Privacy Policy

Effective: June 7, 2026

This policy explains what information Fundly collects, how we use it, and the choices you have. We do not sell personal information, and we do not use Fundly for third-party advertising.

What we collect

We collect account information for org admins and advisors (name, email, role), organization details (name, EIN where provided), the campaign content you create, transaction records for donations and orders, and basic device and log data needed to keep the service secure. Card numbers are entered directly into Stripe's secure fields and are never seen or stored by Fundly.

Children's privacy

Fundly is designed for adult-led school organizations. No one under 13 may create an account or have personal information collected. A student's age is not established by typing in a date of birth; it is established by an attestation from a responsible adult — the student's advisor or the organization's admin — recorded with the adult's identity, the method of attestation, and a timestamp on both the user record and the audit log. Students aged 13-17 may participate in campaigns only when invited by an advisor and are not asked to create accounts. When a student is named in a campaign, the responsible adult advisor attests that they have consent from the student's parent or guardian. We do not knowingly collect personal information from children under 13. If you believe we have, please contact [email protected] and we will delete it.

How we use data

We use the information we collect to operate Fundly, process payments, send transactional emails (donation receipts, order confirmations), provide support, meet legal and tax obligations, and improve the product. We do not sell personal information, and we do not use it for third-party advertising or cross-site tracking.

Cookies

We use two strictly functional cookies. The session cookie keeps you signed in and protects against fraud; it expires when you close your browser or when you sign out. The device-hint cookie remembers the display name on a given device so the sign-in page can pre-fill it, but it is NOT a login token — the cookie holds no secret, expires after 90 days, and is HttpOnly and SameSite=Strict (Secure on production). We do not use advertising cookies, third-party tracking pixels, or analytics that follow you across other sites. You can clear both cookies by signing out.

Data retention

We keep different kinds of data for different periods. The formal schedule, with the legal basis for each period, is in our written Data Retention Policy. In summary: financial transaction records (donations, orders, payouts, related audit trail) are kept for seven years to satisfy IRS recordkeeping requirements; account and membership data for the lifetime of the account plus three years; student personal information until the adult attestation that established the student's 13+ status is revoked, plus three years; student-authored outreach media (voice, video, or text clips) for seven days after the campaign ends, then the file bytes are purged; server access and application logs for 90 days; and database backups on a 14-day rolling rotation with an off-host copy. After an account is deleted, financial records tied to past transactions are retained for the seven-year period regardless of the account deletion. The full policy, including deletion and anonymization method, is published as a separate document for auditors.

Your rights and contact

You can request access to, correction of, or deletion of your personal data by emailing [email protected]. We respond to verifiable requests within 45 days. For product support, contact [email protected]. Fundly is operated under the laws of the State of Delaware.