Third Party Index

Snapshot 73176

Document
Security page
URL
https://www.givelively.org/data-privacy-and-security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
299119 bytes
SHA-256 (raw)
9fb6211267e2349e8cc04732c2e6a9ad73cc31113b8d94cc3118d8bf2520a34c
SHA-256 (normalized text)
5db140f6e2919b1d58c81136f91f6cfd41c67bd77511952ba0992f73f4f665ff

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Privacy & Security
SummaryData PrivacySecurityBusiness ContinuityTroubleshootingValues
DATA PRIVACY
Rights we respect
We never sell, rent or lease personal or business details to any third parties. Never. When we share data with nonprofits and partners, it is always in keeping with our Privacy Policy.
SECURITY
Standards we protect
We never charge a card, digital wallet or bank account without authorization. Our security safeguards protect all purchases and payments, ensuring that confidential information is never vulnerable.
TROUBLESHOOTING
Practices we expect
When faced with unanticipated tech issues or security concerns, we react. We mobilize immediately to tackle the issues and find responsible solutions.
VALUES
Priorities we project
We support values that make the world a better place. We terminate uses of our tech that we deem to be in violation of our values, as stated in our Terms of Use.
DATA PRIVACY
The Full Story
How is private data handled so that everyone can be sure it stays private?
Nothing is more significant to us than the goodwill of donors and vitality of the nonprofits they support. That is why we spare no effort to ensure data privacy in accordance with the law, best practices and what is right.
First and foremost, we and our nonprofit members never directly see or store any donor payment information. Saved payment details are captured by and stored securely in a third-party payment processor without passing through our servers.
With any data we do collect and retain, we take every reasonable action to protect against its loss or misuse, both in transit and at rest. While in transit, it is protected using end-to-end encryption and SSL protected web pages (see more below). At rest, it resides in encrypted databases, where we store data for as long as required. Critically, we will never sell, rent or lease it to third parties.
We are however obligated to disclose some personal data to nonprofit members receiving donations and to third-party partners who help process those donations, as fully described in our Privacy Policy. With nonprofits, we share donor first and last name, email address and any other provided information.
Other personal payment data may be passed through to partners for the purpose of processing donations.
For more about individual nonprofits’ privacy policies and how they use and protect personal data, contact the nonprofits directly. For more about some of our partners, see more about our partners’ security below.
These details aside, we acknowledge and respect donors’ right to control their data. We also set store by the spirit of the California Consumer Privacy Act and the stricter standards of the European Union’s General Data Protection Regulation (GDPR), both of which govern data protection and privacy, and we comply with them where possible. For more regarding this, see our Master Service Agreement, Terms of Use, and Privacy Policy.
In terms of hardware, our website and technology are hosted by Amazon Web Services (see more below), a robust and reliable platform that ensures continuous operations, round-the-clock support and top-quality security, including firewalls, encryption, monitoring, penetration testing and more. Learn more about AWS security.
SECURITY
Industry-standard safe practices
What kinds of measures ensure the complete security of Give Lively’s fundraising technology?
01
End-to-End encryption and SSL protected web pages
02
PCI Level 1 Compliance
03
SOC 1 and 2 reports
01
End-to-End encryption and SSL protected web pages
02
PCI Level 1 Compliance
03
SOC 1 and 2 reports
Donation Disbursement
We believe all money donated to nonprofits should get to those nonprofits as quickly as possible. The speed of disbursement is in part a function of the form of payment and whether the nonprofit is a Give Lively member.
For full details about transaction fees and donation disbursement, click below.
Transaction Fees & Donation Disbursement
More about our tech partners’ security
Salesforce
CRM used as an integration for nonprofits
Learn More
Give Lively offers a free, native Salesforce integration. Our member nonprofits that use Salesforce can install our Salesforce app to automatically sync donation information. Learn more about data privacy and security at Salesforce.
Zapier
One integration, thousands of applications
Learn More
Zapier is a software company that automates connections between apps, turning everyday tasks into effortless workflows. In our case, Zapier allows nonprofits to connect Give Lively to 6,000+ other web services. The automated connections nonprofits create are called Zaps, which consist of a trigger and one or more actions; the trigger automatically initiates the action(s) through Zapier. Zaps can be set up in minutes with no coding. Learn more about Zapier’s security compliance.
