Privacy Policy
Last Revised: August 17, 2026
1. Introduction
donortap.co (the "Site"), the DonorTap web portal at portal.donortap.co, and the DonorTap mobile application (together, the "Services") are owned and operated by Global Aid Technologies Inc. ("DonorTap," "we," "us," "our").
This Policy explains what we collect, why, who we share it with, and the choices available to you. It applies to three groups, who are treated differently:
- Nonprofit organizations and their administrators and staff
- Volunteers who collect donations using the mobile application
- Donors who make contactless donations
DonorTap currently supports only nonprofits domiciled in the United States.
2. What we collect
2.1 Nonprofit organizations — business information only. Organization name, EIN, business registration number, physical and legal business addresses, business contact email and phone, website, logo and favicon images, and descriptive content for the organization and its campaigns. This is business information about the entity, not personal information about the individuals who own or control it.
2.2 Account holders (administrators, staff, volunteers). Email address, first and last name, the organizations you belong to, your role (organization administrator, administrator, or volunteer), and account status. Staff accounts have a password; volunteer accounts are passwordless and sign in by emailed link only.
2.3 Donation records. For each donation we record the amount, the fee, the campaign, the volunteer who collected it, the payment status, the card brand and the last four digits of the card, and identifiers issued by our payment processors.
We never receive or store full card numbers. On iPhone, the contactless read is performed by Apple's Tap to Pay on iPhone and the card data passes encrypted to our payment processor. Card numbers are not stored on the device or on our servers.
2.4 Donors. Donors do not create accounts and we do not collect donor names, addresses or contact details as part of a donation. We hold only the card brand, last four digits and processor identifiers described above. If a donor asks for a receipt, we collect the email address or mobile number given for that purpose and use it only to deliver the receipt.
2.5 What we do not collect: owner information and bank details
To accept donations, a nonprofit must be underwritten by our payment partner. That underwriting requires sensitive information about the organization and the individuals who own or control it, including:
- Names, dates of birth and home addresses of beneficial owners and control persons
- Government identifiers, including Social Security Numbers
- Copies of identity documents, where requested
- Bank account and routing numbers for settlement
DonorTap does not collect, receive, transmit, store or process any of this information.
It is submitted by your organization directly to our payment partner through that partner's own secure interface. It does not pass through DonorTap's systems and is not held in DonorTap's databases at any point. DonorTap receives only an identifier for the resulting merchant record, and a status indicating whether underwriting is pending, approved or declined.
Our payment partner is the custodian of that information, and it is governed by that partner's privacy policy and its agreement with your organization. DonorTap is not responsible for its collection, use, retention, security or disclosure, and cannot access, retrieve, correct or delete it on your behalf. Requests concerning that information must be directed to the payment partner.
2.6 Technical information. Server and application logs including IP address, timestamps, request paths and error diagnostics, retained for security, fraud prevention and troubleshooting.
2.7 Device information (mobile application). Whether the device supports and is enrolled for contactless acceptance, and a processor-issued reader identifier. Authentication tokens and merchant credentials are held in the device Keychain. The application requires no camera, location, contacts or microphone access.
2.8 What we do not collect. In addition to the owner and bank information described in 2.5: we do not use advertising trackers, we do not sell personal information, and we do not build donor profiles across organizations.
3. How we use it
- To provide the Services: creating accounts, managing campaigns and volunteers, processing donations, issuing receipts
- To calculate and apply fees, and to reconcile our records against the payment processor's
- To send transactional email — invitations, sign-in links, receipts and service notices
- To secure the Services, prevent fraud and abuse, and comply with legal and payment-network obligations
- To provide support
We do not use personal information for advertising, and we do not send marketing email to donors.
4. Who we share it with
We share personal information only with service providers who need it to operate the Services, and only for that purpose:
| Provider | Purpose | Data involved |
|---|---|---|
| Koard | Contactless payment acceptance and transaction processing | Transaction data, merchant and terminal identifiers, card brand and last four |
| Worldpay for Platforms (Payrix) | Merchant underwriting, payment settlement and funding | Business details and transaction data. Owner information and bank details are provided to this partner directly by your organization, not by DonorTap — see 2.5 |
| Supabase | Database, authentication, file storage (United States) | Account, organization, campaign and donation records |
| Vercel | Application hosting (United States) | Request logs |
| Resend | Transactional email delivery | Recipient email address and message content |
| Apple | Tap to Pay on iPhone contactless reading | Encrypted card data; DonorTap does not receive it |
We also disclose information where required by law, to enforce our terms, or to protect the rights and safety of users and the public. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
If DonorTap is involved in a merger, acquisition or sale of assets, personal information may transfer as part of that transaction; we will give notice before it becomes subject to a different privacy policy.
5. Data separation between organizations
Each nonprofit's data is isolated. Administrators and volunteers can access only the organizations they belong to, enforced at the database layer. A volunteer who serves several nonprofits sees each one's data separately, and donations are attributed to the organization for which they were collected.
6. Retention
We retain account and organization records for as long as the account is active. Donation and receipt records are retained as long as necessary to comply with our financial, tax and payment-network obligations. Logs are retained on a shorter cycle. On account closure we delete or de-identify personal information except where retention is legally required.
We do not retain owner information or bank details at all — see 2.5.
7. Security
Data is encrypted in transit. Access to the database is restricted by row-level security so that each organization's records are reachable only by its own members. Payment credentials are stored server-side with restricted access and are never exposed to browsers or to volunteer devices beyond what the application needs to operate. On the mobile application, credentials and session tokens are held in the device Keychain.
No system is perfectly secure, and we cannot guarantee absolute security.
8. Your choices and rights
- Access and correction. Account holders can view and update their information in the portal, or contact us.
- Deletion. You may request deletion of your account; we will honor it except where records must be retained for financial or legal reasons.
- Email. Transactional messages — sign-in links, invitations, receipts — are necessary to the Services and cannot be opted out of while an account is active.
- Donors. A donor who wishes to know what is held about a donation, or to have a receipt email address deleted, may contact us with the date and amount.
- Owner information and bank details. We hold none, so we cannot action requests about it. Direct those to the payment partner — see 2.5.
California residents have rights under the CCPA/CPRA to know, delete, correct and limit use of sensitive personal information, and not to be discriminated against for exercising them. We do not sell personal information or share it for cross-context behavioral advertising.
To exercise any right, contact hello@donortap.co.
9. Children
The Services are not directed to children under 13 and we do not knowingly collect their personal information. Account holders must be at least 18. If we learn that we have collected information from a child under 13, we will delete it.
10. International users
The Services are operated in the United States and intended for United States nonprofits. Information is stored and processed in the United States.
11. Changes
We will post any changes here and update the "Last Revised" date. Material changes will be notified to account holders by email.
12. Contact
Global Aid Technologies Inc.
Email: hello@donortap.co
Support: support@donortap.co