We may update this Privacy Policy from time to time.
The date of the last change will always be displayed at the top of this page.
Last updated 5 July 2026
Our commitment to open and transparent management of your personal information
1. Who we are
Made With Ed Pty Ltd trading as Funraisin ("Funraisin," "we," "us," "our") is a software company incorporated in Australia. We operate a white-labelled fundraising platform used by nonprofit and charity organisations across Australia, New Zealand, the United Kingdom, Europe, Canada, and the United States.
Our registered address is: 1 Sussex St, Barangaroo, NSW 2000, Australia.
Funraisin operates through the following wholly owned subsidiaries, each responsible for employing staff who support and service customers in their respective regions:
- Funraisin Inc: United States
- Funraisin Limited: United Kingdom
- Funraisin Limited: New Zealand
All customer agreements are entered into with Made With Ed Pty Ltd. Our subsidiaries do not contract directly with customers; they support the delivery of the Funraisin platform and services.
2. About this policy
This Privacy Policy explains how we collect, use, store, and share personal data in connection with:
- Our corporate website at funraisin.co and its subdomains ("our website"); and
- The fundraising platform we provide to our customers ("the platform").
This policy covers two distinct roles we play in relation to personal data — as a data controller (where we determine how and why data is processed) and as a data processor (where we handle data solely on behalf of our customers). Both roles are explained below.
We may update this policy from time to time. The date at the top of this page reflects when it was last changed. Where any update materially changes the way we process your personal data, we will notify affected individuals or organisations by email where we hold contact details, or by prominent notice on our website, before the change takes effect. For processing that relies on your consent, we will seek fresh consent to any material change.
3. Our role: Data Controller and Data Processor
Understanding which role we play is important for understanding your rights and who to contact.
When we are the data controller
We act as the data controller for personal data collected through our own website and web properties operating under the funraisin.co domain, including funraisin.co itself and any subdomains such as support.funraisin.co, including information submitted via webforms, marketing contact requests, support enquiries, and job applications. In this role, we decide what data to collect and why, and we are directly responsible for it.
When we are the data processor
We act as a data processor when handling personal data that is collected through the platform on behalf of our customers — the charity and nonprofit organisations that use Funraisin to run their fundraising campaigns, events, and donation programmes.
In these circumstances, the relevant charity or nonprofit is the data controller. They determine what data to collect, for what purpose, and how long to retain it. We act only on their documented instructions, as set out in the Data Processing Agreement (DPA) we enter into with customers.
If you have interacted with a fundraising campaign, event, or donation page powered by Funraisin, the organisation running that campaign is responsible for your personal data and your rights in relation to it. Their own privacy policy governs how your data is used.
4. Data we collect as Data Controller
This section applies to personal data collected through our website and our direct marketing and sales activities.
4.1 Information you provide to us
When you contact us, request a demo, submit a webform, or otherwise engage with us directly, we may collect:
- Your name and job title
- Organisation name
- Email address, phone number, and mailing address
- Any other information you choose to include in your message
4.2 Usage data
When you visit our website, we automatically collect certain technical data about your device and how you interact with our site. This may include:
- IP address and approximate location
- Browser type, version, and operating system
- Device identifiers and network information
- Pages visited, time spent, and referring URLs
- Search queries and click behaviour
IP addresses and device identifiers constitute personal data in the jurisdictions we operate in, including under the GDPR and the Australian Privacy Act.
We collect usage data using cookies and similar tracking technologies. For details on how we use cookies and how to manage your preferences, see Section 9 (Cookies) of this policy.
5. Data we process on behalf of our customers
This section describes the personal data we handle in our capacity as a data processor on behalf of our charity and nonprofit customers.
Funraisin provides the technology infrastructure that powers our customers' fundraising campaigns, donation pages, peer-to-peer fundraising programmes, events, ticketing, raffles, and related activities. When individuals engage with these activities, they are interacting with our customers' platform — not with Funraisin directly.
