GIVELY

GivelyCF Privacy Policy

Proposed website policy · Canada-first platform

Accountable organization: Gively Crowdfunding & Digital Finance Inc.

Platform: www.givelycf.com

Related service: GivelyDF donor recognition and GLT administration

Version: Draft 2.0 • 30 July 2026

Date of posting: 30 July 2026

Status: FOR CANADIAN PRIVACY AND REGULATORY REVIEW

Publication warning. This draft must be reconciled with Gively’s actual data map, vendors, hosting locations, cookie deployment, retention schedule, security controls and GivelyCF–GivelyDF account architecture before publication. It is not legal advice.

Privacy at a glance

Our approach. Gively collects only the personal information reasonably needed to operate and secure its fundraising, donation, verification, receipting and donor-recognition services. We do not sell personal information. We use service providers where necessary, remain accountable for information under our control, and provide choices where processing is optional.

  • Donors: we use identity, contact, donation and receipt information to process and document giving, prevent fraud and, if selected, administer GLT through GivelyDF.
  • Organizations and organizers: we use representative, authority, registration, banking-verification and campaign information to activate accounts, remit funds and meet legal and risk requirements.
  • Payments: payment-card and banking credentials are generally collected and processed by specialized providers. Gively should not receive or store complete card numbers or online-banking credentials unless its approved architecture expressly requires it.
  • Public pages: campaign content, organizer names, charity details, supporter names and messages may be public when the user submits them for publication. Anonymous giving hides the donor from the public page, not necessarily from Gively, processors or the recipient.
  • Your choices: you may manage marketing preferences, cookie choices and public-display settings, and may request access to or correction of personal information, subject to applicable law.

Contents

  • 1. Scope and accountable organization
  • 2. Personal information we collect
  • 3. How we collect information
  • 4. Why we use personal information
  • 5. Consent and other lawful authority
  • 6. Donations, receipts and recipients
  • 7. Organization and organizer verification
  • 8. GivelyDF, GLT and giving records
  • 9. Public content and social features
  • 10. Cookies, analytics and similar technologies
  • 11. Marketing and service communications
  • 12. When we disclose information
  • 13. Service providers and cross-border processing
  • 14. Retention and disposal
  • 15. Safeguards and security incidents
  • 16. Your privacy rights and choices
  • 17. Children and young people
  • 18. Third-party services
  • 19. Changes to this Policy
  • 20. Contact and complaints
  • Schedule A — Launch decisions requiring confirmation
  • Schedule B — Privacy sources and drafting notes

1. Scope and accountable organization

This Privacy Policy explains how Gively Crowdfunding & Digital Finance Inc. (“Gively,” “we,” “us” or “our”) collects, uses, discloses, retains and protects personal information when individuals visit or use www.givelycf.com, related applications, dashboards and services that link to this Policy (collectively, “GivelyCF” or the “Platform”). It also explains relevant information flows to GivelyDF when a donor elects or administers Gively Love Token (“GLT”), recognition levels or a Lifetime Impact Certificate.

Gively is accountable for personal information under its control and will designate a Privacy Officer responsible for its privacy program. This Policy should be read with the GivelyCF Terms of Use, cookie choices, checkout notices, campaign disclosures and any feature-specific privacy notice.

This Policy applies to donors, visitors, account holders, charity and nonprofit representatives, organizers, beneficiaries, subscribers, prospective customers and other people whose personal information Gively handles. It does not govern the independent privacy practices of a recipient charity, organizer, payment provider, identity-verification provider, social network or other third party.

“Personal information” means information about an identifiable individual, including information that can reasonably be linked to that individual. It does not ordinarily include business contact information used solely to communicate in relation to employment, business or professional responsibilities where applicable law excludes it.

2. Personal information we collect

The information collected depends on how a person interacts with Gively. We seek to limit collection to what is reasonably necessary for identified purposes.

