right to:
- •Know what personal information is collected and how it is used
- •Access copies of their personal information
- •Request deletion of personal information (subject to legal exceptions)
- •Opt out of the sale or sharing of personal information (Givelayer does not sell personal information)
- •Opt out of targeted advertising (Givelayer does not engage in targeted advertising)
- •Non-discrimination for exercising privacy rights
9.3 Rights Under GDPR (European Economic Area, UK)
Users in the EEA and UK have the right to:
- •Access, rectify, or erase personal data
- •Restrict or object to processing
- •Data portability
- •Withdraw consent
- •Lodge a complaint with a supervisory authority
9.4 How to Exercise Your Rights
To exercise privacy rights, contact:
- •Receiving charity (for donor data): Use the contact information on your receipt or campaign page
- •Givelayer (for visitor or charity admin data): Email privacy@givelayer.com
We respond to verified requests within 30 days for PIPEDA and GDPR, or as required by applicable state law (typically 45 days under US state laws, with possible extension).
We may need to verify your identity before fulfilling certain requests. Some requests may be denied or limited due to legal retention obligations (e.g., 7-year donation records under IRS rules).
Security
Givelayer implements technical and organizational safeguards to protect personal information:
- •Encryption in transit: TLS 1.3 for all data transmitted between donors, charities, and Givelayer
- •Encryption at rest: AES-256 encryption for stored data
- •Access controls: Role-based access with row-level security in our database
- •Authentication: Multi-factor authentication required for charity administrator accounts
- •Infrastructure security: SOC 2-compliant infrastructure providers (Supabase, Cloudflare, Stripe)
- •Code security: Code review, dependency scanning, and infrastructure hardening
- •Payment security: All payment data handled exclusively by Stripe (PCI-DSS Level 1 certified)
No system is perfectly secure. While we work to protect personal information, we cannot guarantee absolute security. In the event of a data breach affecting personal information, we will notify affected users and applicable regulators as required by law.
For security concerns or to report a vulnerability, contact security@givelayer.com.
Children's Privacy
The Service is not directed at children under 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete it.
If you believe a child has provided information to Givelayer, contact privacy@givelayer.com.
Third-Party Links
The Service may contain links to third-party websites, including charity websites and external resources. We are not responsible for the privacy practices of third parties. Review the privacy policies of any third-party sites you visit.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by:
- •Posting the updated Policy on the Service with a new effective date
- •Sending email notice to charity administrators
- •Displaying a notice on the Service for at least 30 days
Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
Contact Us
For privacy questions, requests, or complaints, contact:
Givelayer Technologies Inc.
Privacy Officer
324 8 Ave SW, 12th Floor
Calgary, Alberta, T2P 2Z2, Canada
Email: privacy@givelayer.com
General support: support@givelayer.com
For unresolved complaints in Canada, you may contact the Office of the Privacy Commissioner of Canada:
- •Website: priv.gc.ca
- •Phone: 1-800-282-1376
For unresolved complaints in the United States, you may contact your state attorney general or the Federal Trade Commission.
By using the Givelayer Service, you acknowledge that you have read and understood this Privacy Policy.
Questions about your privacy?
Our Privacy Officer is here to answer any questions or fulfill data requests.
Email privacy@givelayer.com