5.1 Categories of data we process
Depending on the features a customer has configured and the nature of their campaign or event, the personal data we process on their behalf may include:
- Identity and contact details — full name, email address, phone number, and mailing address
- Financial and transactional data — donation amounts, transaction records, and payment method details. Payment card data is handled directly by our certified third-party payment processors (Stripe and PayPal) and is not stored on our systems
- Fundraiser profile data — peer-to-peer fundraising pages, progress, messaging, and activity history
- Event and participation data — ticket purchases, event registrations, merchandise orders, and raffle or lottery entries
- Webform submissions — any information a user submits through a form hosted on a customer's platform
- Technical and usage data — browser type, device information, IP address, and session data, collected to deliver and secure the platform
- Social profile data — where a user connects a social media account (such as Facebook) to their fundraising activity, we may receive profile information they have chosen to share through that connection
This list reflects the categories our platform is capable of processing. What is actually collected in any given campaign is determined by our customers' own configuration and their applicable privacy notices — not by Funraisin.
5.2 How we handle this data
We process personal data on behalf of our customers only in accordance with their documented instructions, as set out in our Data Processing Agreement. We do not use end-user data collected through customer platforms for our own marketing, product development, or commercial purposes, except where data is fully anonymised and aggregated in a way that cannot reasonably be used to identify any individual.
We will not access, use, or disclose customer end-user data beyond what is required to deliver the contracted platform services, maintain platform security, or meet our legal obligations. If required by law to disclose data, we will notify the relevant customer unless prohibited from doing so by law.
Data Processing Agreements
Funraisin enters into a Data Processing Agreement (DPA) with each customer that requires one under applicable law. Our DPA reflects the requirements of GDPR Article 28(3), the Australian Privacy Act, Canada's PIPEDA, and other applicable regulations, and includes provisions covering: processing only on documented instructions; confidentiality obligations; security measures; sub-processor obligations; assistance with data subject rights; post-contract deletion procedures; and cooperation with audits.
Customers may request a copy of our standard DPA by contacting dpo@funraisin.co
5.3 Health-related and sensitive cause data
Our platform processes donations, registrations, and fundraising activity on behalf of charities whose charitable purposes relate to health conditions, disability, mental health, and similar causes. Where an individual makes a donation or participates in a campaign conducted by such an organisation, that activity may — depending on context — constitute or imply health-related or other sensitive information within the meaning of Article 9 of the UK/EU GDPR or equivalent provisions under applicable law.
Funraisin does not itself collect or use such information for its own purposes. Processing of this nature occurs solely on the instructions of the relevant customer and is governed by that customer's own privacy notice and lawful basis for processing.
Where a customer's intended use case requires the collection of data that explicitly constitutes special category data under applicable law — including health data, biometric data, data revealing racial or ethnic origin, religious beliefs, or data concerning a person's sex life or sexual orientation — the following conditions apply:
- The customer must notify Funraisin in advance and obtain Funraisin's prior written agreement before configuring their platform to collect such data;
- The customer must confirm in writing that they have a valid Article 9(2) exemption (or equivalent under applicable law) and an appropriate privacy notice in place;
Customers may not collect special category data through the platform without completing this process. Funraisin reserves the right to suspend access to any platform instance where special category data is being collected in breach of this requirement.
For the avoidance of doubt: cause-based donation data (i.e., the fact that a person has donated to a health charity) is not treated by Funraisin as special category data unless the customer has explicitly configured their platform to collect data that, on its face, reveals health status or other sensitive attributes. Funraisin does not infer health status or other special category attributes from cause-based donation behaviour.
5.4 Your rights as an end user
If you are a donor, fundraiser, event participant, or supporter who has interacted with a campaign powered by Funraisin, the charity or nonprofit running that campaign is responsible for your personal data. To exercise your rights — including the right to access, correct, erase, or port your data — please contact that organisation directly using the contact details in their privacy policy.
If you are unable to identify or reach the relevant organisation, contact us at dpo@funraisin.co. We will acknowledge your enquiry within 5 business days and direct it to the appropriate party.
