Gift of Parenthood

Privacy Policy

Last Updated: September 22, 2026

This Privacy Policy explains how Give Panda, LLC ("Give Panda"), a Wyoming limited liability company that operates the Gift of Parenthood crowdfunding platform, and Gift of Parenthood, Inc., a Pennsylvania nonprofit corporation and 501(c)(3) organization that operates the Gift of Parenthood blog and grant program (together, "we," "us," or "our"), collect, use, share, and protect information about you when you visit our websites (including giftofparenthood.org, give.giftofparenthood.org, and blog.giftofparenthood.org), read our blog, use our web application, donate, or organize or contribute to a fundraiser (collectively, the "Service").

About the entities. The crowdfunding platform is operated by Give Panda, LLC, a for-profit company. Charitable grants are awarded separately by Gift of Parenthood, Inc., a Pennsylvania nonprofit corporation and 501(c)(3) organization. Where this policy refers to grant applications or grant awards, Gift of Parenthood, Inc. is the responsible party for that activity and processes your information for those purposes.

By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.


1. Important Notice About Health and Reproductive Information

We are not a healthcare provider, and we are not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). Information you share with us is not protected by HIPAA.

If you choose to share information about your fertility journey, treatments, providers, diagnoses, adoption process, or related topics, you are doing so voluntarily and we will treat that information as "consumer health data" subject to the protections described in this policy. Do not share clinical records, diagnostic results, prescriptions, or other medical documentation unless we specifically request it as part of grant verification, in which case we will limit collection to what is necessary.

Where applicable state law (such as Washington's My Health My Data Act, Connecticut's Data Privacy Act, or Nevada's SB 370) provides additional protections for consumer health data, those protections apply to you, and Section 8 of this policy describes how to exercise the related rights.

2. Information We Collect

2.1 Information You Provide

We collect information you give us directly, which may include:

  • Account information: name, email address, password, date of birth, phone number, mailing address, country of residence
  • Profile and story content: photographs, videos, audio, written narratives about your family-building journey, partner or family member information you choose to include
  • Donation and payment information: billing name and address, payment card details (handled by our payment processor; we do not store full card numbers), donation amounts, donor preferences
  • Fundraiser information: campaign descriptions, fundraising goals, beneficiary details, payout bank account information (handled by Stripe Connect)
  • Grant application information: financial circumstances, family-building goals, intended use of funds, supporting documentation, references (processed by Gift of Parenthood, Inc.)
  • Contacts you import: if you use the invite feature, you can import contacts from your device, a vCard file, a CSV file, or a connected Google account. We store only each contact's name, email address, and phone number, and use them solely to send the invitations you explicitly request. See Section 5.3.
  • Communications: emails, messages, support tickets, and survey responses
  • Identity verification information: government-issued ID, tax identification number (SSN, SIN, NI number), and similar information collected by Stripe for payout accounts

2.2 Information Collected Automatically

When you use the Service, we and our service providers automatically collect:

  • Device and connection information: IP address, browser type and version, operating system, device identifiers, language preferences, time zone
  • Usage information: pages viewed, links clicked, referring and exit pages, time spent, features used, video and content interactions
  • Cookies and similar technologies: described in Section 6
  • Approximate location: derived from IP address (we collect precise geolocation only with your permission)

2.3 Information From Third Parties

We may receive information from:

  • Payment processors and platforms like Stripe (transaction details, account verification status)
  • Identity verification services for fundraiser organizers and grant recipients
  • Social media platforms if you connect your account or interact with our content
  • Analytics and advertising partners (aggregate or pseudonymous information)
  • Public sources for fraud prevention and verification purposes

2.4 Sensitive Information

Some information we collect is treated as "sensitive" under applicable laws, including consumer health data, precise geolocation, government identifiers, financial account information, and information about minors. We process sensitive information only as needed to operate the Service, fulfill your requests, comply with law, or with your consent.