2.1 Identity, contact and account information
  • Name, username, postal address, email address, telephone number, language and communication preferences.
  • Account identifiers, password hash, authentication status, sign-in history, security settings and account-recovery information.
  • Age or age-range information where needed to assess eligibility or obtain appropriate consent.
2.2 Donation, transaction and receipt information
  • Donation amount, currency, date, recipient, campaign, frequency, status, transaction reference and refund or chargeback information.
  • Donor name, address and other details required for an official charitable donation receipt or a non-tax receipt.
  • The donor’s choice between an official tax receipt, where available, and GLT with a non-tax receipt under the approved product design.
  • Public-display choice, supporter message, dedication, tribute or other information the donor submits.
  • Limited payment information and payment status returned by a processor, such as payment method type, last digits, token or risk result. Full card numbers and online-banking credentials should ordinarily remain with the specialized provider.
2.3 Organization, organizer and beneficiary information
  • Legal name, registration or business number, jurisdiction, address, website, organization type and public registry information.
  • Representative’s name, position, business contact details, authorization certification, electronic signature, identity-verification results and supporting authority records.
  • Bank-account ownership or verification status, payout instructions and related processor references.
  • Campaign title, description, images, video, beneficiary information, intended use of funds, updates, evidence and complaints.
  • For personal causes, information reasonably required to verify the organizer, beneficiary, relationship, need and lawful purpose. Such submissions may include sensitive financial, family, health or hardship information; users should provide only what is necessary.
2.4 GLT and donor-recognition information
  • Eligible verified giving history, GLT earned, adjustments, reversals, recognition level and reward or experience eligibility.
  • Lifetime Impact Certificate details and verification code or QR identifier.
  • Evidence submitted to verify giving that did not originate on GivelyCF, if this feature is offered.
2.5 Technical, usage and communications information
  • IP address, browser, device, operating system, language, pages viewed, referring URL, timestamps, cookie or similar identifiers, approximate location and interaction events.
  • Support requests, complaints, survey responses, call or correspondence records and information provided in communications.
  • Fraud, security, sanctions, device-risk and transaction-monitoring signals generated by Gively or its providers.

3. How we collect information

We collect personal information directly from individuals when they create an account, donate, subscribe, activate an organization, create or administer a campaign, submit verification records, elect GLT, contact support, complete a form or otherwise use the Platform.

We may also receive information from an authorized organization administrator or organizer; a donor or beneficiary; payment, banking, identity and fraud-prevention providers; public charity or corporate registries; professional advisers; referral sources; GivelyDF; and other persons who are authorized or permitted by law to provide it.

We collect technical and usage information automatically through server logs, cookies, software development kits, pixels and similar technologies, subject to the choices and consent described in section 10.

If a person provides information about another individual, the provider must have authority to do so and must give any notice or obtain any consent required by law. Gively may ask for evidence of that authority.

3.1 Integrations and partner-originated information

If Gively offers an approved integration with a charity, fundraising service or other third party, Gively may receive the donation and account information described at the point of connection. The organization that originally collects the information remains responsible for its own collection, notices and disclosures, while Gively is responsible for information under its control.

Gively will not activate a data integration or partner flow merely because it is technically possible. The parties must first define their respective roles, the information exchanged, the purposes, retention, security, user notice and any consent required by law.

4. Why we use personal information

Gively may use personal information for the following identified purposes:

  • Create, authenticate, administer and secure accounts.
  • Process donations, recurring donations, subscriptions, fees, refunds, disputes, chargebacks, holds and remittances.
  • Verify organizations, representatives, organizers, beneficiaries, authority, registration and banking arrangements.
  • Prepare, facilitate and deliver official donation receipts on a participating charity’s behalf, and issue or deliver non-tax receipts.
  • Operate campaigns, dashboards, analytics, customer support and Fundraising Infrastructure as a Service (“FIaaS”).
  • Link eligible verified giving to GivelyDF; calculate, issue, correct and reverse GLT; administer recognition levels, certificates and eligible privileges.
  • Detect, investigate and prevent fraud, abuse, account takeover, money laundering, sanctions violations, illegal activity and violations of Platform terms.
  • Respond to support requests, complaints, legal demands, audits, disputes and regulatory obligations.
  • Maintain records, reconcile funds, perform accounting, tax, risk, security, governance and internal-control activities.
  • Measure service performance, troubleshoot, research and improve functionality using information appropriate for those purposes.
  • Send necessary service, account, security, donation, campaign, receipt and policy communications.
  • Send marketing or fundraising-related communications where Gively has the consent or other authority required by law.
  • Establish, exercise or defend legal claims, protect users and the public, and support a corporate transaction subject to appropriate safeguards.