6. How we use your data (Controller role)
For data we collect directly as a data controller (through our website and direct engagement), we use it for the following purposes. The table below identifies the lawful basis we rely on for each processing activity.
| Processing purpose | Description | Lawful basis |
|---|---|---|
| Respond to enquiries and demo requests | When you contact us or request a demo, we use your data to respond and follow up as part of our sales process. | Contractual necessity (pre-contractual steps) / Legitimate interests |
| Customer account administration | Managing your Funraisin account, billing, and contractual obligations. | Contractual necessity |
| Deliver professional services | Supporting services you have engaged us to provide. | Contractual necessity |
| Send marketing communications | Email newsletters and product updates sent only to opted-in contacts. You may unsubscribe at any time via the link in any email or by emailing support@funraisin.co. | Consent |
| Improve our website and platform | Using aggregated, anonymised usage data to improve performance and features. | Legitimate interests |
| Legal and regulatory compliance | Fraud prevention, tax, audit, and regulatory requirements. | Legal obligation |
| Job applications | Reviewing applications and conducting pre-employment checks. | Legitimate interests (unsuccessful applicants) / Legal obligation (right-to-work checks) |
7. When we share personal data
We do not sell personal data. We share it only in the following circumstances.
7.1 Service providers and sub-processors
We may engage trusted third-party service providers to help operate our website and deliver our platform. These providers process data on our behalf under contractual obligations that require them to protect the data and use it only as instructed. See Section 8 for our sub-processor list.
7.2 Our group companies
Our subsidiary companies — Funraisin Inc (USA), Funraisin Limited (UK), and Funraisin Limited (NZ) — may access personal data where necessary to provide support and services to our customers in those regions. All such access is governed by internal data sharing agreements and is limited to what is required for the relevant service function.
7.3 Legal requirements
We may disclose personal data where required to do so by applicable law, court order, or regulatory authority. Where possible and legally permissible, we will notify the relevant customer or individual before making such a disclosure. Where we receive a request from law enforcement or a government authority and are legally prohibited from notifying the affected party (for example, under a non-disclosure order), we will comply with that prohibition but will document the request internally for audit purposes.
7.4 Business transfers
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. Any such transfer will be subject to confidentiality obligations, and we will notify affected parties as required by applicable law prior to any transfer of personal data to a new controller taking effect.
8. Sub-processors
The following third parties process personal data on our behalf. We maintain protections with each to ensure data is handled appropriately. We will notify customers of any intended addition or replacement of a sub-processor with a minimum of 30 days' advance notice, giving customers the opportunity to raise any objection before the change takes effect.
8.1 Funraisin website (funraisin.co)
| Processor | Country | Purpose | Data types |
|---|---|---|---|
| Amazon Web Services | USA / Global | Website hosting and infrastructure | Usage and contact data |
| Campaign Monitor | Australia | Email delivery and marketing | Name, email, company data |
| ActiveCampaign | USA | Marketing automation and CRM | Name, email, company data |
8.2 Funraisin platform (customer-hosted instances)
Customer data is stored in regional AWS data centres matched to each customer's geographic location, as detailed in Section 10 (Data Residency). Platform-level sub-processors include:
| Processor | Country | Purpose | Data types |
|---|---|---|---|
| Amazon Web Services | AU / EU / US / CA | Platform hosting and data storage | All platform data |
| Stripe | USA / Global | Payment processing | Payment and transaction data |
| PayPal | USA / Global | Payment processing | Payment and transaction data |
| Zendesk | USA / Global | Customer support and helpdesk ticketing | Customer and end-user data (access only as required for support resolution) |
| New Relic | USA | Error monitoring and platform diagnostics | Technical and session data (error logs, stack traces) |
8.3 Funraisin platform (customer-hosted instances: customer-activated native integrations)