3. How We Use Your Information

We use information to:

  • Operate, maintain, and improve the Service
  • Create and manage your account, fundraiser, donation, or grant application
  • Process payments, payouts, and refunds
  • Verify identity and prevent fraud, abuse, and unlawful activity
  • Communicate with you about your account, transactions, applications, and the Service
  • Send newsletters, updates, fundraising appeals, and program announcements (you can opt out at any time)
  • Personalize content and recommendations
  • Conduct research, analytics, and program evaluation (typically using aggregated or de-identified data)
  • Comply with legal obligations, respond to lawful requests, and protect our rights and the rights of others
  • Train and improve our internal tools, including AI-assisted administrative tools, using de-identified or aggregated data where feasible

4. AI and Automated Tools

Google user data is never used with AI or machine learning. Data obtained from Google APIs — including Google Contacts imported through the optional "Invite Friends" feature — is never processed by, transferred to, or used to create, train, or improve any artificial intelligence or machine learning model, whether ours or a third party's, and is never transferred to any third-party AI or ML service. It is used only to send the invitations you explicitly request (see Section 5.3). Gift of Parenthood integrates no third-party AI service providers of any kind.

The remainder of this section describes AI use that is entirely separate from, and never applied to, Google user data.

We use artificial intelligence ("AI") and machine learning tools as administrative aids in operating the Service. Specifically, we may use AI to:

  • Draft routine communications (such as application acknowledgments, status updates, and donor thank-yous) which our staff reviews before sending
  • Summarize grant applications and supporting materials for human reviewers
  • Detect potential fraud, duplicate accounts, or policy violations
  • Translate content
  • Improve search, categorization, and editorial workflows

Google user data is excluded from every use listed above, as stated at the start of this section.

Self-hosted, offline image model. So that faces stay centered when fundraiser cover photos are cropped, the Service runs a face-detection model (face-api.js "TinyFaceDetector") entirely within our own infrastructure: the model weights are served from our own domain and the analysis runs locally in the browser. No image is ever transmitted to a model provider or any third-party AI service, and the model performs detection only — it is never trained or fine-tuned on user data. It is applied solely to fundraiser cover images uploaded by organizers, and never to Google user data.

Grant selection decisions are made by human reviewers based on need-based criteria. AI tools may help organize and summarize information for those reviewers, but no grant decision is made solely by an automated system.

If we ever change this practice, for example by introducing automated decisioning that materially influences grant outcomes, we will update this policy, provide notice to applicants, and offer the rights required by applicable law (including the right to request human review of an adverse decision).

5. How We Share Information

We share information in the following circumstances:

5.1 Service Providers

We share information with vendors and service providers who help us operate the Service, including:

  • Payment processing: Stripe, Inc. (donations, fundraiser payouts, grant disbursements)
  • Email and communication: our email service providers
  • Hosting and infrastructure: cloud and content delivery providers
  • Analytics: privacy-aware analytics providers
  • Customer support tooling
  • Identity verification and fraud prevention
  • AI and language services: bound by contract to use information only for the services they provide to us

These providers are contractually limited to using information for our purposes.

5.2 Payment Processors

When you donate, organize a fundraiser, or receive a grant, payment-related information is handled by Stripe under Stripe's own terms and privacy policy. For grant recipients and fundraiser organizers, Stripe collects identity verification information directly. We receive transaction status and limited account details, not full card or bank numbers.

5.3 Contacts You Import

If you import contacts to invite friends to a fundraiser, we store only each contact's name, email address, and phone number, and use them solely to send the invitations you explicitly request — never for marketing to your contacts, and we do not sell or share them. Invitations identify you as the sender, are limited to one per person per fundraiser, and recipients are not added to any mailing list. If you connect a Google account, we access your Google contacts read-only, at your direction, only to populate this list; we request the minimum scope, do not store your Google credentials or access token, and use the data only as described here. You can delete your imported contacts at any time from your dashboard.

Gift of Parenthood's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data — raw, aggregated, anonymized, or derived — to create, train, or improve any generalized or foundational AI or machine learning model, and we do not transfer it to any third-party AI or ML service. See Section 4.

5.4 YouTube Channel Connection (Administrators Only)

In this subsection, "we," "us," and "our" mean Gift of Parenthood, Inc. alone. Gift of Parenthood, Inc. operates the blog described below, owns the YouTube channel, and holds the authorization granted through Google's consent screen. Give Panda, LLC does not connect the channel, does not hold that authorization, and receives no information obtained through YouTube API Services.

No visitor, donor, fundraiser organizer, or grant applicant is ever asked to connect a YouTube or Google account. This subsection describes an internal, staff-only integration. It is the only part of the Service that uses YouTube API Services to access an account, and it involves no end-user Google data of any kind. Embedded YouTube players on our blog are a separate matter and are described in Section 6.

