Donor Privacy Policy

1. Introduction, Definitions, and Important Information

1.1. iDonatio (“We” or “us”) are committed to protecting and respecting your personal data and privacy.

1.2. App: The iDonatio mobile application that can be downloaded and installed on smart phones to donate money to Donees registered on the platform.

1.3. Charity: Any charitable organisation registered on the iDonatio platform for the purpose of receiving donations and is registered with the Charity Commissions of England and Wales or Northern Ireland or Scotland.

1.4. Individual: These are individuals that are not registered charities but are registered on the iDonatio platform to receive non-charitable donations for their individual events.

1.5. Donee: This refers to a charity or individual.

1.6. Donor: A person who donates to a Donee via the iDonatio mobile App.

1.7. Financial Gateway: Stripe - This is the payment processor that processes all donations made on this platform.

1.8. This privacy policy relates to how we use and collect personal data from you when you use our platform or access our website. It also relates to our use of any personal information you provide to us by telephone and in written correspondence (including letter and email).

1.9. Our platform and website are intended for people 16 years old and over and we do not collect data relating to children.

1.10. Our platform and website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling connections to them may allow these third parties to collect or share data about you. We are not in control of these third-party websites and are not responsible for their privacy statements. We encourage you to read their privacy policy before you visit their website.

1.11. We may collect your data and information on behalf of third parties we have partnered with.

1.12. All personal data and information you provide to us are used in line with all applicable laws concerning the protection of such data and information; including but not limited to the Data Protection Act 1998 and 2018 (DPA) and the UK General Data Protection Regulation (UK GDPR), described in this policy as the “Data Protection Laws”.

1.13. This privacy policy also forms part of iDonatio platform terms and conditions. This privacy policy is not intended to override our terms and condition.

1.14. This policy may be amended or updated from time to time and any revisions will be posted to this page. You will be informed when there are changes.

2. Who we are and how to contact us.

2.1. iDonatio platform with company house registration number 12722710 are the data controller. We are a limited company registered in England and Wales with the Company House. Our registered office is at 9, Chapel Place, London, United Kingdom, EC2A 3DQ. If you require more information about our privacy policy or information about the data and information we hold about you, contact us using the details below:

Privacy Officer
iDonatio UK Limited
9, Chapel Place,
London,
United Kingdom,
EC2A 3DQ
Email: info@idonatio.com

2.2. If you have a complaint about how we collected your data and information or/and how we are using your data and information, please contact us at the above address. If you are not satisfied with the way we handled your complaint, you can contact the - Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance

3. The data we collect

3.1. We collect and process personal data. The personal data we collect, and process include identity, contact, transactional, technical, profile, usage, password and marketing and communications data as described below:

3.1.1 Personal Identity Data includes first name, last name, title or other identifier, gender, job title, date of birth, and images.

3.1.2 Contact Dataincludes company registered address, private address, email addresses (including private and company) and telephone numbers.

3.1.3 Location Data is captured from your computer device during the registration process, and it is used for analytics.

3.1.4 Transaction Data includes details about donations received and given when you use our platform (website and mobile APP).

3.1.5 Financial Data Data includes bank account details. Even though you submit these data via our platform, we do not store these data. They are collected and stored by Stripe (our financial gateway). Please visit to see how they handle your financial data.

3.1.6 Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.

3.1.7 Profile Dataincludes feedback and survey responses.

3.1.8Proof of Identityas required by our Payment Processor.

3.1.9 Usage Dataincludes information about how you use our website, products, and services.

3.1.10 Passwordto gain secure access to your account in the future.

3.1.11 Marketing and Communications dataincludes your preferences in receiving marketing from us and our third parties and your communication preferences.

3.2. Please note that we may collect and/or process other personal data from time to time

3.3. We only collect data from you directly or via third parties.

3.4. Why do we ask for this information?

3.4.1 To ensure your donation is administered to your chosen charity and where applicable, Gift Aid can be claimed on your donation. A successful donation email is sent to you when your donation has been successfully processed.

