Privacy Policy
Last updated: July 25, 2026
This policy explains what information KindLumen collects, how we use and share it, and the choices you have. It covers our website, dashboard, hosted donation pages, and the embeds we provide.
1. Who is responsible for your data
KindLumen provides software that organizations use to collect donations. Responsibility for personal data is split, and which part applies to you matters:
- Donor data belongs to the organization. When you give to an organization through a KindLumen form, that organization decides what to collect and what to do with it. They are the controller. We handle it on their behalf, as a processor, under their instructions.
- We are the controller for our own data — account holders, our website, security and anti-abuse records, and product telemetry.
In practice this means a donor request to access or delete personal data should go first to the organization you donated to. If you contact us instead, we will pass the request on and support them in answering it.
2. Information we collect
- Account information — name, email, phone, job title, timezone, and login credentials for people who sign in; and organization details including legal name, tax ID, address, and website.
- Donation information — the amount, frequency, campaign, whether the donor chose to cover transaction costs, and the resulting breakdown of the charge.
- Donor information — name, email address, an approximate location, and any custom fields the organization chooses to collect, handled on that organization’s behalf.
- Approximate location — when a donation is submitted, the donor’s IP address is sent to a third-party lookup service to derive a city and country. We do not store the IP address. The derived “City, Country” text is stored with the donation.
- Anti-abuse records — to rate-limit our public endpoints we store an irreversible hash computed from the IP address, browser user-agent, and organization. We cannot read the IP address back out of it, but it is derived from personal data and we treat it as such.
- Attribution metadata — when a donation comes through an embed we may record a short source label (for example, “WordPress”).
- Website analytics — see “Analytics and error monitoring” below.
3. Payment information
KindLumen never receives or stores card numbers, CVC codes, or bank details. Card entry happens inside a payment field served directly by Stripe, or on Stripe’s own hosted page. That data goes to Stripe, not to us. What reaches our systems is the donation amount and Stripe’s reference identifiers for the payment.
Payments are charged on the organization’s own connected payment account. Stripe processes them under its own privacy policy and its agreement with the organization.
4. Donations shown publicly
Organizations can enable a “recent donations” display on their campaign and donation pages. When it is on, a donor’s first name, approximate location (city and country), and gift amount may be visible to anyone who visits that page. Full names, email addresses, and any custom answers are never shown.
The organization controls this setting. When it is switched off, we do not include the data in the page at all. If you would prefer your gift not to appear, ask the organization before you donate.
5. Analytics and error monitoring
- Website analytics. We use StatCounter to measure traffic across our site, including our hosted donation pages. It collects your IP address, browser and device information, referring page, and the pages you view, and sets its own identifiers. It does not receive donation amounts or the details you type into a form.
- Error monitoring. We use Sentry to detect and diagnose faults. When an error occurs it records technical details and a replay of the page. Text and images in these replays are masked — we capture layout and interaction, not the content you typed. We also filter email addresses and long numeric strings out of error reports before they are sent.
- Bot protection. Cloudflare Turnstile protects some of our forms and receives your IP address to assess whether a submission is automated.
6. How we use information
- To provide, maintain, and improve the service.
- To process donations and send receipts, confirmations, and notifications.
- To secure the platform and prevent fraud and abuse.
- To communicate with account holders about the service.
- To meet legal, tax, and accounting obligations.
Where the GDPR applies, we rely on: performance of a contract (providing the service and processing a donation you initiated); legitimate interests (security, abuse prevention, and improving the product); legal obligation (records we must keep); and consent where we ask for it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are used in California law. We do not use donor data to advertise, and we do not disclose one organization’s donor data to another.
7. Who we share information with
We use the following service providers, each only for the purpose listed:
- Stripe — payment processing.
- Convex — application database and backend.
- Vercel — website hosting and content delivery.
- Resend — sending transactional email such as receipts and notifications.
- Sentry — error monitoring and diagnostics (United States).
- StatCounter — website analytics.
- Cloudflare Turnstile — bot protection.
- ipwho.is — deriving an approximate location from an IP address.
Where an organization has enabled another payment provider, that provider also receives the data needed to process the payment. We may also disclose information where required by law, to enforce our Terms of Use, or as part of a merger or acquisition.
8. International transfers
KindLumen and its service providers operate primarily in the United States, so information may be transferred to and processed in the US and other countries whose data protection laws differ from your own. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
9. Data retention
We keep donation and donor records for as long as the organization maintains its account, because organizations need a durable record for receipting, accounting, and tax purposes. Account information is kept while the account is active. Anti-abuse records are kept while they remain useful for rate limiting.
We do not currently apply automatic time-based deletion to donation records. If an organization closes its account, or a donor asks for erasure through the organization, contact us at privacy@kindlumen.com and we will delete or de-identify the data we hold, subject to records we are required to retain.
10. Security
We use encryption in transit, encrypt connected-account credentials at rest, restrict internal access, and never store card data. No service can promise perfect security, and we do not. If a breach affects your personal data we will notify you and the relevant regulator where the law requires it.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a copy in a portable format, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights.
Donors: please direct these requests to the organization you donated to, since they control that data. Contact us if you cannot reach them and we will help.
Account holders: email privacy@kindlumen.com. We will verify your identity before acting and respond within the time the applicable law allows. If you are in the EEA or UK you also have the right to complain to your local supervisory authority.
12. Email preferences
Transactional messages — donation receipts, confirmations, and account notices — are part of the service and are not marketing. Donors can opt out of non-essential email using the unsubscribe link in any message we send them.
13. Embedded forms
Our donation forms can be embedded on other websites in an iframe. The embedding website does not receive donor or payment data — that information flows to KindLumen and the payment provider. For attribution, an embed may pass a source label and, only when the site owner enables it, the site’s public domain or page address. No donor personal data is added to these parameters.
14. Children
KindLumen is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
15. Changes
We may update this policy. Material changes will be posted here with an updated date.
16. Contact
Privacy questions or requests: privacy@kindlumen.com. General support: support@kindlumen.com.
Listicles
9 Best Donorbox Alternatives for 2026 (Honest Comparison)
Donorbox works fine for a lot of nonprofits. But if you have ever wished the form looked more like your site, or cost less, or stopped sending donors off-page, here are nine alternatives worth a look.
High-Intent
Best fundraising software for nonprofits
Use this buyer-first comparison to choose fundraising software based on your website, your team size, and the amount of maintenance you actually want to own.
How-To Guides
How to Add a Donation Form to a Webflow Site
Webflow gives you a gorgeous site and exactly zero native ways to take a donation. Here is how to fix that without wrecking your design or shipping donors off to a third-party page.