Gively will not use personal information for a materially new purpose without providing additional notice and obtaining consent where required, unless the new use is otherwise permitted or required by law.

5. Consent and other lawful authority

Gively seeks meaningful consent by explaining, in understandable language, the personal information involved, the purposes, the parties to whom it may be disclosed, and the reasonably foreseeable consequences. Important choices should be presented at the relevant point of collection rather than relying only on this Policy.

Consent may be express or implied depending on the sensitivity of the information, the reasonable expectations of the individual and legal requirements. Express consent should be used for sensitive or unexpected processing, optional marketing, non-essential tracking and GivelyCF–GivelyDF linking where required.

Certain collection, use or disclosure is necessary to provide a requested service. For example, Gively cannot process a donation without transaction information or activate an organization without authority and payout verification. If an individual withdraws consent for required processing, Gively may be unable to continue the relevant service.

An individual may withdraw consent for future processing, subject to reasonable notice and legal or contractual restrictions. Withdrawal does not invalidate processing that was lawful before withdrawal and does not require Gively to delete records it must retain.

Gively may collect, use or disclose information without consent where applicable law authorizes or requires it, including for certain investigations, fraud prevention, emergencies, legal proceedings, debt collection, business transactions or compliance purposes.

6. Donations, receipts and recipients

To process a donation, Gively and its providers use transaction, contact and risk information. Information necessary to administer and acknowledge a donation may be provided to the recipient charity or organization. A participating registered charity may also receive information needed to authorize, issue, correct and maintain an official receipt.

A recipient may receive the donor’s name, contact details, donation amount, date, campaign, receipt status, public-display preference and message, to the extent reasonably necessary and disclosed at checkout. Gively should provide a clear checkout notice identifying the recipient and the information it will receive.

Choosing “anonymous” or a similar option generally hides the donor’s identity from the public campaign page. It does not make the transaction anonymous to Gively, its payment and compliance providers, the recipient where administration or law requires disclosure, or authorities with lawful access.

Recipient organizations and organizers are independently responsible for personal information they receive and must use it only for donation administration, acknowledgements, reporting and other disclosed lawful purposes. They must not sell donor information or use it for unrelated marketing without valid consent.

Donors should avoid including sensitive information in public supporter messages, dedications or tributes. A donor who provides another person’s name or story must have authority to do so.

7. Organization and organizer verification

Gively may verify identity, authority, registration, contact information, banking arrangements, campaign purpose and beneficiary information directly or through specialized providers. Providers may ask an individual to submit government-issued identification, a selfie or liveness check, corporate records, bank ownership information or other evidence.

Gively should receive only the verification information reasonably needed for its role, such as verification status, matched attributes, risk flags and provider reference, unless full documentation is required for law, investigation or enhanced review. Any use of biometric information must be specifically assessed, disclosed and consented to where required before launch.

Verification information is used to prevent unauthorized profile claims, fraudulent campaigns and misdirected payouts, and to meet payment, sanctions, anti-money-laundering and other applicable requirements. Verification does not constitute Gively’s endorsement or guarantee.

Public registries may be used to pre-list or verify organizations. Public availability does not remove Gively’s obligation to use the information only for appropriate purposes.

8. GivelyDF, GLT and giving records

When an eligible donor selects GLT, claims a reward, accesses a Lifetime Impact Certificate or otherwise uses GivelyDF, GivelyCF may disclose to GivelyDF the account identifier, verified donation amount and date, recipient, transaction status, GLT election, refund or chargeback status and other information needed to administer GLT and recognition.

GivelyDF may return GLT balance, recognition level, certificate status, redemption or privilege activity, corrections and security or fraud signals to GivelyCF where needed to provide a connected account experience, support the user, reconcile records or enforce applicable terms.