3.4.2. To enable us to verify that the bank details provided to us are linked to you.

3.4.3. To allow iDonatio and the Payment Processor conduct due diligence on your account.

3.4.4. To contact you if required about your registration and any other matter relating to your registration and activities on the platform.

3.4.5.To enable iDonatio and Donees to identify and manage donations.

3.4.6. To allow the iDonatio platform perform analytics on donors donating on premise and off premise.

3.4.7. To allow Donees you have donated to, and our partners send you marketing communications if you agreed to receive such communications.

3.4.8.To enable the iDonatio platform fulfil its requirements to all applicable laws (e.g., claiming Gift Aid) and where necessary for the purposes of Donees and iDonatio legitimate interests (i.e., ensuring the functioning of the iDonatio platform and effective administration of donations).

3.4.9. To ensure you can access your iDonatio Donor account using your email via the mobile App.

3.4.10. To allow iDonatio and our partners send you marketing communications if you agreed to receive such communications.

3.4.11. Job title, email address, address, date of birth and proof of identity are collected to enable iDonatio and the Payment Processor to verify that you are the person registering on the iDonatio platform.

3.4.12. To ensure that our records about you that we hold are accurate and up to date.

3.5. Who Do We Share Your Information With? (Third Parties)

3.5.1 Stripe – They use your personal data to payout your received donations to your chosen bank account. They use appropriate technologies and procedures to protect personal information, and all personal and organisation information they hold are held on secure servers and are encrypted. For more information on how Stripe processes your personal information, please refer to .

3.5.2. Donee you are donating to – This will enable them to send you a thank you email for your donation, if applicable, claim Gift Aid on your donation and if you opted to receive marking communications, send you marking information.

3.5.3. HMRC when the Donee you donated to is claiming Gift Aid on eligible donations regardless of if you mark the donation anonymous or not.

3.5.4. As the personal information about you we collect could be used by Stripe, HMRC and the Donee you are donating to, please ensure you carefully read and understand their privacy policy and the way in which they will use your personal information. iDonatio is not responsible for the way any Donee uses the information which it collects via the iDonatio platform.

3.5.5. We will not share your details with any third parties unrelated to iDonatio, except where we are under a legal obligation to do so or in order to enforce or apply our Terms Donor Terms and Conditions

3.6. How to access the information we hold about you.

3.6.1. If you would like to know what information we hold about you or how your information has been processed, you have the right under the GDPR to submit a Subject Access Request by following the ICO guidance. Please send your request to info@idonatio.com. For further information on Subject Access Request, please visit: Your right of access | ICO.

3.7. How do we collect data about you?
We use the following methods to collect data from and about you.

3.7.1. Online Forms. We collect your Identity, Contact Details, Profile and Financial Data by filling out forms on our website when you:

a) Register to use our platform.
b) Contact us.
c) Request marketing information to be sent to you.
d) Give us feedback.

3.7.2 Automatically. When you interact with our website, we may with your consent collect technical data about your equipment, browsing actions and patterns.

3.8. If you fail to provide personal and organisation data, we require.

3.8.1. Where we need to collect personal data by law, or under our terms and conditions, and you fail to provide that data when requested, you will not be able to use our platform. In this case, we may have to suspend or delete your account with us, but we will notify you if this is the case at the time.

3.9. How your data will be used. We use information held about you to:

3.9.1. Carry out our obligations arising from any contracts entered between you and us in relation to your giving donations to charity organisations and individuals, Donees claiming Giftaid where applicable, carryout feedback and research on our services, and notify you about changes to our services.

3.9.2. We never sell your data to third parties or allow third parties to contact you without your permission.

3.9.3. We may share your data with third parties where there is a legal obligation for us to do so or we have identified a valid lawful basis as set out in our terms and condition. We may process your personal data without your knowledge or consent where this is required or permitted by law.

3.10. When you donate anonymously, your data is not visible to the Donee you are donating to. However, when the Donee is claiming Gift Aid on such anonymous donations, your data, as required will be sent to HMRC.