The following third-party platforms are available as native integrations within the Funraisin platform. These integrations are optional and are enabled solely at the direction of individual customers. When activated, data is transmitted to the relevant third party in accordance with that customer's configuration and their own agreement with the integration provider. Funraisin facilitates the technical connection, the customer (as data controller) is responsible for ensuring they have a lawful basis to share data with each integration they enable, and that their own privacy notices reflect the use of these tools. Native integrations supported sub-processors include:
| Processor | Country | Purpose | Data types |
|---|---|---|---|
| Salesforce | USA | CRM sync - transfer of supporter data to customers' Salesforce instance | Donor and transaction data (customer controlled) |
| Blackbaud (Raiser's Edge NXT) |
USA / Global | CRM sync - transfer of supporter data to customers' Raiser's Edge NXT instance | Donor and transaction data (customer controlled) |
| Mailchimp (Intuit) |
USA | Email marketing - sync of supporter contact lists and campaign engagement data for customer-managed email programmes | Name, email address, subscription status, campaign engagement data |
| Campaign Monitor | Australia / USA | Email marketing - sync of supporter contact lists and campaign engagement data for customer-managed email programmes | Name, email address, subscription status, campaign engagement data |
| Orrto (formerly Autopilot) |
Australia | Email marketing - sync of supporter contact lists and campaign engagement data for customer-managed email programmes | Name, email address, subscription status, campaign engagement data |
| Chariot (DAFPay) USA customers only |
USA | Donor-advised fund (DAF) payment processing - enables donors to give directly from their DAF account | Donor name, DAF account details, donation amount, charity designation |
| Double the Donation |
USA | Gift matching verification - enables donors to identify employer matching programmes and submit match requests | Donor name, email address, employer details, donation amount |
| Google Analytics and Google Tag Manager Customer responsible for ensuring GA consent compliance visible on their platform |
USA | Platform and campaign analytics - tracking of supporter behaviour and campaign performance on customer-hosted platforms | Pseudonymous identifiers, session data, page views, event data, approximate location |
| Zapier | USA | Workflow automation - enables customers to connect Funraisin data to third-party tools via automated workflows | Customer controlled |
| Nuclavis | USA | P2P mobile companion app and mobile messaging to drive fundraiser recruitment, coaching, and engagement | Name, email address, subscription status, campaign engagement data |
9. Cookies
We use cookies and similar tracking technologies on our website to collect usage data, improve performance, and deliver relevant marketing content.
9.1 Our website
Disabling certain categories of cookies may affect your experience on our website. Where we rely on consent for non-essential cookies, that consent is collected before any non-essential cookies are set.
9.2 Customer-hosted platforms
Funraisin provides the platform infrastructure; individual charity and nonprofit customers are responsible for implementing their own cookie consent mechanism on their Funraisin-powered sites. Customers choose and manage their own consent management platform (CMP) and must ensure compliance with applicable cookie laws in their jurisdiction — including the ePrivacy Directive (EU/UK), the Privacy and Electronic Communications Regulations (UK), and equivalent requirements in other markets.
10. Data residency and international transfers
We store customer platform data in regional AWS data centres matched to each customer's geographic location. Our data residency assignments are:
- Australia and New Zealand — AWS Sydney, Australia
- United Kingdom and EU — AWS EU West (Ireland)
- Canada — AWS Canada (Central)
- United States — AWS US East (Virginia)
Customer data is not transferred between regions for operational purposes.
10.1 EU and UK data transfers — transfer mechanisms
Where personal data originating in the EU or UK is transferred to a country not subject to an adequacy decision under EU GDPR or UK GDPR — including transfers to our US-based sub-processors (Amazon Web Services, Stripe, PayPal, and others) — we rely on the following transfer mechanisms:
- EU transfers: Standard Contractual Clauses (SCCs) in the form approved by the European Commission (Implementing Decision 2021/914), incorporating the applicable module for processor-to-processor or controller-to-processor relationships as relevant
- UK transfers: The UK International Data Transfer Agreement (IDTA) or, where applicable, the UK Addendum to the EU SCCs approved by the Information Commissioner's Office
11. AI-powered features
Funraisin is developing AI-powered features designed to help our customers improve fundraising outcomes for their supporters.
