Privacy Policy
Last updated: September 3, 2026
This policy explains what information KindLumen collects, how we use and share it, and the choices you have. It covers our website, dashboard, hosted donation pages, and the embeds we provide.
1. Who is responsible for your data
KindLumen provides software that organizations use to collect donations. Responsibility for personal data is split, and which part applies to you matters:
- Donor data belongs to the organization. When you give to an organization through a KindLumen form, that organization decides what to collect and what to do with it. They are the controller. We handle it on their behalf, as a processor, under their instructions.
- We are the controller for our own data — account holders, our website, security and anti-abuse records, and product telemetry.
In practice this means a donor request to access or delete personal data should go first to the organization you donated to. If you contact us instead, we will pass the request on and support them in answering it.
2. Information we collect
- Account information — name, email, phone, job title, timezone, and login credentials for people who sign in; and organization details including legal name, tax ID, address, and website.
- Donation information — the amount, frequency, campaign, whether the donor chose to cover transaction costs, and the resulting breakdown of the charge.
- Donor information — name, email address, an approximate location, and any custom fields the organization chooses to collect, handled on that organization’s behalf.
- Approximate location — when a donation is submitted, the donor’s IP address is sent to a third-party lookup service to derive a city and country. We do not store the IP address. The derived “City, Country” text is stored with the donation.
- Anti-abuse records — to rate-limit our public endpoints we store an irreversible hash computed from the IP address, browser user-agent, and organization. We cannot read the IP address back out of it, but it is derived from personal data and we treat it as such.
- Attribution metadata — when a donation comes through an embed we may record a short source label (for example, “WordPress”).
- Website analytics — see “Analytics and error monitoring” below.
3. Payment information
KindLumen does not receive or store raw card numbers, CVC codes, or bank-account credentials. Payment details are entered through the selected provider’s interface or hosted checkout and sent directly to Stripe, Square, or PayPal, as applicable. KindLumen receives transaction metadata and provider reference identifiers needed to record the donation, not the raw payment credentials.
Payments are processed on the organization’s own connected payment account. The selected provider processes them under its own privacy policy and its agreement with the organization.
4. Donations shown publicly
Organizations can enable a “recent donations” display on their campaign and donation pages. When it is on, a donor’s first name, approximate location (city and country), and gift amount may be visible to anyone who visits that page. Full names, email addresses, and any custom answers are never shown.
The organization controls this setting. When it is switched off, we do not include the data in the page at all. If you would prefer your gift not to appear, ask the organization before you donate.
5. Analytics and error monitoring
- Website analytics. With your permission, KindLumen records a random visitor identifier, campaign labels, demo use, and signup progress. When you create an account, we connect that attribution to your account and organization so we can measure setup completion. Attribution lasts 30 days in your browser; these acquisition records expire after 90 days. Development traffic and donor checkout are excluded from acquisition tracking.
- Advertising measurement. If you allow analytics, Meta Pixel may receive visits to our marketing and signup pages and a successful account-registration event, along with browser and connection information. Meta may associate these events with your Meta account to measure and improve our ads. We do not send names, email addresses, passwords, donor details, or donation amounts through this integration. Automatic event detection and automatic advanced matching are not enabled by our code. You can decline or withdraw permission using “Analytics preferences” in the website footer. We honor Global Privacy Control.
- Error monitoring. We use Sentry to detect and diagnose faults. When an error occurs it records technical details and a replay of the page. Text and images in these replays are masked — we capture layout and interaction, not the content you typed. We also filter email addresses and long numeric strings out of error reports before they are sent.
- Bot protection. Cloudflare Turnstile protects some of our forms and receives your IP address to assess whether a submission is automated.
6. How we use information
- To provide, maintain, and improve the service.
- To process donations and send receipts, confirmations, and notifications.
- To secure the platform and prevent fraud and abuse.
- To communicate with account holders about the service.
- To meet legal, tax, and accounting obligations.
Where the GDPR applies, we rely on: performance of a contract (providing the service and processing a donation you initiated); legitimate interests (security, abuse prevention, and improving the product); legal obligation (records we must keep); and consent where we ask for it.
We do not sell personal information for money. Optional advertising measurement with Meta may constitute sharing under applicable privacy laws; you can decline it in Analytics preferences. We do not use donor data to advertise, and we do not disclose one organization’s donor data to another.
7. Who we share information with
We use the following service providers, each only for the purpose listed:
- Stripe — payment processing when enabled by an organization.
- Square — payment processing when enabled by an organization.
- PayPal — payment processing when enabled by an organization.
- Convex — application database and backend.
- Vercel — website hosting and content delivery.
- Resend — sending transactional email such as receipts and notifications.
- Sentry — error monitoring and diagnostics (United States).
- Meta — optional advertising measurement.
- Cloudflare Turnstile — bot protection.
- ipwho.is — deriving an approximate location from an IP address.
The payment provider selected by an organization receives the information needed to process its payments. We may also disclose information where required by law, to enforce our Terms of Use, or as part of a merger or acquisition.
8. International transfers
KindLumen and its service providers operate primarily in the United States, so information may be transferred to and processed in the US and other countries whose data protection laws differ from your own. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
9. Data retention
We keep donation and donor records for as long as the organization maintains its account, because organizations need a durable record for receipting, accounting, and tax purposes. Account information is kept while the account is active. Anti-abuse records are kept while they remain useful for rate limiting.
We do not currently apply automatic time-based deletion to donation records. If an organization closes its account, or a donor asks for erasure through the organization, contact us at privacy@kindlumen.com and we will delete or de-identify the data we hold, subject to records we are required to retain.
10. Security
We use encryption in transit, encrypt connected-account credentials at rest, restrict internal access, and never store card data. No service can promise perfect security, and we do not. If a breach affects your personal data we will notify you and the relevant regulator where the law requires it.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a copy in a portable format, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights.
Donors: please direct these requests to the organization you donated to, since they control that data. Contact us if you cannot reach them and we will help.
Account holders: email privacy@kindlumen.com. We will verify your identity before acting and respond within the time the applicable law allows. If you are in the EEA or UK you also have the right to complain to your local supervisory authority.
12. Email preferences
Transactional messages — donation receipts, confirmations, and account notices — are part of the service and are not marketing. Donors can opt out of non-essential email using the unsubscribe link in any message we send them.
13. Embedded forms
Our donation forms can be embedded on other websites in an iframe. The embedding website does not receive donor or payment data — that information flows to KindLumen and the payment provider. For attribution, an embed may pass a source label and, only when the site owner enables it, the site’s public domain or page address. No donor personal data is added to these parameters.
14. Children
KindLumen is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
15. Changes
We may update this policy. Material changes will be posted here with an updated date.
16. Contact
Privacy questions or requests: privacy@kindlumen.com. General support: support@kindlumen.com.
Website & Setup Guides
How to Accept Stripe Donations Without Writing Code
Stripe offers one genuinely zero-code donation route and several lower-code checkout routes. This guide separates them so you can choose without buying too much—or too little—technology.
By Kiran Patel
Website & Setup Guides
How to Add a Stripe Donation Form to WordPress With the KindLumen Plugin
The KindLumen plugin connects a WordPress site to a KindLumen form, then adds a button, inline form, or campaign card without storing card or donor data in WordPress.
By Devon Reed