Under the approved current model, GLT is calculated at 1 GLT for each complete C$25 of eligible verified donations. Gively maintains an auditable link between GLT and the underlying donation and reverses associated GLT after a refund or chargeback. These records may need to be retained for reconciliation, fraud prevention, complaints and legal obligations.

Gively must implement clear just-in-time notice and any required consent before linking CF and DF accounts. If GivelyCF and GivelyDF are operated by the same corporation, Gively remains accountable for both environments; if that structure changes, this Policy must be updated.

9. Public content and social features

Charity profiles, registration details, campaign pages, organizer identity, campaign content, updates, images, videos, funding progress and selected supporter content may be visible publicly and indexed by search engines. Public content may be copied or reshared by others beyond Gively’s control.

Before publication, the Platform should clearly identify which fields are public. Users must not publish unnecessary identity documents, banking details, full addresses, medical records, information about children or other sensitive information.

If a user deletes or changes public content, cached or reshared copies may remain temporarily or may be retained where required for evidence, complaints, fraud prevention or law. Gively may preserve a non-public record of removed content.

Social-sharing buttons or embedded services may allow the third-party provider to collect information about a user’s visit. Their privacy policies apply to their independent collection.

9.1 Platform integrity and moderation

Gively may review, restrict, preserve or disclose user content and related account or transaction information where reasonably necessary to operate the Platform, investigate complaints, enforce Platform terms, protect users, prevent fraud or misuse, respond to safety concerns, or comply with law. Review may be performed by authorized personnel or service providers subject to appropriate confidentiality and access controls.

Gively does not undertake to monitor every fundraiser, message or item of content. Any moderation practice that uses automated profiling or produces a significant decision about an individual must be separately assessed and disclosed as required by applicable law.

10. Cookies, analytics and similar technologies

Gively may use cookies and similar technologies to operate sign-in and security functions, remember preferences, maintain sessions, measure performance, understand use, prevent fraud and, if approved and consented to, support advertising or campaign attribution.

Strictly necessary technologies are used to provide requested functionality and security and may not be available for rejection where they are essential. Analytics, personalization, advertising and other non-essential technologies should remain disabled until the user makes the required choice.

A cookie banner or preference centre should identify deployed categories, purposes, providers and durations, and allow users to withdraw or change optional choices as easily as they gave them. Browser controls may also limit cookies, but blocking essential technologies can affect functionality.

Gively should not use sensitive donation, hardship, health, beneficiary or GLT information for cross-context behavioural advertising. No advertising or tracking claim should be published until the implemented tags and software development kits have been audited.

The final website should include a cookie notice or preference centre maintained consistently with this Policy.

11. Marketing and service communications

Gively may send transactional communications necessary to administer accounts, donations, receipts, security, campaigns, subscriptions, complaints, GLT and policy changes. These are not treated as optional marketing where the message is genuinely necessary for the service.

Marketing and promotional electronic messages will be sent only with the consent or other authority required by applicable law. Such messages will identify the sender, provide required contact information and include a working unsubscribe mechanism.

Unsubscribing from marketing does not prevent necessary service communications. Gively will maintain records of consent and unsubscribe choices and will apply requests within the period required by law.

A recipient charity or organizer may send its own communications only in accordance with its own legal obligations and the donor’s choices. Consent to receive Gively marketing is not automatically consent to receive unrelated marketing from a recipient, and vice versa.

12. When we disclose information

Gively may disclose personal information only as reasonably necessary for identified purposes, with consent where required, or as permitted or required by law. Potential recipients include:

  • Recipient charities, nonprofits, organizers and beneficiaries for donation, campaign, acknowledgement, receipt and reporting purposes.
  • Payment processors, banks, payout providers and financial-connection providers.
  • Identity, authority, sanctions, fraud, security and banking-verification providers.
  • Hosting, cloud, content-delivery, email, SMS, customer-support, analytics, accounting, CRM and other technology providers.
  • GivelyDF and reward or experience providers where a user selects the connected service and disclosure is necessary.
  • Professional advisers, auditors, insurers, financing parties and contractors subject to appropriate duties.
  • Regulators, courts, law-enforcement bodies, tax authorities or other persons where disclosure is legally required or permitted.
  • A prospective or completed purchaser, investor, lender, successor or transaction party in a financing, reorganization, merger, acquisition or sale, subject to applicable safeguards and use limitations.