11.1 What these features do
When enabled by a customer, our AI features may use anonymised and aggregated data — including historical transaction patterns, campaign performance signals, device type, browser, approximate location, and time of activity — to personalise the fundraising experience for a supporter. This may include:
- Suggesting donation amounts based on what has worked well for similar supporters on that platform
- Surfacing relevant fundraising messages or social sharing prompts
- Recommending next steps to encourage ongoing participation
These features will only be active where a customer has explicitly chosen to enable them. They are not enabled by default.
11.2 Automated processing and your rights
Some of our AI features involve automated processing that influences what content a supporter sees or what actions are suggested to them. Where this constitutes automated decision-making within the scope of applicable privacy law — including GDPR Article 22 — our customers must ensure appropriate disclosures are in place through their relevant privacy notices before they activate these features for their platform.
Customers wishing to enable AI features will be required to: (a) confirm that their privacy notices have been updated to reflect the relevant automated processing; (b) confirm they have a valid lawful basis for that processing; and (c) confirm that a Data Protection Impact Assessment (DPIA) has been conducted where required. Funraisin will provide reasonable assistance to customers in completing these steps as part of the onboarding process.
11. AI-powered features
Funraisin is developing AI-powered features designed to help our customers improve fundraising outcomes for their supporters.
11.1 What these features do
When enabled by a customer, our AI features may use anonymised and aggregated data — including historical transaction patterns, campaign performance signals, device type, browser, approximate location, and time of activity — to personalise the fundraising experience for a supporter. This may include:
- Suggesting donation amounts based on what has worked well for similar supporters on that platform
- Surfacing relevant fundraising messages or social sharing prompts
- Recommending next steps to encourage ongoing participation
These features will only be active where a customer has explicitly chosen to enable them. They are not enabled by default.
11.2 Automated processing and your rights
Some of our AI features involve automated processing that influences what content a supporter sees or what actions are suggested to them. Where this constitutes automated decision-making within the scope of applicable privacy law — including GDPR Article 22 — our customers must ensure appropriate disclosures are in place through their relevant privacy notices before they activate these features for their platform.
Customers wishing to enable AI features will be required to: (a) confirm that their privacy notices have been updated to reflect the relevant automated processing; (b) confirm they have a valid lawful basis for that processing; and (c) confirm that a Data Protection Impact Assessment (DPIA) has been conducted where required. Funraisin will provide reasonable assistance to customers in completing these steps as part of the onboarding process.
12. Data security
Funraisin maintains a SOC 2 Type 2 certification, which provides independent third-party assurance that our security controls meet recognised industry standards. Our security measures include, but are not limited to:
- Encryption of data in transit (TLS 1.2 or higher) and at rest
- Access controls and role-based permissions limiting data access to authorised personnel
- Regular security testing and vulnerability assessments
- Incident detection and response processes
- Staff training on data handling and security obligations
13. Data retention
13.1 Data we hold as controller
We retain personal data collected through our website and direct marketing activities only for as long as is necessary for the purpose for which it was collected, or as required by applicable law.
When data is no longer required, we securely delete or irreversibly anonymise it. Anonymised data that cannot reasonably be used to identify any individual may be retained for longer periods for statistical and analytical purposes.
13.2 Customer platform data
For personal data processed on behalf of our customers, retention is governed in the first instance by the terms of our Data Processing Agreement with each customer. Customers are responsible for determining appropriate retention periods for data collected through their campaigns, consistent with their obligations under applicable law.
During the contract term: We retain customer platform data for the duration of the active customer relationship to enable delivery of the contracted services.
Following contract termination: We will retain customer platform data for no more than 12 months following termination to enable data export and transition, after which it is securely deleted or irreversibly anonymised, unless the customer requests earlier deletion (completed within 30 days of request) or law requires longer retention of specific records.
At the end of the post-termination window, customer data — including all associated end-user personal data — will be securely deleted or irreversibly anonymised, unless:
- The customer has submitted a written request to extend retention for a defined further period and Funraisin has confirmed that extension in writing; or
- We are required to retain specific data by applicable law, court order, or regulatory obligation, in which case only the data subject to that obligation will be retained, for the minimum period required.