What the integration does. Our blog at blog.giftofparenthood.org is an API Client of YouTube API Services. It uses the YouTube Data API v3 to publish our own short videos, which we publish under the Gift of Parenthood name, to our own YouTube channel. Each video post the Service prepares carries a YouTube entry, and that entry stays a draft until an administrator acts on it in our administrative interface — uploading it immediately, or setting a time for it, after which our own scheduled job performs the upload at that time. Completing a post's pre-publication checklist does not by itself book a YouTube upload. The screen that carries the upload control displays the certification YouTube requires, above that control. Because we use YouTube API Services, we are bound by the YouTube Terms of Service — on a mobile device, m.youtube.com/terms — as stated in Section 10.3 of our Terms of Service, and Google's handling of the information it receives is governed by the Google Privacy Policy.

What we access, and why. We request the minimum permissions the integration needs, and only these two OAuth scopes:

  • youtube.upload (https://www.googleapis.com/auth/youtube.upload): required by the YouTube Data API videos.insert method, which is what uploads a video to the connected channel
  • youtube.readonly (https://www.googleapis.com/auth/youtube.readonly): used for a single call, channels.list, to confirm which channel the authorization belongs to and to keep that detail current — without it a connection succeeds with no way to confirm the destination, which is how a video ends up on the wrong account. This scope grants read access to more of the channel's YouTube data than we use. We make no other read call with it, and we store only the channel's ID, display name, and handle

We request no other Google permission for this integration — no Google profile, no email address, no account identity, and no YouTube Analytics API or YouTube Reporting API access. The Google Contacts integration described in Section 5.3 is a separate application operated by Give Panda, LLC, with its own consent.

What we store, and where. When an administrator connects a channel, we store the following in a single access-controlled row of our managed PostgreSQL database (Supabase, Inc.):

  • A refresh token: the long-lived credential Google issues once per authorization. We store it because two things need it without a person present — an upload an administrator scheduled for a later time, and the weekly connection check described below, which exchanges it to re-read the channel and to notice an authorization that has been withdrawn. Unlike the Google Contacts integration in Section 5.3, we do store it
  • An access token and its expiry: the short-lived token issued alongside the refresh token, valid for about one hour. It is written once when the channel is connected and is never refreshed in place, so for most of the life of a connection it is an expired value that nothing reads; every call to Google obtains a fresh token, which is held in memory for that one request
  • The connected channel's ID, display name, and handle: read from channels.list. The handle or display name is shown on our administrative screens so staff can confirm which channel is connected; the ID is stored to identify the channel we publish to, and is not displayed
  • The video ID and link for each video we publish: recorded in our internal publishing log as a record of our own publications
  • The video ID, where staff record performance figures by hand: when staff type in figures for one of our own published videos, that video's ID is copied onto the metrics record as well as remaining on the publishing record
  • Error messages returned by the YouTube Data API: when a publish fails, the message YouTube returned — which can include the video's privacy status and its link — is stored on that failed publishing record so staff can diagnose it

What we send to YouTube. When the blog publishes, it uploads the video file we produced together with a title and description we wrote, the category "Nonprofits & Activism" (category 29), the privacy status we are asking for, and a declaration that the video is not "Made for Kids." The title and description are copy we wrote, drafted with AI-assisted editorial tools from our own published articles, and they contain no information obtained from Google or the YouTube Data API. Where a video uses a photograph supplied by a fundraiser organizer or photographer, the description carries a short photo credit naming them, exactly as it does on our other social channels; where a video is about a grant recipient, it names them on the same basis as the published announcement it is drawn from. We do not send account, donation, payment, or imported-contact information to YouTube. The video then lives on our own channel under YouTube's terms and can be removed only there.

How we use the information. The tokens are used for one purpose: authenticating our own calls to the YouTube Data API on our own channel — exchanging the refresh token for an access token, uploading a video with videos.insert, and reading channels.list to confirm the connected channel. They are used for nothing else, and they are never displayed anywhere in the Service. The channel ID, display name, and handle are used only to identify and display the connection, and are shown only to the administrators who operate it. Three things are worth naming precisely. An upload begins with an administrator acting in our administrative interface, either uploading a video or setting a time for it; where a time is set, our own scheduled job performs the upload at that time on our servers rather than at the click of a person. Opening the administrative Settings page while a channel is connected performs a token refresh and one channels.list call, so the page can report whether the connection still works. And once a week a scheduled job of ours exchanges the refresh token and reads channels.list, to keep the stored channel details current and to notice an authorization that has been withdrawn at Google.