Gively does not sell personal information for money and does not permit service providers to use personal information for their own unrelated purposes. Gively does not rent or trade donor lists. If Gively later introduces a practice that applicable law treats as a sale or sharing for targeted advertising, it will update this Policy and provide required notice and choices before doing so.

13. Service providers and cross-border processing

Gively uses service providers to perform functions on its behalf. Gively remains accountable for personal information transferred to a provider for processing while it remains under Gively’s control and uses contractual and other measures appropriate to the sensitivity and risk.

Providers may process or store information outside the individual’s province or outside Canada. Information in another jurisdiction may be subject to that jurisdiction’s laws and may be accessible to courts, law-enforcement or national-security authorities in accordance with those laws.

The final Policy should identify material processing countries or regions once Gively completes its data map and vendor review. Individuals may contact the Privacy Officer for information about service-provider processing and safeguards.

Some third parties, such as recipient charities or independent payment services offered directly to users, may act independently rather than solely as Gively’s processors. Their own privacy notices govern their independent handling.

14. Retention and disposal

Gively retains personal information only as long as reasonably necessary for the identified purposes and legal requirements. The applicable period depends on the type of information, the duration of the relationship, transaction and receipt obligations, charity and accounting records, anti-fraud needs, disputes, limitation periods, security requirements and regulatory directions.

When information is no longer required, Gively will securely delete, destroy or anonymize it, subject to backup cycles and legal holds. Anonymized or aggregated information that no longer identifies an individual may be retained and used for legitimate business, risk, research and reporting purposes.

Closing an account does not require immediate deletion of donation, receipt, payment, GLT, complaint, fraud or legal records that Gively must or reasonably needs to retain. Public content may be removed from active display while a limited non-public record remains.

Before publication, Gively must approve a record-specific retention schedule. The following table states proposed criteria and must not be represented as implemented until validated.

Record categoryProposed retention approach
Account and profileActive relationship, then a defined closure period subject to legal, security and dispute needs.
Donation, payment, remittance and receiptPeriod required for tax, charity, accounting, payment, audit, dispute and anti-fraud obligations.
Verification and authorityOnly as long as necessary for eligibility, re-verification, legal duties, investigations and limitation periods; minimize raw identity documents.
Campaign and public contentWhile active and for a defined archival, complaint, fraud and evidentiary period afterward.
GLT and Lifetime ImpactWhile the connected account or GLT record remains active and afterward as needed for reconciliation, reversals, fraud and disputes.
Marketing consentFor the relationship and afterward as evidence of consent and suppression preferences.
Security and system logsShort risk-based periods unless an incident, investigation or legal hold requires longer retention.
Privacy breach recordsAt least the period required by applicable law; under PIPEDA regulations, breach records are retained for at least 24 months.

15. Safeguards and security incidents

Gively will use administrative, technical and physical safeguards appropriate to the sensitivity, amount, format and distribution of personal information. Safeguards may include access controls, authentication, encryption where appropriate, logging, secure development, vendor due diligence, backups, staff confidentiality, training, incident response and secure disposal.

Payment-card and banking credentials should be handled by specialized providers and tokenized or otherwise minimized in Gively systems. Users must protect credentials, use unique passwords and promptly report suspected compromise.

No method of transmission or storage is completely secure. Gively cannot guarantee absolute security, but this does not limit any safeguard or breach obligation imposed by law.

Gively will investigate suspected incidents and maintain breach records. Where a breach of security safeguards creates a real risk of significant harm or another reporting threshold is met, Gively will notify affected individuals and report to the appropriate regulator as required by law. It may also notify another organization or government institution that can reduce the risk of harm.

16. Your privacy rights and choices

Subject to applicable law and verified identity, an individual may ask Gively to:

  • Explain whether Gively holds personal information about them and how it has been used or disclosed.
  • Provide access to personal information under Gively’s control.
  • Correct or complete inaccurate personal information.
  • Withdraw consent for future processing where consent is the applicable basis.
  • Change marketing, cookie and public-display preferences.
  • Request deletion, restriction, portability or objection where applicable law provides such a right.
  • Complain about Gively’s privacy practices.