Anonymised and aggregated statistical data derived from customer platform activity — where such data cannot be used to identify any individual — is not subject to the deletion obligations above, and we may choose to use that data for improving the services we provide.
13. Your rights
Depending on where you are located, you may have the following rights in relation to your personal data:
- Right of access — to request a copy of the personal data we hold about you
- Right to rectification — to request correction of inaccurate or incomplete data
- Right to erasure — to request deletion of your personal data in certain circumstances
- Right to restriction — to request that we limit our processing of your data
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making — to request human review of automated decisions that significantly affect you
To exercise any of these rights in relation to data we hold as a controller (i.e. data collected through our website), contact us at dpo@funraisin.co. We will acknowledge your request within 5 business days, verify your identity, and respond in full within 30 days (or within any shorter period required by applicable law). Where additional time is required, we will notify you before the initial period expires.
To exercise your rights in relation to data processed on behalf of one of our customers (i.e. your data as a donor, fundraiser, or event participant), please contact the relevant charity or nonprofit directly. We will provide reasonable assistance to customers where required.
13. Minimum age requirements
15.1 Our customers
Organisations that apply to use the Funraisin platform undergo a verification process before their account is activated. We confirm the registered status of each applicant charity or nonprofit prior to enabling their platform access.
15.2 End users on customer platforms
Funraisin does not impose a universal minimum age for end users across all customer platforms. Our customers are responsible for determining the appropriate minimum age for their campaigns and for implementing any required age validation on their forms. Funraisin provides age validation functionality that customers may configure and apply at their discretion.
Where a customer's platform is directed at or likely to attract users under the age of 16 (or the applicable age of digital consent in their jurisdiction), they are responsible for obtaining appropriate parental or guardian consent before collecting that user's personal data, in accordance with applicable law.
13. Contact us and complaints
If you have questions about this Privacy Policy or how we handle personal data, please contact our Data Protection Officer: dpo@funraisin.co or by mail to Funraisin, 1 Sussex St, Barangaroo, NSW 2000, Australia.
If you are located in the EU or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). In Ireland (and for EU purposes), this is the Data Protection Commission (dataprotection.ie).
We welcome direct contact before any regulatory complaint is submitted and will work in good faith to resolve your concerns promptly.
Appendix A: Additional rights for individuals in the EU and UK
The General Data Protection Regulation (GDPR) and its UK equivalent (UK GDPR) provide individuals located in the EU and UK with additional rights and protections. This Appendix supplements the main Privacy Policy and applies to any personal data that falls within the scope of those laws.
Lawful basis for processing
Where Funraisin acts as a data controller, we process personal data on one or more of the following lawful bases. The specific basis for each processing activity is set out in the mapping table in Section 6 of this policy.
- Legitimate interests — to operate and improve our website, communicate with prospective and current customers, and protect our business
- Contractual necessity — to fulfil our obligations under a contract with you, or to take steps at your request before entering into a contract
- Legal obligation — where we are required to process data to comply with applicable law
- Consent — where we ask for and receive your explicit consent to a specific use of your data. You may withdraw consent at any time without affecting the lawfulness of prior processing
Where we act as a data processor, we process personal data on the instructions of the data controller (our customer). The lawful basis for that processing is determined by the controller.
Data subject rights (EU/UK)
In addition to the rights set out in Section 14, individuals in the EU and UK have the right to object to decisions made solely by automated means that produce legal or similarly significant effects on them, and to request human review of such decisions. See Section 11 (AI Features) for details of our approach to automated processing.
You also have the right to lodge a complaint with your national supervisory authority at any time. We would welcome the opportunity to resolve any concerns directly before you do so.
International transfers (EU/UK)
Where personal data originating in the EU or UK is transferred outside those territories, we ensure appropriate safeguards are in place. See Section 10.1 for the specific transfer mechanisms we rely on (SCCs, IDTA, and transfer impact assessments).
Acting as a processor
Where Funraisin receives personal data from one of our charity customers in its capacity as a data processor, that customer is the data controller and is responsible for the lawfulness of the original collection. To understand how your data is processed and to exercise your rights, please contact the relevant charity directly.
