logo

PRIVACY POLICY

In Your Hand, Inc. (GDPR-, CCPA-, and International Compliance-Aligned)

Effective Date
May 8, 2026
Headquarters
New York, United States
Scope
Global users, donors, beneficiaries, institutions, partners, and all platform visitors

This page explains how we handle personal data on the In Your Hand platform.

1. Introduction

Link

This Privacy Policy explains how In Your Hand, Inc. (“In Your Hand,” “we,” “our,” or “us”) collects, uses, stores, discloses, and protects personal information when Users:

  • Create an account
  • Donate
  • Open or operate a project
  • Upload media or documents
  • Use any feature of the platform
  • Interact with communications or reporting tools

By using the platform, you agree to this Privacy Policy.

3. Categories of Personal Data We Collect

Link

We collect different levels of data depending on the user category.

3.1 General Users

  • Name
  • Email address
  • Password (encrypted)
  • Device and browser information
  • IP address and geolocation
  • Usage statistics
  • Communication preferences

3.2 Donors

Additionally:

  • Donation amounts and history
  • Payment method (tokenized by payment processor)
  • Billing region
  • Gift Aid / tax receipt data
  • Anonymity preferences
We never store full credit card numbers.

3.3 Individual Project Owners

Additional required data:

  • Full legal name
  • Date of birth
  • Government-issued ID
  • Biometric verification (if requested)
  • Address and proof of address
  • Phone number
  • Bank account or payout information
  • Uploaded documents, invoices, receipts
  • Photos, videos, field reports

3.4 Institutional Partners

We collect:

  • Organization registration documents
  • Tax ID or equivalent
  • Board resolution
  • Authorized signatory information
  • Incorporation certificate
  • Bank verification documents
  • Sanctions screening data

3.5 Beneficiaries (Indirect Data Collection)

We may receive:

  • Age group
  • Region or location
  • Needs assessment data
  • Non-identifying demographic data

We do not request or store:

  • Government IDs of beneficiaries
  • Sensitive personal data unless legally required
Photo consent rules apply.

4. Sensitive Data Processing (AML / KYC / KYB)

Link

To comply with U.S. law, In Your Hand must process:

  • Identity documents
  • Sanctions screening results
  • Watchlist data (OFAC, UN, EU, UK)
  • Risk scoring
  • Fraud detection signals
  • Criminal history indicators (where legally permissible)
This data is processed under the “Legal Obligation” basis (GDPR Art. 6.1.c).

5. How We Use Personal Data

Link

We process personal data to:

  • Provide platform services
  • Verify identity & prevent fraud
  • Conduct AML/CFT & sanctions screening
  • Process donations and issue receipts
  • Manage fundraising projects
  • Communicate with users
  • Ensure transparency and donor protection
  • Improve the platform experience
  • Conduct audits and legal compliance reviews

We will not use your data for:

  • Selling to third parties
  • Behavioral advertising
  • Profiling unrelated to safety or fraud prevention

7. Data Sharing and Third-Party Disclosures

Link

We share data only when necessary and only with:

7.1 Payment Processors

  • Stripe
  • PayPal
  • Banking partners

Data shared:

  • Donation amount
  • Donor region
  • Payment token (never full card numbers)

7.2 Identity & Verification Providers

For KYC/KYB:

  • Onfido, Veriff, Jumio, Stripe Identity

We share:

  • Photos
  • ID documents
  • Compliance metadata

7.3 Sanctions & AML Screening Providers

  • LexisNexis
  • World-Check
  • Government watchlists

7.4 Cloud Hosting & Security Services

  • Encrypted data storage
  • Logging and monitoring systems

7.5 Legal Obligations & Regulatory Authorities

In Your Hand may disclose information to government or regulatory bodies when required by:

  • U.S. federal law (IRS, FinCEN, OFAC)
  • Foreign financial regulations
  • Court orders or subpoenas
  • Law enforcement investigations
  • AML/CFT reporting requirements
  • Sanctions compliance
  • Mandatory Expenditure Responsibility reports
Disclosures are made strictly within the minimum scope required by law.

7.6 Fraud Prevention & Security Providers

We may share data with cyber-security partners to:

  • Prevent fraud
  • Identify malicious activity
  • Protect donor payments
  • Secure platform systems

This includes IP monitoring, bot detection, behavioral anomaly scanning, and device fingerprinting.

7.7 No Sale of Personal Data

Under CCPA and GDPR, In Your Hand:

  • Does NOT sell personal data
  • Does NOT rent or trade personal information
  • Does NOT use donor data for third-party marketing

We only share data necessary for security, identity verification, donation processing, and compliance obligations.