Stripe
Our required payment processor
Learn More
We rely on Stripe to process and disburse donations. By connecting an activated Stripe account to Give Lively – a necessary step for Give Lively membership – nonprofits grant us permission to process donations, transfer funds and deliver donor data through their Stripe account.
However, much like an account with Facebook, a Stripe account is entirely independent of Give Lively. We selected Stripe because it is PCI Level 1 compliant, which means the company maintains the highest level of data security when it comes to protecting payment information. Learn more about Stripe's PCI compliance and privacy practices.
Shift4
Our optional alternative payment processor
Learn More
Learn More
Shift4 is our optional alternative payment processor. It offers some of the best technology and lowest transaction fees in the industry, as well as industry-leading fraud prevention and security tools that ensure higher conversion rates, fewer chargebacks and ironclad data protection.
When a nonprofit uses Shift4 in conjunction with Give Lively, it allows us to process donations, transfer funds and deliver donor data through its Shift4 account. Learn more about Shift4's PCI compliance and privacy policy.
PayPal
Our optional additional payment processor
Learn More
PayPal is an optional donation-processing and disbursement method available to our nonprofit members. By using it in conjunction with Give Lively, a nonprofit allows us to process donations, transfer funds and deliver donor data through its PayPal account.
Just like a bank account, however, a PayPal account is not at all connected to Give Lively. We have great confidence in PayPal because of its PCI Level 1 compliance, placing it at the highest level of data security when protecting payment information. Learn more about PayPal's PCI compliance and privacy practices.
Chariot
Our online donor-advised fund (DAF) payment provider
Learn More
Learn More
Learn More
Learn More
Learn More
We use Chariot to power our DAF payment method, called DAFpay, a tool that solves both donor and nonprofit DAF-grant pain points, while helping to increase adoption of DAFs.
Chariot technology only allows authorized users to take authorized actions, and with end-to-end encryption that protects all parties involved. DAFpay by Chariot only interacts with fields in a portal that are necessary to submit a grant request. Learn more about Chariot’s safety program and privacy policy.
Double the Donation
Taps into matching gift programs through donors’ companies
Learn More
Learn More
Learn More
Learn More
Learn More
We work with Double the Donation to help nonprofit organizations raise more money and improve donor engagement by tapping into the matching gifts programs available through donors’ companies. To do this, we share a limited amount of information with Double the Donation. Learn more about Double the Donation's privacy policy and security.
Intercom
Our customer service and digital marketing platform
Learn More
Learn More
Learn More
We rely on Intercom in several ways. We use it for customer support, to manage and record relationships with member organizations and contacts, and to track their utilization of our various offerings. We also leverage it to send marketing and service emails, as well as to post important information across our website and portals. Learn more about privacy and security at Intercom.
‍
Mandrill
Email service that send receipts and other notifications
Learn More
Learn More
Learn More
Mandrill is a transactional email service, run by MailChimp, through which Give Lively sends receipts. Although no personal data is permanently filed with Mandrill, what passes through it – donation information, not including bank or card details – is stored for 30-90 days and carefully safeguarded in keeping with legal data protection requirements, as well as laws against spam. Learn more about Mailchimp's data security and privacy and its anti-spam requirements.
Amazon Web Services
Cloud services platform that hosts our website and tech
Learn More
Amazon Web Services (AWS) is the cloud services platform that Give Lively uses to host its website and all of its technology. Security at AWS is an extremely high priority, built to levels demanded by the most security-sensitive organizations, complete with firewalls, encryption, monitoring, penetration testing and more. Learn more about AWS security.
Heroku
Cloud platform we use to build and monitor our apps
Learn More
As a platform for its technology, Give Lively uses Heroku, a PCI Level 1-compliant cloud service for building, delivering, monitoring and scaling apps. Heroku’s security-conscious operations include constant threat monitoring, automatic and seamless vulnerability patching, and 24-hour support. This extends to data synchronization with Salesforce. Heroku’s physical infrastructure is hosted and managed within Amazon’s secure data centers and utilizes Amazon Web Service technology. Learn more about Heroku security.