What we do not store, and what we do not do. We never obtain, proxy, request, collect, modify, cache, store, or use YouTube account login credentials — authorization is by Google OAuth only, and no password is ever seen or held by the Service. We do not collect or store Google account email addresses or profile information, subscriber counts, viewer or audience data, comments, or watch history, and we call no YouTube Analytics API and no YouTube Reporting API. If staff record performance figures for one of our own published videos by hand from YouTube Studio, those figures are aggregate counts for our own video and are not obtained through YouTube API Services. We do not sell, rent, license, or disclose information obtained from YouTube API Services to any third party for that party's own purposes: the only parties that handle it are the vendors that run the application — Supabase, Inc. (database), Vercel, Inc. (hosting and environment secrets), and, for the link to a video we have published only, Resend (the provider that delivers our internal staff digest email) — as described in Section 5.1. We display no advertising alongside or derived from information obtained through YouTube API Services.

Limited Use. Gift of Parenthood, Inc.'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use information received from YouTube API Services only to provide and improve the publishing feature described in this subsection, which is prominent in the administrative interface where the connection is managed. We transfer it to no one except as necessary to provide that feature, for security purposes such as investigating abuse, to comply with applicable law, or as part of a merger or acquisition as described in Section 5.7. We do not sell it, use it for advertising or ad targeting, use it to determine creditworthiness or for lending purposes, or use it for any surveillance purpose. Authorization tokens are never displayed and are not read by humans except as narrowly permitted by that policy — for security purposes such as investigating abuse, or where the law requires; the connected channel's display name or handle is shown back to the administrators who authorized the connection, and to no one else. We do not use information received from Google APIs — raw, aggregated, anonymized, or derived — to create, train, or improve any generalized or foundational AI or machine learning model. See Section 4.

AI and machine learning. No authorization token, and no channel ID, display name, or handle we receive from Google, is placed in any AI prompt, sent to any AI service, or used to train, fine-tune, or improve any model. One thing we state rather than leave to inference: after a video is published, its video ID and link appear in our internal publishing records, in the internal staff digest we email to ourselves through our email provider, and in internal staff reporting tools that use AI. That identifier is the address of a video we published ourselves on our own channel; it carries no token, no channel credential, and no information about any person, and it is never used to create, train, fine-tune, or improve any model. See Section 4.

Retention. These are among the few entries in our retention schedule that are not measured in years. See Section 7.

  • Authorization tokens: kept only while the channel connection is active, and only for the purpose the administrator consented to, and deleted when the channel is disconnected or when Google reports that the authorization has been withdrawn
  • Channel ID, display name, and handle: re-read from the YouTube Data API on a weekly automated schedule, and in no case less often than every 30 calendar days; deleted when Google reports that the authorization has been withdrawn; deleted outright when the channel is disconnected
  • Video IDs and links for videos we have published: retained after a connection ends as a record of our own publications, including any copy held on a hand-entered metrics record — disconnecting does not delete them, and nothing we delete removes a video from YouTube. They are deleted on request as described below, and we delete them if we stop using YouTube API Services
  • On termination: if we stop using YouTube API Services, or our access is terminated, we will stop accessing YouTube properties and delete all data obtained through YouTube API Services that is in our possession or control, including from our servers

Disconnecting withdraws the authorization at Google and deletes our copy, in one step. An administrator can do it at any time from the administrative Settings page, and it does not depend on finding the authorization anywhere in Google's own account settings.

  • What it does: the Service asks Google to revoke the credential, and then deletes the stored record outright — refresh token, access token, expiry, channel ID, display name, and handle are removed together in a single operation, immediately and in every case within 7 calendar days of the disconnection. A revoked authorization stops working for us at once and cannot be renewed; connecting again requires a new consent
  • If Google cannot be reached: we still delete our copy, and the Service reports that the withdrawal was not confirmed rather than reporting success — the authorization may then still be active, and we no longer hold the credential needed to withdraw it ourselves. Email support@giftofparenthood.org and we will see it through
  • Withdrawing it from Google's side instead: where a Google Account lists an authorization, it can be removed from the connected-apps list at myaccount.google.com/permissions. Our channel is held through a Google Brand Account, and we have not found this authorization listed there, in the personal accounts that manage the channel, or in YouTube Studio — which is why the Service revokes it directly rather than relying on that page. However a withdrawal happens, our weekly connection check deletes the stored record in the same run once Google reports it, and in every case we delete everything we obtained under that authorization within 30 calendar days of the revocation

Disconnecting does not remove videos we have already published; those are removed from the channel in YouTube Studio.

