This policy explains how the GiveFlow plugin and giveflow.io handle data.
What GiveFlow collects
The GiveFlow plugin stores donor records (name, email, address, phone) on your own WordPress database. All personally identifiable information is encrypted at rest using AES-256-GCM. Email addresses are hashed with SHA-256 for lookup purposes.
Payment data
Payment card details are handled entirely by your chosen payment gateway (Stripe or PayPal). GiveFlow never stores card numbers or bank account details.
Data ownership
Because GiveFlow is self-hosted, all donor data lives on your WordPress site. You control access, retention, and deletion.
Cookies
The GiveFlow plugin does not set tracking cookies. The donor portal uses a session token for authentication.
GDPR
GiveFlow includes built-in tools for GDPR compliance: consent management, donor data export, account deletion, IP anonymization, and configurable retention policies.
Contact form
When you send us a message through the contact form we receive your name, email address, and the message itself. We use them to reply and keep a record of the exchange, and you can ask us to show or delete them at any time.
Contact
For questions about this policy, or to ask what we hold about you, use the contact form.