Privacy Policy

This policy explains how the GiveFlow plugin and giveflow.io handle data.

What GiveFlow collects

The GiveFlow plugin stores donor records (name, email, address, phone) on your own WordPress database. All personally identifiable information is encrypted at rest using AES-256-GCM. Email addresses are hashed with SHA-256 for lookup purposes.

Payment data

Payment card details are handled entirely by your chosen payment gateway (Stripe or PayPal). GiveFlow never stores card numbers or bank account details.

Data ownership

Because GiveFlow is self-hosted, all donor data lives on your WordPress site. You control access, retention, and deletion.

Cookies

The GiveFlow plugin does not set tracking cookies. The donor portal uses a session token for authentication.

GDPR

GiveFlow includes built-in tools for GDPR compliance: consent management, donor data export, account deletion, IP anonymization, and configurable retention policies.

Contact form

When you send us a message through the contact form we receive your name, email address, and the message itself. We use them to reply and keep a record of the exchange, and you can ask us to show or delete them at any time.

Contact

For questions about this policy, or to ask what we hold about you, use the contact form.