Requesting deletion. If we hold information obtained through YouTube API Services that relates to you, or you are an administrator whose authorization we hold, you may ask us to delete it by emailing support@giftofparenthood.org with "YouTube" in the subject line. After we verify the request as described in Section 8, we delete that information as soon as possible and in every case within 7 calendar days of the request, unless the law requires us to retain it, in which case we will tell you. This 7-day commitment applies specifically to information obtained through YouTube API Services and is shorter than the general response timeline described in Section 8.

Security. The routes that connect, complete, and disconnect this integration are reachable only by a signed-in administrator. The stored credential is read in four places, all of them ours. The administrative Settings page exchanges the refresh token for a fresh access token when an administrator opens it, so the page can report whether the connection still works; that page is reachable only by a signed-in administrator. Our publishing job performs an upload at the time an administrator set for it. Our weekly connection check re-reads the channel. And disconnecting reads the refresh token in order to revoke it at Google before the record is deleted. The two jobs run on our servers and are authenticated by a secret key. No page of the public website reads the credential, and it is never displayed anywhere in the Service. Traffic to Google and to our database travels over TLS. The stored row lives in our managed PostgreSQL database, which encrypts data at rest at the storage layer; we do not apply an additional layer of application-level encryption to those columns, and access is limited to the application's own server-side credentials and to staff with an administrator role. Our Google OAuth client ID and client secret are held as environment variables at Vercel, Inc. and appear neither in our application code nor in our source repository. Section 9 describes our general security practices.

One channel at a time, and future changes. The Service holds one channel connection at a time. Connecting a different channel replaces the one connected before it. If Google completes an authorization without issuing the long-lived credential we need, we refuse to store the partial result and ask the administrator to withdraw the existing authorization, as described above, before connecting again. Our configuration currently records Google's review of our API access as outstanding, and while it does, the Service asks YouTube to upload every video with a private privacy status, visible only to the channel owner. YouTube locks a video uploaded before that review is complete to private permanently: it cannot afterwards be made public, by us or by the channel owner, even once the review has passed, and the only remedy is to upload the video again from a reviewed client. Our administrative upload screen states this whenever it applies. If we ever request additional permissions, store information obtained through YouTube API Services beyond what is listed above, or use that information for a purpose not described here, we will update this policy and obtain a new authorization through Google's consent screen before doing so.

Questions. Questions or complaints about this integration, including about how we handle information obtained through YouTube API Services, go to support@giftofparenthood.org or to Gift of Parenthood, Inc. at the address in Section 14. Administrators can disconnect the channel at any time from the administrative Settings page, which withdraws the authorization at Google and deletes every credential and channel detail we hold.

5.5 Other Users and the Public

If you organize a fundraiser, your campaign content (story, photos, fundraising progress, organizer name) is publicly visible. If you accept a grant, you may be featured in Gift of Parenthood, Inc.'s communications under its Materials Release Agreement, with the privacy choices described there.

5.6 Legal and Safety

We may disclose information when we believe in good faith it is necessary to:

  • Comply with applicable law, legal process, or government requests
  • Enforce our Terms of Service or other agreements
  • Detect, prevent, or address fraud, security, or technical issues
  • Protect the rights, property, or safety of Give Panda, Gift of Parenthood, our users, or others

For requests related to reproductive healthcare, gender-affirming care, or other sensitive matters, we will scrutinize the legal basis carefully and require valid legal process where the law permits.

5.7 Business Transfers

If we are involved in a merger, acquisition, financing, sale of assets, dissolution, or similar transaction, information may be transferred as part of that transaction, subject to the receiving party honoring this Privacy Policy or providing equivalent protection.

5.8 With Your Direction or Consent

We share information for any other purpose disclosed to you at the time of collection or with your consent.