Twillio
Communication platform that powers Text-to-Donate
Learn More
We work with Twilio, a cloud communication platform, to power our Text-to-Donate technology. Twilio allows donors to text our shortcode with a nonprofit-specific text code and, in return, receive a link to that nonprofit’s campaign. Learn more about Twilio's privacy practices.
BUSINESS CONTINUITY PLANS
No matter the circumstances, Give Lively’s commitment to the nonprofit community remains the same.
Our commitment to working with and for the nonprofit community is unwavering. We are fully confident of our ability to continue supporting our nonprofit members through service disruptions and turbulent times. Their work is never more critical than when health, welfare and economic vulnerabilities expand into new populations in the face of unexpected challenges.
To ensure our uninterrupted operations during times of crisis, we’ve taken the following steps as part of our Business Continuity plan:
We always plan for the unexpected, but we also set up contingency plans, including workarounds to guarantee nonprofits’ uninterrupted ability to raise funds.
As a function of circumstance, our staff is capable of delivering Give Lively services from almost anywhere.
The robustness of our technical, support and communications systems has been reviewed to accommodate this remote work. Our operations will continue to be secure and monitored as regularly as always.
Our service providers' continuity plans
Importantly, as our platform rests on the strong shoulders of several service providers, we urge our nonprofit members to proactively check our technology partners' continuity plans:
Stripe
Learn More
Heroku
Learn More
Amazon Web Services
Learn More
Twillio
Learn More
Salesforce
Learn More
TROUBLESHOOTING
What happens when something goes wrong?
While we do everything we can to keep data secure and operations seamless, there is no such thing as 100% secure and error-free systems. Unfortunately, service interruptions and failures happen, as do unexpected and very rare instances of fundraising tech misuse.
Whatever the event, we respond to any and all concerns as quickly and thoroughly as possible. Our engineering and membership teams search for solutions, communicate how long they may take, recommend workarounds, if needed, and then advise of fixes once they have been implemented. Followup monitoring, proactive communication with all nonprofit members affected by the interruption, after-the-fact diagnostics and systemwide improvements are all part of the process.
If there is ever any reason to believe that Give Lively and its technology are not doing what they should or that the security of an account has been compromised, please contact us immediately at support@givelively.org.
Remember: Give Lively is unable to issue refunds on behalf of our nonprofit members, due to our Terms of Use. Refunds can only be made by the nonprofit named on the donation receipt.
VALUES
What are the values that Give Lively holds dear?
We support values that inspire nonprofits to tackle tough challenges and complex issues such as gender equality, LGBTQ+ rights, social and environmental justice and more. Accordingly, we work to terminate all uses of our technology that promote activities not in alignment with our values.
Unacceptable uses include:
Discrimination on the basis of race, color, religion (creed), gender, gender expression, age, national origin (ancestry), disability, marital status, sexual orientation or military status in any activities, programs or operations
Advocating against or denying the rights of women
Advocating against or denying the rights or existence of anyone on the basis of their sex, gender, gender expression or sexual orientation, including transgender and gender nonconforming people
Advocating against or denying the rights of historically underrepresented groups, including Black, brown, AAPI and Indigenous people
Advocating against or denying environmental or social sustainability practices, especially with regard to renewable energy; land, water and air rights and use; and the growing climate emergency
Advocating for the sale, ownership and/or civilian use of assault weapons, weapons of war, high capacity magazines, automatic weapons or any mechanism that can convert a firearm into an automatic weapon
Disseminating hate speech or dangerous speech, promoting or inciting violence online or offline.
We have included this here (and in our Terms of Use) because we place great significance on the safety of the space we are proud to share with donors and our nonprofit members.
OUR FAQs
We have some answers that will help you
How and why is Give Lively’s platform free for nonprofits?
What is Give Lively membership and what are the requirements?
How does Give Lively support its members?
Why does Give Lively use UTC for Giving Basket donation receipt times and dates?
Still got questions? Let us help you
More FAQs