Privacy Policy
Last updated: December 2025
December 2025 changes
- Clarified billing metadata we receive from Polar.sh (subscription status, billing period, and discount)
- Added link to Polar's Privacy Policy in payment provider section
- Added Cloudflare for fraud and abuse prevention
This explains how Charity Record collects, uses, and protects your information. Charity Record is owned and operated by Infoportfolio LLC, a New Hampshire limited liability company, and this policy applies only to the Charity Record donation-tracking service at charityrecord.com (including its apps and APIs); it does not cover any other Infoportfolio LLC websites or services. Use of the service is also governed by our Terms of Service.
What We Collect
Account Data
Email (required), name (optional), and securely hashed password.
Optional tax profile data you can provide to improve estimates: estimated income (AGI estimate) and filing status.
If you subscribe to a paid plan, billing information is collected and processed by our merchant of record, Polar.sh. We receive non-sensitive billing metadata (subscription status, billing period, discount applied). We do not store credit card numbers.
Donation Records
Organization details and donation data you enter or import, including dates/amounts, item descriptions and values, charitable mileage, and stock & securities details, plus any notes you add.
Uploaded Files
We do not retain your CSV or XLSX files. We parse uploads on submission to create donation records, then discard the files. The parsed donation data is stored in your account. If we later support receipt or photo uploads, those files will be stored in encrypted object storage and will be subject to the same deletion policies described below.
Technical Data
We also collect standard web analytics (for example IP address, browser/version, device type, pages viewed, referral URLs, and timestamps) so we can understand how people access Charity Record and keep the service secure. We also log signup metadata (IP address, country, user agent, referrer, and UTM parameters) for fraud prevention and service analytics. Our analytics and advertising vendors may collect additional data under their own policies; for details see Google Analytics & Ads, Microsoft Privacy Statement, and any other services listed below.
How We Use Your Data
- • Run the service: Store and organize your donations
- • Generate exports: Create files for tax software
- • Send notifications: Account emails, password resets, two-factor authentication (2FA) setup emails and security changes, responses to your inquiries, and important service announcements (for example, pricing changes or policy updates). These transactional notices go out even if you opt out of marketing so we can inform you about your account.
- • Send product updates and promotional offers: Tax season reminders, upgrade notifications, new features, and special offers. We will only send marketing emails if you opt in during registration or via your account settings. You can unsubscribe at any time via the link in any email. Transactional emails (account notifications, security alerts, billing reminders) cannot be disabled.
- • Improve the product: Anonymized or aggregated usage analytics
- • Provide support & ensure safety: When you contact us, when we investigate errors (Sentry), and when we monitor for abuse, fraud, or illegal content. We reserve the right to remove data that violates our Terms (for example, CSAM or malware) and report it to authorities.
You Own Your Data
We never share information about your individual donations or charities with anyone outside our organization unless the law or a business transfer requires it. If we receive a valid legal request (for example, a subpoena or warrant), or if Charity Record is ever sold or merged, we will notify you when possible and only disclose the minimum data necessary, continuing to protect it under this policy. Export everything anytime in CSV format.
- Free accounts: Account deletion is immediate and permanent; data is removed as soon as you confirm deletion.
- Paid accounts: A 30-day countdown before deletion is permanent.
Who We Share With
We never sell your data. We only share it with service providers to keep Charity Record running, or with a new owner if Charity Record is bought, and the data stays under this policy:
Email: Amazon SES (transactional and marketing emails from hello@charityrecord.com), FeedBlitz (newsletter, optional), and email providers (Gmail/Migadu) for correspondence
Payments: Polar.sh (merchant of record) processes subscription payments. They may use sub-processors including Stripe for payment processing. See Polar's Privacy Policy for details.
Hosting: DigitalOcean (US servers)
Security & abuse prevention: Cloudflare. See Cloudflare’s Privacy Policy.
Error tracking: Sentry
Analytics & Advertising: Google Analytics 4, Google Ads, and Microsoft Advertising for conversion tracking and ad targeting. We also use internal, aggregated analytics to understand usage patterns and improve the product.
We may disclose your information if required by law, to comply with valid court orders or government requests, to protect our rights, or to prevent harm. If Charity Record is involved in a merger, acquisition, or asset sale, we will provide notice before your personal information is transferred to a different owner whenever legally permitted; some transactions (for example government orders that include non-disclosure requirements) may restrict our ability to notify you.
Security & Retention
We use HTTPS encryption, secure password hashing, backups, and rate limiting. You can also enable two-factor authentication (2FA) on your account using an authenticator app or email verification. No system is 100% secure, but we take reasonable precautions.
In the event of a data breach affecting your personal information, we will notify you via email within 72 hours of discovering the breach and outline the steps we're taking to address it.
Your data stays active as long as your account exists. Delete your account anytime – free account deletion is immediate, paid accounts have a 30-day grace period. We will permanently remove deleted accounts within 30 days, except where we must retain limited records for legal, security, or billing purposes (for example, transaction records for tax compliance). For abuse prevention, we retain a one-way hash of deleted email addresses for up to one year.
Your Rights
Access, export, correct, or delete your data anytime. Unsubscribe from marketing emails with one click. If you are a U.S. resident, your rights may vary by state (for example, California users have CCPA/CPRA rights). Contact us to exercise your rights, and we typically respond within 30 days.
State Privacy Rights (California)
No sale: We do not sell your personal information. We may share limited identifiers (such as cookie or device IDs) with analytics and advertising partners to measure campaigns and improve our marketing; you can opt out by declining non-essential cookies in our cookie banner.
CCPA/CPRA rights: California residents can request access, correction, or deletion of personal information and can designate an authorized agent. We do not discriminate for exercising privacy rights.
Other Details
Children: Our service is not intended for users under 13. We do not knowingly collect data from children; if we learn we have, we will delete it.
International: We host in the United States. If you are outside the US, your data will be transferred to and processed in the US. By using our service, you consent to this transfer.
Cookies: We use essential cookies for login sessions and CSRF protection, plus analytics/advertising cookies (for example Google Analytics and ad conversion tracking) to understand site usage and measure marketing. You can control cookies in your browser, but the app may not function without essential cookies.
Updates: We post the “Last updated” date at the top and email you about significant changes. We’ll also maintain a publicly accessible change history so you can see what changed. Your continued use after updates means you accept the changes.
Questions?
Email: legal@charityrecord.com (privacy inquiries)
Infoportfolio LLC (Attn: Charity Record)
6801 Jefferson St NE Ste 150 PMB 3682
Albuquerque, NM 87109