5.9 What We Do Not Do

We do not sell consumer health data. We do not share consumer health data for cross-context behavioral advertising. We do not use precise geolocation to track you near healthcare facilities, and we do not engage in geofencing of any healthcare facility.

6. Cookies and Tracking Technologies

We use cookies, pixels, web beacons, and similar technologies to operate the Service, remember your preferences, measure usage, and (where permitted) personalize content. Categories include:

  • Strictly necessary: needed for the Service to function (always on)
  • Functional: remember your preferences and improve experience
  • Analytics: help us understand usage patterns
  • Advertising: where used, deliver relevant content (you can opt out)

You can block or delete cookies through your browser settings, and most browsers let you do so by category. We do not present a cookie consent banner on give.giftofparenthood.org or blog.giftofparenthood.org: the analytics and tag-management technologies described above load when you visit the public pages of those sites, and we do not distinguish by location before they load. If you do not want them, block or clear cookies for those sites in your browser. See our Cookie Policy for more detail.

Embedded YouTube videos. Articles on our blog may embed a video using YouTube's standard embedded player, served from youtube.com. When you load a page containing one, your browser contacts Google directly, and Google may set cookies and collect information such as your IP address, device information, and your interactions with the player, under the Google Privacy Policy; your use of the player is subject to the YouTube Terms of Service — on a mobile device, m.youtube.com/terms. We do not receive that information. Videos played in the embedded player may include advertising served by YouTube, which we do not control. You can block or delete these cookies through your browser settings, as described in our Cookie Policy. Google's EU User Consent Policy applies to our use of Google services for users in the European Union. This is separate from the administrator-only channel connection described in Section 5.4, which involves no visitor data.

7. Data Retention

We keep information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. General retention guidelines:

  • Account information: while your account is active, plus a reasonable period after closure for fraud prevention, legal, and tax recordkeeping
  • Donation records: at least seven years for tax and audit purposes
  • Fundraiser records: while the fundraiser is active, plus a reasonable period for payout reconciliation, tax recordkeeping, and dispute resolution
  • Grant application records: applicant case files retained per IRS Publication 4221-PC requirements (typically at least seven years)
  • Communications: typically two to three years
  • Aggregated or de-identified data: may be retained indefinitely

You may request deletion as described in Section 8. Some information may be retained longer where required by law, for legitimate business purposes, or where deletion is technically infeasible (in which case we isolate and protect it).

8. Your Rights and Choices

Your rights depend on where you live. We honor the rights described below regardless of jurisdiction where reasonably possible.

8.1 Rights Available to U.S. Residents

If you are a U.S. resident, you may have the following rights, depending on your state of residence (including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Florida, Delaware, New Jersey, New Hampshire, Kentucky, Maryland, Minnesota, Rhode Island, and others):

  • Right to know / access: confirm whether we process your information and obtain a copy
  • Right to correct: ask us to fix inaccurate information
  • Right to delete: request deletion of your information
  • Right to portability: receive a copy in a portable format
  • Right to opt out of sale or sharing for cross-context behavioral advertising: we do not sell information for money, but some sharing for analytics or advertising may qualify. We do not currently detect an automated opt-out preference signal such as Global Privacy Control; to opt out, email support@giftofparenthood.org with "Opt out of sharing" in the subject line and we will process the request manually and confirm when it is complete
  • Right to opt out of profiling that produces legal or similarly significant effects: we do not currently engage in this kind of profiling for grant decisions, as described in Section 4
  • Right to limit use of sensitive information
  • Right to non-discrimination for exercising these rights
  • Right to appeal a denied request (where required by your state)

To exercise these rights, email support@giftofparenthood.org with your name, email associated with your account (if applicable), state of residence, and the specific request. We will verify your identity through reasonable means and respond within the timeframe required by your state's law (typically 45 days, with possible extension).

8.2 California Residents

In addition to the rights above, California residents have rights under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), including the rights to know specific categories and sources of personal information, the purposes of collection, the categories of third parties with whom we share, and to direct us to limit use of sensitive personal information. California minors aged 13 to 17 have specific rights regarding the removal of content they posted (Cal. Bus. & Prof. Code § 22581).

