Privacy Policy
Version 1.1 — in effect since 30/07/2026
This Policy explains what data Care About Us Fund collects, why it collects it, who it is shared with, and what you can require of us.
1. Controller and contact
The data controller is Care About Us Fund. The controller's address will appear in this section once incorporation of the entity is complete.
Requests about personal data can be made directly on the platform, under My account → My data, or through support.
2. What we collect
From donors: the amount, the payment method, and the payer details the provider returns to us. A public name and message only if you choose to leave them. An e-mail address only if you type one at checkout — it is optional, it is used solely to send the receipt for that donation, and it does not go on any mailing list.
From organisers: your sign-up e-mail, the public name you choose, the text and images of the fundraiser, your city and region if you give them, identity-verification data when we ask for it, and the payout details for withdrawals.
From everyone: IP address, technical access data, and the link source (utm) used to measure how a fundraiser is being shared.
We do not ask for sensitive data. If you publish it in your fundraiser's text — health information, for example — you are publishing it on your own account.
3. Why we collect it (legal bases)
Performance of the contract: running the fundraiser, processing the donation, paying the withdrawal.
Legal and regulatory obligation: identifying the payer and keeping financial records, as anti-money-laundering rules require.
Legitimate interest: preventing fraud, measuring use of the platform and improving the product — always to the minimum necessary.
Consent: the e-mail you optionally give at checkout to receive the receipt, optional communications, and anything you choose to make public (name, message, testimonial).
4. Who we share it with
Payment providers, to process donations and withdrawals.
Infrastructure providers: hosting, database and e-mail delivery, which process data on our instructions.
A machine-translation engine, when a fundraiser is translated — it receives only the public title and story, never a donor's personal data.
Authorities, on a valid order.
We do not sell personal data and we do not pass it to third parties for advertising.
5. International transfers
Care About Us Fund is in the United States and some of our infrastructure sits outside your country. By using the platform your data is transferred internationally, under the contractual safeguards required of our processors.
6. What is public
Public: title, story, images, goal, amount raised, city and region, the organiser's public name, and testimonials.
Of a donor, only the display name and the message they choose appear publicly — and nothing at all if they give anonymously.
An anonymous donation is anonymous to the public, not to us: the payer stays identified internally, because anti-money-laundering law requires it.
We never display anyone's e-mail address, identity document or payout details.
7. How long we keep it
Account and fundraiser data: for as long as the account exists.
Financial records (donations, withdrawals, the ledger): kept even after an account is deleted. Payer identifiers held under anti-money-laundering rules are erased 5 years after deletion; the amounts, dates and entries remain, without anyone's name.
Access logs: for the period the applicable law requires.
8. Your rights
At any time, under My account → My data, you can download a file with everything we hold about you, and request deletion of your account.
Deletion is scheduled 30 days ahead — time to withdraw your balance and close fundraisers — and can be cancelled in that period. On the date, access is revoked, active fundraisers are closed, and personal data we are not required to keep is erased.
You can also ask for incorrect data to be corrected, for information about who it was shared with, and to withdraw consent, through support.
9. Security
We use encryption in transit, role-based access control, and an audit trail of administrative actions. Verification documents are kept in private storage, never at a public URL.
Documents and payment keys never appear in logs.
No system is immune. In an incident carrying material risk we notify the people affected and the authority, as the law requires.
10. Cookies
We use the minimum: one cookie to keep your session and another to remember the language you chose. We use no third-party advertising cookies.
11. Children
The platform is not intended for people under 18 and we do not create accounts for them. A fundraiser may benefit a minor, organised by their legal guardian.
12. Changes
Material changes to this Policy are announced with reasonable notice. Every version has a number and a date.
