Corporate Giving HubPrivacy notice

Privacy notice

How Corporate Giving Hub treats your data, in plain language. What we collect, who can see your volunteer activity, and how to export or delete everything.

Last updated

Section 1

What we collect

This is a list rather than a sentence, because a sentence is where an incomplete list hides. Everything below is something the platform actually stores about you.

  • Your account: your name and email address, and your phone number if you sign in with a code sent by text. Signing in with Google, Microsoft or Apple also gives us the name and profile photo held by that provider; there is nowhere here to upload one yourself.
  • Your profile: the username you choose, a home address if you add one (street, city, region, postal code, country), and the causes, skills and availability you want to be matched on. We also keep the language you read the site in, your time zone, and whether you accepted analytics and marketing when you were asked.
  • The volunteer activity you log: sessions, hours, dates, the organizations and places you served, what you did, what it achieved, the skills you used, how many people you helped, any photos you attach and whether you allowed one to be featured, the charity’s registration number and what our lookup said about it, and your answers to any extra questions your employer added to the form.
  • Who you volunteered with: the colleagues you credit on a session, and the family and friends you describe in the platform. A family profile you create holds that person’s name and, if you fill them in, their relationship to you, their age or year of birth, gender, nationality, city, country and any note you write.
  • Your circle: who you are connected to, requests you have sent or received, and any note attached to a request.
  • If you join your employer’s organization: the workplace attributes held for reporting, which are department, job title, business region, cost centre, city, country, any role label your employer defines, the employee reference their systems use for you, whether you asked to be left off leaderboards, and whether your membership is active or has been off-boarded. Some of these come from your employer and some you set yourself.
  • Your program record: messages between you and your organization’s admins, notes those admins write about you internally that you never see, notifications and announcements sent to you, awards you reach, and any employer matching you request, which records the amount, the charity, its registration number and address, and the decision.
  • Your devices and your account history: a subscription per browser you turn push notifications on in, which holds the address your browser gives us for delivery, the keys that encrypt the message, a device label taken from your browser (“Chrome · macOS”), and when it was added and last used. We also keep an audit record of sign-ins and account changes, which your organization’s admins can read for actions inside their organization.

Section 2

Who can see your volunteer activity

Volunteering through your employer’s program is a shared record by design. Hours you log to an organization are visible to that organization’s admins, appear in its rollups and reports, and may be exported by them. Messages you exchange with your org’s admins are visible to that org’s admin team. Your personal impact page is yours; organization dashboards show your name, hours, and recognition to your program’s admins.

Separately from your employer, you can build a personal circle in Family and friends by sending friend requests and accepting the ones sent to you. Everyone in your circle sees your total volunteer hours and your recent personal sessions, including the organization, the city, the date and the length of each. Hours you log into an employer’s program are not part of this unless you switch it on in Family and friends, and when you do they count toward your hours total only: the organization, the event and the date stay inside the program. A circle is mutual, and removing someone ends what they can see about you.

Section 3

What we don't do

  • We don’t sell your data, ever.
  • We don’t show ads. There are none.
  • We don’t use your data to train AI models.
  • We don’t share your volunteer activity with anyone beyond your organization’s program and the circle you build yourself.

Section 4

Employer-connected apps

Some employers connect their own workplace app to Corporate Giving Hub through our partner API. In that case, hours you submit in the employer’s app flow into your organization’s approval queue here, and approval decisions and admin messages flow back to the employer’s app. The employer’s own privacy policy governs what happens inside their app.

Section 5

Your rights

You can export your data, correct any field, or request deletion. A deletion request opens a 30-day window in which nothing is erased and you can change your mind and cancel from your profile. Your account is erased at the end of that window rather than at some point inside it, by a job that runs once a night. Email privacy@corporategivinghub.com.

Erasure removes your profile, your sign-in identity, your volunteer sessions and the hours your employer holds against your name, your photos, your messages, and your personal circle. Where you appear on a record that belongs to somebody else, your name comes off it instead of the record being destroyed: a place you added to your organization’s directory stays in the directory, and hours you approved as an admin stay approved, with nobody attached. One record is kept on purpose. The log entry showing that you asked for deletion and that we carried it out survives, because it is how we can show the request was honoured, and it is never shown to your employer.

If you own an organization on the Hub, we cannot erase your account while you hold it: an organization has one owner, and removing them would leave its members and its volunteer history with nobody able to administer them. We tell you that when you ask, rather than accepting the request and not acting on it. Transfer ownership to another admin in the organization’s settings, then ask again. Ownership moves the moment you confirm it, with nothing for the other person to accept. You stay on as an admin afterwards, which does not hold an erasure up. If nobody else is an admin, make somebody one first, and if you are the only person left in the organization, delete it in those same settings instead.

Section 6

Where data lives

Data is encrypted in transit (TLS) and at rest by our infrastructure vendors. The application runs on Vercel and Fly.io; the database is Neon (Postgres); sign-in is handled by Supabase Auth; photos and media live in Cloudflare R2; transactional email is sent by Resend; SMS codes by Twilio, the provider configured in Supabase Auth; and maps and address lookup use Google Maps Platform alongside the public map services described below. We also send crash and error diagnostics to Sentry, product analytics to PostHog, and page performance measurements to Vercel Analytics and Vercel Speed Insights. PostHog receives events from our servers only; there is no PostHog code in your browser. Each processes data only to provide their service to us.

Maps work differently from everything above, and the difference is worth stating plainly. When a map appears on a page, your browser fetches the map tiles directly from whoever serves them, so your IP address, your browser’s user agent and the coordinates of the tiles you request reach that service, and those coordinates show roughly which part of the world you are looking at. The impact, team and organization maps take their tiles from Google when a browser Maps key is configured, and from OpenStreetMap’s tile servers when it is not, or when the Google map fails to load. Your organization’s impact atlas always takes its tiles from CARTO and has no Google path at all.

Address lookup runs the other way round. It happens on our servers rather than in your browser, so what is sent is the place name being resolved, not your IP address or anything about your browser. It goes to Google Maps Platform when a server key is configured and to OpenStreetMap’s Nominatim service when it is not. OpenStreetMap and CARTO are public services we use on their published terms: we have no contract with either, they are not processors acting on our instructions, and what reaches them is handled under their own policies rather than under an agreement with us.

Corporate Giving Hub is operated from the United States: our API runs in Fly.io’s US East region. If you use the platform from outside the United States, including from the EU or the UK, your personal data is transferred to the United States to run the service.

Section 7

Children

Corporate Giving Hub is for adults and working-age volunteers. Creating an account requires you to confirm that you are at least 13. We ask rather than verify: there is no date of birth behind that confirmation, because we do not collect one. Family volunteering features are intended to be used under an adult’s account.

Section 8

Changes

Changes are published here, and the date at the top of this page moves whenever the text does. A meaningful change goes up at least 14 days before it takes effect. There is no policy mailing list, so this page is where a change is announced rather than your inbox.