8.3 Washington, Nevada, and Connecticut Consumer Health Data

If you are a resident of Washington, Nevada, or Connecticut, you have additional rights with respect to your "consumer health data," including:

  • Right to confirm whether we are collecting, sharing, or selling your consumer health data and to access that data
  • Right to withdraw consent to our collection and sharing of consumer health data
  • Right to deletion of consumer health data, including from any of our service providers and processors
  • Right to a complete list of all third parties and affiliates with whom we have shared or to whom we have sold your consumer health data, along with active contact information

We do not sell consumer health data, and we do not share consumer health data for cross-context behavioral advertising. To exercise these rights, contact support@giftofparenthood.org. We will respond within the timeframes required by applicable law, including a right to appeal under Washington's My Health My Data Act.

8.4 European Economic Area, United Kingdom, and Switzerland

If you are in the EEA, UK, or Switzerland, our processing is subject to the General Data Protection Regulation (GDPR) or its UK equivalent. Our lawful bases for processing include:

  • Consent: where you have given us consent (you can withdraw at any time)
  • Contract performance: where processing is necessary to provide the Service you requested
  • Legitimate interests: such as operating the Service, preventing fraud, communicating with donors and applicants
  • Legal obligation: where required by law
  • Vital interests in narrow circumstances

You have rights to access, rectification, erasure, restriction of processing, data portability, objection, and to lodge a complaint with your supervisory authority. Information you provide is transferred to and processed in the United States, and we rely on appropriate safeguards (such as Standard Contractual Clauses) where required.

8.5 Canada

If you are in Canada, our processing is subject to applicable Canadian privacy laws, including PIPEDA and provincial laws (such as Quebec's Law 25). You have rights to access and correct your information and to withdraw consent. Contact us at support@giftofparenthood.org.

8.6 Marketing Communications

You can opt out of marketing emails by clicking the unsubscribe link in any email or contacting us. You may continue to receive transactional and account-related communications.

8.7 Authorized Agents

You may designate an authorized agent to make a request on your behalf where state law allows. We will require reasonable verification of the agent's authority and your identity.

8.8 Text Messages (SMS)

If you turn on the guided journey, you can give us a mobile number and agree to receive text messages about your own fundraiser. We text only you, at the number you gave us, and only after you have ticked the consent box and replied YES to a confirmation text.

What we send. Messages about your fundraiser: when someone gives, when a step of your journey is funded, a draft update or thank-you for you to approve, and reminders about something you have not answered yet. We never text your friends, family, donors, or contacts. Messages you choose to send to them go from your own phone.

How often. About 2 to 4 texts a week while a phase of your journey is active, fewer between phases, and none while you have paused. Message and data rates may apply.

How to stop. Reply STOP to any message to end texts at any time, or turn texts off from your dashboard. Reply HELP for help, or email support@giftofparenthood.org. Stopping texts does not affect your fundraiser or your account.

Your mobile information is not shared. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with our messaging service provider, who delivers the messages on our behalf and may not use your information for any other purpose.

What we keep. The number you gave, the consent wording you agreed to, the date, time, and IP address of your consent, your confirmation and any STOP, and a log of messages sent and received, so we can honor your choices and prove that we did.

9. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, and destruction. Safeguards include encryption in transit, access controls, vendor security review, and employee training. No system is perfectly secure, and we cannot guarantee that information will never be compromised. If we experience a data breach affecting your information, we will notify you and applicable regulators as required by law, including under the FTC Health Breach Notification Rule where it applies.

10. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13 without verifiable parental consent, we will delete it. Parents or guardians who believe their child has provided information to us can contact us at support@giftofparenthood.org.

For users aged 13 to 17, we follow age-appropriate practices and provide California minors the rights described above. If you are under 18 and believe your information should be removed, please contact us.

11. International Data Transfers

We are based in the United States, and information you provide is processed in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses).

12. Third-Party Sites and Services

The Service may contain links to or integrations with third-party websites and services we do not control. Their privacy practices are governed by their own policies, which we encourage you to review.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (where we have your address) or by prominent notice on the Service before the changes take effect, and we will update the "Last Updated" date at the top. Your continued use of the Service after changes take effect means you accept the updated policy.

14. Contact Us

If you have questions or want to exercise any rights described in this policy:

Give Panda, LLC Attn: Privacy 150 E B St, Lobby #1810, SMB #24817 Casper, WY 82601 United States Email: support@giftofparenthood.org

For matters concerning the charitable grant program, you may also contact Gift of Parenthood, Inc. For media or other inquiries, please use the contact form on our website.