A request should be sent to the Privacy Officer using the contact information in section 20. Gively may request information reasonably necessary to verify identity and authority. It will respond within the period required by applicable law and may extend that period where legally permitted.

Access may be limited where information is protected by legal privilege, would reveal confidential commercial information or another person’s information, cannot be disclosed for security or fraud-prevention reasons, has been collected for an investigation, or another legal exception applies. Gively will explain a refusal where permitted.

Gively may charge only a fee permitted by law and will advise the requester in advance. If Gively and an individual cannot agree on a correction, Gively may record the unresolved challenge and transmit it to relevant recipients where appropriate.

16.1 Additional rights where provincial law applies

Additional rights and obligations may apply under provincial private-sector privacy law. For example, where Quebec’s Act respecting the protection of personal information in the private sector applies, an individual may have rights concerning access, rectification, withdrawal of consent, cessation of dissemination or de-indexing in the circumstances prescribed by law, and information about certain decisions based exclusively on automated processing.

Where Quebec law applies, the person with the highest authority within Gively is responsible for the protection of personal information unless that function is delegated in writing and the delegate’s title and contact information are published as required. Gively must also complete any privacy impact assessment and confidentiality-incident steps required by that law.

Gively does not state in this draft that it currently makes decisions producing legal or similarly significant effects based exclusively on automated processing. If that changes, the Policy and the relevant just-in-time notice must be updated before the feature is used.

17. Children and young people

GivelyCF is not directed to children under 14. Individuals must ordinarily be at least the age of majority in their province or territory to create an organizer, organization-administrator or paid subscriber account or make binding decisions for another person or organization.

A young person may be permitted to visit public pages or participate in limited giving or fundraising only through a parent or legal guardian and where Gively has implemented an age-appropriate process. In all but exceptional circumstances, consent for a child under 13 must be obtained from a parent or guardian.

Organizers must not publish a child’s full name, precise location, school, identity documents, medical records, financial information or images without lawful authority, appropriate notice and consent. Campaigns involving children require heightened review and data minimization.

If Gively learns that it collected a child’s information without appropriate authority, it will take reasonable steps to delete or otherwise address it. A parent or guardian may contact the Privacy Officer.

18. Third-party services

The Platform may link to, embed or depend on recipient websites, payment services, identity providers, banks, social networks, analytics services, reward providers or other third parties. This Policy does not govern information a third party collects for its own purposes.

Users should review the third party’s privacy notice before providing information. A link, listing, verification step or integration does not mean Gively endorses the third party’s privacy practices.

No prospective merchant or ecosystem provider, including Runa, Ascenda, Collinson or Priority Pass, should be named in the public version of this Policy unless a contract and implemented data flow exist.

19. Changes to this Policy

Gively may update this Policy to reflect changes in law, technology, services, vendors or practices. The revised Policy will state its effective date and be posted on the Platform.

If a change materially affects how Gively handles personal information, Gively will provide additional notice and obtain renewed consent where required. Gively will not apply a materially new purpose retroactively without appropriate authority.

20. Contact and complaints

Questions, requests or complaints may be directed to Gively’s Privacy Officer:

Privacy inquiries

Gively Crowdfunding & Digital Finance Inc.

36 McNaughton Drive

Saint John, New Brunswick, Canada E2J 4K6

Email: info@givelycf.com

Telephone: 506-607-7813

Please do not send passwords, complete payment-card numbers, online-banking credentials or identity documents by ordinary email. Gively may provide a secure method for sensitive submissions.

Gively will investigate privacy complaints and explain the outcome. If an individual is not satisfied, they may contact the Office of the Privacy Commissioner of Canada or the provincial, territorial or other privacy regulator with jurisdiction. Gively should provide the correct regulator link in the published Policy based on the individual’s location and applicable law.

We use cookies
This website uses cookies to ensure you get the best experience on our website. Cookies Policy