Legal
Cookie Policy
Last updated September 28, 2026
This policy explains how Givevery Enterprise Inc. ("givevery", "we") uses cookies and similar technologies, such as local storage, on:
- our marketing website, givevery.com;
- the nonprofit dashboard, app.givevery.com;
- donation pages and forms we host for nonprofits.
Read it alongside our Privacy Policy.
The short version
- Donation pages and the dashboard use only strictly necessary cookies. No analytics, no ads, no tracking your donors didn't agree to. PostHog is not currently loaded.
- The marketing website uses Google Analytics only if you agree. Analytics cookies stay off until you opt in. This follows the GDPR, the ePrivacy rules and Québec's Law 25, which requires that technology used to identify, locate or profile you be deactivated by default.
- We don't use advertising, retargeting or social-media tracking pixels. Anywhere.
- The AI widget builder does not set cookies. It calls Anthropic from our servers when you opt in; your browser does not talk to Anthropic directly.
2. What cookies are
Cookies are small text files a website stores in your browser. "Similar technologies" include local storage and session storage, which work in a similar way. Some are set by us ("first-party"). Others are set by service providers, such as Stripe, whose code runs on our pages ("third-party").
3. Cookies we use
3.1 Strictly necessary (always on)
These cookies are needed for the Services to work and keep them secure. They don't require consent. You can block them in your browser, but sign-in or donations may then stop working.
| Name | Set by | Where | Purpose | Duration |
|---|---|---|---|---|
sb-<project>-auth-token (may be split into .0, .1) | givevery (Supabase Auth) | Dashboard | Keeps you signed in; refreshes your session | Session refresh; up to 7 days |
| MFA / session-assurance values | givevery (Supabase Auth) | Dashboard | Enforces multi-factor authentication | Session |
gv_consent | givevery | givevery.com | Remembers your cookie choices | 12 months |
__stripe_mid | Stripe | Donation pages | Fraud prevention | 1 year |
__stripe_sid | Stripe | Donation pages | Fraud prevention | 30 minutes |
Stripe may also set cookies on payment screens it hosts (for example, 3-D Secure authentication). See Stripe's Cookie Policy.
3.2 Analytics (givevery.com only, opt-in)
| Name | Set by | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | Distinguishes visitors so we can count them | 2 years |
_ga_<container-id> | Google Analytics | Keeps session state for analytics | 2 years |
We use Google Analytics 4 with Google signals and advertising features turned off, and analytics data is retained for 14 months. Google may process this data in the United States. See How Google uses information from sites that use its services.
3.3 Advertising
None. Ever.
3.4 Email engagement
Donation confirmation, receipt and dedication emails sent on a nonprofit's behalf may contain a small image (a "pixel") that tells the nonprofit whether the email was delivered and opened. This helps nonprofits confirm donors received their tax receipts. Most email apps let you block images to prevent it.
4. Your choices
- Cookie banner: when you first visit givevery.com, you can accept or reject analytics cookies. Rejecting is as easy as accepting.
- Change your mind: click Cookie settings in the footer of givevery.com at any time.
- Browser controls: most browsers let you block or delete cookies. Blocking strictly necessary cookies may break sign-in or donations.
- Google Analytics opt-out: you can also install the Google Analytics Opt-out Browser Add-on.
- Global Privacy Control: we treat a GPC signal as a rejection of analytics cookies.
5. nonprofit-added tools
If a nonprofit embeds a givevery donation form on its own website, the nonprofit's cookie policy and consent banner apply to that website. The form sets only the strictly necessary cookies in section 3.1, such as Stripe's fraud-prevention cookies, and nonprofits should list them in their own cookie notice. Any analytics or advertising tools a nonprofit adds to its own site are the nonprofit's responsibility.
6. Changes
If we add a new category of cookies, we will update this Policy and, where consent is required, ask for your consent before setting them.
7. Contact
privacy@givevery.com. Privacy Officer: Mo Tabesh, CEO, Givevery Enterprise Inc.
Related: Privacy Policy · Subprocessors · Trust Center