8. International Data Transfers

Link

As a global nonprofit platform, In Your Hand may process and store data:

  • In the United States
  • In the European Union
  • In other jurisdictions where our secure cloud hosts operate

We ensure compliance through:

  • Standard Contractual Clauses (SCCs)
  • GDPR Article 46 appropriate safeguards
  • Data minimization
  • Encryption at transit and rest

Users in the EU acknowledge that their data may be transferred to the United States under these legal safeguards.

9. Data Retention Periods

Link

In Your Hand retains personal data based on legal, regulatory, and operational requirements.

9.1 Standard User Data

Retained as long as the account is active, plus 3 years.

9.2 Donor Records

Financial records must be retained for 7 years (IRS compliance).

9.3 KYC / KYB, AML, Sanctions Screening Data

Stored for 7–10 years, as required by U.S. federal law and international AML standards.

9.4 Project Documentation

Receipts, invoices, media, and reports retained for minimum 7 years.

9.5 Request for Deletion

Users may request deletion, except where data is required for:

  • Legal compliance
  • Fraud prevention
  • Ongoing investigations
  • Mandatory financial documentation
  • Historical donor tax records

10. Your Data Protection Rights

Link

Depending on your jurisdiction, you may have some or all of the following rights:

10.1 Right to Access

You may request a copy of personal data we hold about you.

10.2 Right to Rectification

You may correct inaccurate or incomplete data.

10.3 Right to Deletion (“Right to Be Forgotten”)

You may request deletion unless retention is required by:

  • AML regulations
  • IRS rules
  • Donor tax records
  • Fraud investigations
  • Expenditure Responsibility requirements

10.4 Right to Restrict Processing

You may limit the processing of your personal data.

10.5 Right to Data Portability

You may request a structured, machine-readable export of your information.

10.6 Right to Object (GDPR)

You may object to:

  • Marketing communications
  • Profiling not related to fraud prevention

10.7 Right to Withdraw Consent

If processing is based on consent, you may withdraw consent anytime.

10.8 California Rights (CCPA/CPRA)

California residents may request:

  • Categories of personal data collected
  • Categories of sources
  • Purposes of collection
  • Categories of third parties receiving data
  • Access, correction, deletion
  • Opt-out of sale (not applicable to our operations)

11. Cookies, Tracking Technologies & Analytics

Link

In Your Hand uses cookies to:

  • Secure accounts
  • Maintain login sessions
  • Detect fraud
  • Analyze platform usage
  • Measure ad-attributed donation conversions after consent where required
  • Improve performance
  • Display regionally relevant content

We use:

  • Essential cookies (required for platform operation)
  • Security cookies (anti-fraud, authentication)
  • Analytics cookies (Google Analytics or equivalent)
  • Advertising measurement cookies (Google Ads conversion tracking)

We do NOT use:

  • personalized advertising or remarketing cookies
  • behavioral targeting
  • third-party data brokers

Users may disable non-essential cookies via browser settings.

12. Children’s Privacy (COPPA Compliance)

Link

The platform is not intended for users under 18. We do not knowingly collect data from minors.

Project Owners must obtain documented parental or guardian consent for:

  • Any media involving children
  • Stories or updates referencing identifiable minors

Violations result in:

  • Immediate removal of content
  • Potential account termination
  • Safeguarding investigation

13. Security Measures

Link

In Your Hand protects data through:

  • End-to-end encryption
  • SSL/TLS for all connections
  • Encrypted storage (AES-256)
  • Role-based access control
  • Two-factor authentication (for internal systems)
  • Intrusion detection and prevention systems
  • Regular penetration testing
  • Routine security audits

Despite strong protections, no system is 100% secure. Users are responsible for safeguarding their passwords and devices.

14. Data Breach Policy

Link

If a breach affects personal data:

  1. Incident will be investigated immediately.
  2. Affected users will be notified within the legally required period (GDPR: 72 hours).
  3. Authorities will be notified when required.
  4. Mitigation measures and corrective actions will be implemented.

15. How We Use Automated Decision-Making

Link

We may use algorithmic tools for:

  • Fraud detection
  • Sanctions monitoring
  • Identity authentication
  • High-risk activity alerts

We do not use algorithms to make:

  • donation decisions
  • beneficiary decisions
  • eligibility judgments without human oversight

16. Third-Party Links

Link

The platform may link to external websites. In Your Hand is not responsible for those sites’ privacy practices.

17. Changes to This Privacy Policy

Link

In Your Hand may update this policy as needed.

Changes are effective upon posting. Continued use of the platform constitutes acceptance of updated terms.

18. Contact Information

Link

For privacy-related questions, data access requests, or deletion requests:

In Your Hand, Inc.
Attn: Data Protection Officer
Email: privacy@inyourhand.org
Address: New York, United States

Users in the EU may also file a complaint with their local Data Protection Authority.

If any part of this Privacy Policy is found unenforceable, the remaining provisions will remain in effect.