Legal
Privacy Policy
Last updated September 26, 2026
givevery helps nonprofits raise more, with beautiful donation forms, tax receipts and insights. This policy explains how we look after the information that flows through them.
givevery is operated by Givevery Enterprise Inc. ("givevery", "we", "us"), a British Columbia corporation (BC1258390). We're proudly Canadian.
The short version
- Nonprofits own their donor data. Always. We handle it only to run givevery for them, on their instructions. We never use it for our own marketing, never sell it, and never use it to train AI.
- Your data lives in Canada. Our primary database is in Montréal. Some of the tools we rely on process data in the U.S.; they're all listed on our Subprocessors page.
- We never see full card numbers. Payments are handled by Stripe.
- Every nonprofit is covered by our Data Processing Addendum. It applies automatically. See the DPA.
- AI widget builder is opt-in. Off by default. If you turn it on, Anthropic receives your prompts and schema metadata only — not donor rows. See Subprocessors.
- Salesforce CRM sync is opt-in. Off until you connect Salesforce in Integrations. We then send donor and gift fields to your Salesforce org, as you configure. Copies already in Salesforce stay under your Salesforce agreement. See Subprocessors.
- Questions? Our Privacy Officer reads every email: privacy@givevery.com.
Are you a donor? Jump to section 5. The short answer: the nonprofit you gave to is in charge of your information. We work behind the scenes on their behalf.
1. Who this policy is for
This policy covers:
- nonprofits and the staff and volunteers who use givevery;
- visitors to givevery.com, people who join our waitlist, and anyone who contacts us.
It also explains, briefly, how we handle donor information on behalf of the nonprofits we serve.
2. Our two roles
Privacy law cares about who decides how information is used. With givevery, that depends on whose information it is.
| Information | Our role | Who decides how it's used |
|---|---|---|
| Your dashboard account and your organization's details | Controller: we're responsible | givevery |
| Visitors to givevery.com, waitlist sign-ups, people who contact us | Controller | givevery |
| Donor and dedication information collected through your forms | Processor: we act for you, under a written agreement | You, the nonprofit |
"Controller" and "processor" are GDPR terms. Canadian privacy laws (PIPEDA, BC PIPA and Québec's Law 25) describe the same relationship as an organization and its service provider.
3. What we collect about you
3.1 Your nonprofit's account
- Your team: name, work email, role, and the organization you belong to.
- Your organization: legal name, charitable registration or tax-exempt number, address, logo, brand settings and receipt settings.
- Sign-in and security: hashed passwords (we never see yours), multi-factor authentication settings, and audit logs of sign-ins, setting changes and exports.
- Stripe onboarding: Stripe collects your banking and identity details directly. We only receive your onboarding status and limited account details.
- Our relationship: your platform fee rate, the fees collected, support conversations and feedback.
3.2 givevery.com visitors and waitlist
- What you tell us: name, work email and organization when you join the waitlist, request a demo or get in touch.
- Analytics, only with your permission: if you accept cookies, Google Analytics tells us which pages were visited, the approximate location (city or country), the device and how people found us. See our Cookie Policy.
3.3 Where it comes from
- From you, when you sign up, use givevery or contact us.
- From your organization, when an administrator invites you.
- From Stripe, which tells us your onboarding status.
- From your browser: security logs automatically, and analytics only if you opt in.
4. How we use it, and why we're allowed to
| What we do | Legal basis (GDPR) |
|---|---|
| Set up and run your account; provide givevery | Contract |
| Keep accounts secure with MFA, audit logs, and fraud and abuse prevention | Legitimate interests: keeping nonprofits and donors safe |
| Support you and send service messages (security alerts, changes to our terms) | Contract; legitimate interests |
| Bill our platform fee and keep tax and accounting records | Legal obligation |
| Respond to legal requests and enforce our terms | Legal obligation; legitimate interests |
| Understand how people use givevery.com | Consent |
| Send product news and updates | Consent, or implied consent where Canada's anti-spam law (CASL) allows |
Where Canadian law applies, we rely on your consent (express or implied, depending on the context) or another lawful authority.
Our emails: every marketing email has an unsubscribe link, and we act on it within 10 business days. We'll still send important service messages, like security alerts.
Optional AI widget builder: when a nonprofit opts in, Anthropic may receive prompts and schema metadata to suggest dashboard widgets. Donation records are queried on Givevery servers and are not sent to Anthropic.
Optional Salesforce CRM: when a nonprofit connects Salesforce, we send donor and gift fields to that nonprofit's Salesforce org (Nonprofit Cloud, NPSP, or standard objects) as they configure. Disconnecting stops new syncs; it does not delete records already written in Salesforce.
5. If you're a donor
5.1 The nonprofit is in charge. When you give through a givevery-powered form, you're giving your information to the nonprofit. They decide what to collect and how to use it, and their privacy policy applies. We provide the technology behind the scenes as their service provider, and handle your information only on their instructions, under a written agreement.
5.2 What we handle on their behalf. Depending on how the nonprofit sets up its form, this may include:
- Your details: name, email, phone and mailing address (for your tax receipt).
- Your gift: amount, date, one-time or monthly, campaign, and whether you covered the fees.
- Dedications: the name and email of the person you're honouring, and your message.
- Anything else you choose to share: for example, answers to a post-donation survey or details you add to your supporter profile.
- How you found the form: referring website and campaign tags (such as UTM parameters).
- Technical details: device, browser, IP address and time zone, used for security and fraud prevention and to show the nonprofit how its forms perform.
- Emails: whether confirmation and receipt emails were delivered and opened.
- Payment details: only limited details from Stripe (card brand, last four digits, expiry, status). We never receive full card numbers.
The nonprofit may use its givevery dashboard to see your giving history and group supporters (for example, "monthly donors"). That happens only within that nonprofit's own account. If the nonprofit connects Salesforce, they may also send your details to their own Salesforce org.
5.3 Embedded forms. Whether the form sits on the nonprofit's own website or on a page we host for them, the nonprofit is responsible for your information. On their own website, their cookie and privacy notices apply.
5.4 What we never do. We never:
- contact you for our own purposes;
- combine your information across nonprofits;
- build profiles of you across organizations;
- sell your information or use it for advertising;
- use it to train AI.
5.5 The small part we're responsible for. To protect every nonprofit on the platform and meet our own legal obligations, givevery is directly responsible for:
- security, fraud and rate-limiting logs (such as IP addresses and timestamps);
- a minimal transaction record (amount, date, fee, Stripe reference, receipt number), kept for tax, audit and dispute purposes.
5.6 Questions or requests. Please contact the nonprofit you gave to. If you contact us instead, we'll pass your request to them within 5 business days and help them respond.
6. Who we share information with
- Our subprocessors: the tools that power givevery, such as hosting, database, payments, email, background jobs and error monitoring. If you enable the AI widget builder, Anthropic receives prompts and schema metadata as described on our Subprocessors page. If you connect Salesforce, donor and gift records are sent to your connected Salesforce org as you configure. Each vendor is bound by a written agreement to keep information confidential and secure, and to use it only as we instruct.
- Stripe, to process payments. Stripe is also independently responsible for its own identity checks, fraud prevention and regulatory duties. See Stripe's Privacy Policy.
- Your own team: administrators can see activity within their organization's account.
- When the law requires it, such as a court order or valid government request, or to protect the safety and rights of nonprofits, donors, givevery or others.
- If givevery changes hands, for example in a merger or financing, with confidentiality protections and this policy still applying.
We never sell personal information. Not donors', not yours, not anyone's. We don't share it for advertising either.