3.11.Where you have indicated to us that you are happy for us to do so, we will also use your data:

3.11.1. To provide you with marketing information about other services we offer that are like those that you are already using with us; and

3.11.2. To provide you, or permit Donees to provide you, with information about campaigns or services that we feel may be of interest to you. We will only disclose your information to Donees to whom you make donations to through our platform.

3.12. Please be aware that where you have indicated to us that you are happy for us to disclose your information to your chosen Donees, Stripe and HMRC, you should check their privacy policy. We do our best to ensure they use your data in the way you have instructed, where your instructions were given directly to us. However, once we have passed that information to them, they will be in control of your information and how they use it will be determined by them. If you have any concerns about how they use your data, please contact your Donee directly.

3.13. Processing your data - We will only process your data where we have identified a lawful basis to do this, as follows. This may include providing your data to a third party.

3.13.1. Contractual obligation - processing your data to comply with our Terms and Conditions. Where you have registered to use our services, we will use the personal data you provided to comply with these terms and conditions.

3.13.2. Legitimate Interest - in the interest of our business, to enable us to give you the best service and product, and a secure experience.

3.13.3. Consent - We will ask for your consent to process your data outside our contractual obligations (see above) unless we have identified a Legitimate Interest (see above).

3.13.4. Legal obligation - We may process your data where it is necessary for us to do so to comply with the law.

4. International Transfers

4.1.Your data is stored by us and processed by our processors on the AWS infrastructure. This is a cloud base infrastructure. We cannot guarantee that all your data will be stored on the AWS infrastructure based in the UK. We will endeavour to ensure that your data remains in the UK. Some of our partners are based outside the UK, if we transfer your personal data out of the UK, we will ensure the security of your data.

5. Data Security

5.1. The security of your information is extremely important to us. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties on a need-to-know basis. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

5.2. The personal data that we collect from you and that we, our Payment Processor, and our third-party service providers process, may be transferred to, and stored at, a destination outside the United Kingdom. It may also be processed by staff operating outside the UK. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this privacy policy, irrespective of the standards in the country where your personal data may be transferred to or processed. This may include entering into data transfer agreements with our Payment Processor and service requiring them to adopt standards that ensure an equivalent level of protection for data as those we adopt.

5.3. Our internet based platform cannot be made 100% secure so, we cannot be held responsible for unauthorised or unintended access that are beyond our control.

6. Data Retention

6.1. We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

6.2 If you delete or close your account:

a) IIf you have donated to a Donee, all your personal identifiable data will be retained as long as the Donee you donated to remains registered on the iDonatio platform.
b) If you have not made any donations, all your personal identifiable data will be removed from our system.
c) We will instruct our Gateway (Stripe) to remove your personal identifiable data and organisation data registered against iDonatio form their system. We cannot guarantee how they handle our request. You may wish to contact Stripe to confirm your data has been deleted. For more information visit: Stripe: Help & Support

6.3. Information that needs to be kept by law.

Information Retention Period
Gift Aid declaration 6 years after the end of the tax year they relate to
Donation record 6 years after the end of the tax year they relate to for a charity that is not a company. Or 3 years after the end of the tax year they relate to for a company charity.

6.4. Reviewing data held by iDonatio.
In line with best practice recommended by the ICO, we will undertake a full review of all personal and organisation data held by the iDonatio platform every 2 years. This will include:

6.4.1 Reviewing the purposes for which we hold personal and organisation data against the original purposes for which it was obtained – if these do not align or the information is no longer needed or it is out-of-date, it will be archived or securely deleted (depending on if there are any legal requirements to retain the information).

6.4.2 Where necessary, we will inform any third parties we share the information with of the data being deleted. For example, our payments processor for out-of-date charity data.

7. Cookies Policy.

7.1. Our website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). The information generated by the cookie about your use of our website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of our website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. Further information about Google’s privacy policy may be obtained from: