This is a realistic sample policy for design purposes. It is illustrative placeholder copy and is not legal advice — your final policy should be reviewed by counsel for your jurisdiction.
01Scope & who we are
Givana (“Givana,” “we,” “us”) provides software that lets communities and faith organisations receive gifts and keep their giving records. This policy explains what information we handle, why, and the choices you have.
It applies to our marketing website, the community dashboard, donor-facing giving pages we host on behalf of communities, and any related services that link to this policy.
It does not govern the independent practices of a community that uses Givana, nor the practices of our payment processor, each of which maintains its own policy.
02Controller & processor roles
For donor information collected through a community's giving page, the community is the data controller and Givana acts as a processoron the community's behalf. For account information of the community's own team and for our own website analytics, Givana is the controller.
This matters because it tells you who to approach with a request. A donor asking about their gift should generally contact the community first; we will support the community in responding.
03Information we collect
We collect only what a giving platform genuinely needs. The table below summarises the main categories.
| Category | Examples | Why |
|---|---|---|
| Community account | Name, email, role, community name, giving-page link | To create and secure accounts |
| Donor details | Name, email, gift amount, fund, optional message | To process a gift & issue a receipt |
| Payment metadata | Last 4 digits, brand, processor reference | Reconciliation & refunds |
| Technical | Device, browser, IP, approximate region | Security & fraud prevention |
We do not collect full card numbers — see Payments & card data.
04How we use information
We use the information above to:
- Operate giving pages, process gifts, and deliver receipts.
- Reconcile settled payments so a community's records reflect what truly arrived.
- Provide dashboards, exports, and statements to authorised community staff.
- Detect and prevent fraud, abuse, and security incidents.
- Send essential service messages (receipts, payout notices, security alerts).
- Comply with our legal, tax, and accounting obligations.
We do not sell personal information, and we do not use donor information to advertise to donors.
05Payments & card data
Payments are processed by our PCI-certified payment processor. Card details are entered directly into the processor's secure, tokenised fields. Full card numbers never reach Givana's servers — there is nothing sensitive for us to store or lose.
Gifts settle into your community's own connected account. Givana never takes custody of funds; we record and reconcile the flow alongside it.
06When we share information
We share information only in these limited circumstances:
- With the community whose giving page received the gift.
- With our payment processor, to charge cards and settle funds.
- With service providers (hosting, email delivery) bound by confidentiality and acting only on our instructions.
- For legal reasons, where required by law or to protect rights and safety.
- In a business transfer, where information may pass to a successor under this same policy.
07Cookies & tracking
We use a small number of cookies that are essential to sign-in and security, plus limited, privacy-respecting analytics on our marketing site. Giving pages avoid non-essential tracking by design.
For the full breakdown and your controls, see our Cookie Policy.
08Data retention
We keep information for as long as a community's account is active, and afterwards only as long as needed to meet legal, tax, and accounting obligations — typically up to seven years for financial records. After that it is deleted or anonymised.
A community can export and delete its data at any time; see Your rights & choices.
09How we protect data
We encrypt data in transit and at rest, isolate each community's data, scope and rotate access keys, and log sensitive actions. For the full picture, see our Trust & security page.
No system is perfectly secure, but we work to keep the surface small — the less sensitive data we hold, the less there is to protect.
10Your rights & choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain uses.
- Communities can manage and export account and donation data directly from the dashboard.
- Donors should contact the community that received the gift; we will assist the community in responding.
- You can unsubscribe from non-essential email at any time via the link in those messages.
To make a request to Givana directly, see Contacting us. We will not discriminate against you for exercising these rights.
11Children's privacy
Givana is intended for use by adults administering a community and by adult donors. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will delete it.
12International transfers
We may process information in countries other than your own. Where we do, we rely on appropriate safeguards — such as standard contractual clauses — to protect it consistently with this policy.
13Changes to this policy
We may update this policy as our service evolves. When we make material changes we will update the version and date at the top, and where appropriate notify communities in the dashboard or by email before the changes take effect.
14Contacting us
Questions about this policy or your information? We'd genuinely like to hear from you.
Email: privacy@givana.app
Post: Givana — Privacy, [registered address placeholder]