7. Where your data lives
Built in Canada. Stored in Canada. Our primary database and file storage are hosted by Supabase in Montréal (AWS ca-central-1). Some of our tools, such as application hosting, email delivery and error monitoring, process data in the United States or elsewhere. Information processed outside your province or country may be accessible to authorities there under local law.
- From the EU/EEA: the European Commission recognizes Canada as providing adequate protection for organizations subject to PIPEDA. When data moves onward, for example to the U.S., we use the EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework or another lawful mechanism.
- From the UK and Switzerland: we use the UK International Data Transfer Addendum or the Swiss version of the Standard Contractual Clauses.
- From Québec: before information leaves Québec, we assess whether it will be properly protected. We can provide the details a nonprofit needs for its own privacy impact assessment.
8. How we keep it safe
Every nonprofit gets the same protection:
- multi-factor authentication for every dashboard user;
- row-level security, so one nonprofit's data is walled off from every other's;
- encryption in transit (TLS 1.2+) and at rest (AES-256);
- least-privilege access for our team;
- audit logs and rate limiting;
- error monitoring that strips out personal information.
Our Trust Center has the details, including where we are on SOC 2.
If something goes wrong, we'll tell you. For donor data, we'll notify the nonprofit within 48 hours of becoming aware of a breach and support its response. We'll also notify affected people and regulators when the law requires it: where there's a real risk of significant harm, or in Québec, a risk of serious injury. Every incident is recorded in our incident register.
9. How long we keep it
| Information | How long |
|---|---|
| Your nonprofit's account | While it's open. After you leave, you have 60 days to export everything, then we delete it within 30 days. Backups expire on their normal cycle. |
| Donor information (held for nonprofits) | As the nonprofit instructs; deleted on the same schedule as their account. Nonprofits keep their own records for the Canada Revenue Agency and can export them at any time. |
| Our transaction record | 7 years |
| Security and audit logs | 1 year |
| Website analytics | 14 months |
| Waitlist and newsletter contacts | Until you unsubscribe, or 2 years without activity |
When we no longer need information, we delete it securely or anonymize it.
10. Your rights
Depending on where you live, you can ask us to:
- show you the information we hold about you and how it has been used and shared;
- fix anything inaccurate or incomplete;
- delete it, or de-index it (Québec), subject to legal retention rules;
- give you a copy in a structured, commonly used format, or send it to another organization;
- stop or limit certain uses, including marketing.
You can also:
- withdraw your consent where we rely on it;
- ask about automated decisions (we don't make any);
- complain to a regulator (see section 13).
Just email privacy@givevery.com. We may need to confirm your identity. We'll respond within 30 days, and there's no charge. Donors, please contact the nonprofit first (see section 5.6). Nonprofits can export their data at any time from Settings.
11. Children
givevery is built for organizations and adults. We don't knowingly collect children's information for our own purposes. If you think we have, email privacy@givevery.com.
12. Our Privacy Officer, and where to complain
The person responsible for privacy at givevery is:
Mo Tabesh, Co-Founder, CEO and Privacy Officer privacy@givevery.com
If we haven't resolved your concern, you can contact:
- British Columbia: the Office of the Information and Privacy Commissioner for BC (oipc.bc.ca)
- Canada: the Office of the Privacy Commissioner of Canada (priv.gc.ca)
- Québec: the Commission d'accès à l'information (cai.gouv.qc.ca)
- EU/EEA: your local data protection authority
- UK: the Information Commissioner's Office (ico.org.uk)
13. U.S. privacy laws
For donor information, givevery is a service provider or processor under U.S. state privacy laws such as the CCPA. We don't sell or share personal information. U.S. residents can use the process in section 11.
14. Changes to this policy
When we update this policy, we'll post it here with a new date. For anything significant, we'll email nonprofit account owners at least 30 days before it takes effect.
Questions? We'd love to hear from you: privacy@givevery.com
Related: Terms of Service · Data Processing Addendum · Subprocessors · Cookie Policy · Trust Center · Acceptable Use Policy