Records of Processing Activities
Funraisin maintains Records of Processing Activities (RoPA) as required under GDPR Article 30, covering both our controller and processor processing activities. Our RoPA is available to supervisory authorities on request.
Appendix B: Australia and New Zealand
This Appendix applies to individuals located in Australia and New Zealand whose personal data is handled by Funraisin, and supplements the main Privacy Policy above.
Australia — Privacy Act 1988 and Australian Privacy Principles
Funraisin is bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) that sit within it. These principles govern how we collect, use, store, disclose, and provide access to personal data.
Under the APPs, you have the right to:
- Know why we are collecting your personal data and how it will be used
- Access the personal data we hold about you
- Request correction of personal data that is inaccurate, out of date, incomplete, irrelevant, or misleading
- Make a complaint if you believe we have breached your privacy rights
Notifiable Data Breaches: Funraisin is subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If we become aware of an eligible data breach — one that is likely to result in serious harm to any affected individuals — we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
Complaints: If you have a privacy concern, please contact us first at dpo@funraisin.co. If you are not satisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au or by calling 1300 363 992.
New Zealand — Privacy Act 2020
Funraisin is also bound by the Privacy Act 2020 (NZ) and the Information Privacy Principles (IPPs) contained within it, which govern the collection, use, disclosure, and storage of personal information relating to individuals in New Zealand.
Under the Privacy Act 2020, you have the right to:
- Request access to personal information we hold about you
- Request correction of personal information that is incorrect
- Make a complaint to us or directly to the Office of the Privacy Commissioner
Notifiable Privacy Breaches: Where a privacy breach is likely to cause serious harm to an individual, Funraisin is required to notify both the affected individual and the New Zealand Privacy Commissioner as soon as reasonably practicable.
Complaints: Contact us first at dpo@funraisin.co. If unresolved, you may contact the Office of the Privacy Commissioner at privacy.org.nz or by calling 0800 803 909.
Appendix C: Canada
This Appendix applies to individuals located in Canada whose personal data is handled by Funraisin, and supplements the main Privacy Policy above.
Federal — PIPEDA
At the federal level, Funraisin's handling of personal data in the course of commercial activity is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA is built around 10 fair information principles covering accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.
Under PIPEDA, you have the right to:
- Know what personal data we hold about you and how it is being used
- Access your personal data and request corrections where it is inaccurate or incomplete
- Withdraw consent to our use of your data, subject to legal or contractual obligations
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC)
Breach reporting: Where a breach of security safeguards involves personal data and creates a real risk of significant harm to an individual, Funraisin is required to report the breach to the OPC and notify affected individuals as soon as feasible.
Complaints: Contact us first at dpo@funraisin.co. If unresolved, you may contact the OPC at priv.gc.ca or by calling 1-800-282-1376.
Quebec — Law 25 (Act respecting the protection of personal information in the private sector)
Quebec's Law 25 — which came into full force in September 2023 — is the most stringent provincial privacy legislation in Canada and applies to any organisation handling the personal information of Quebec residents, regardless of where that organisation is located.
In addition to the rights available under PIPEDA, individuals in Quebec have the right to:
- Data portability — to receive personal data we hold about you in a structured, commonly used, technological format, and to have it transferred to another organisation where technically feasible
- De-indexation — to request that we stop disseminating your personal data or de-index any hyperlinks attached to your name, where certain conditions are met
- Automated decision-making disclosure — to be informed when a decision is made about you solely through automated processing, and to request human review of that decision. See Section 11 of the main policy for details of our AI features
Privacy by default: Under Law 25, Funraisin is required to ensure that, by default, only the personal data necessary for the specific purpose of collection is collected and used, and retained only for as long as necessary. Customers using our platform to collect data from Quebec residents share responsibility for meeting this requirement in their own campaign configuration.
Complaints: Individuals in Quebec may lodge a complaint with the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca.
Other provinces — Alberta and British Columbia
Alberta and British Columbia each have their own provincial privacy legislation (PIPA Alberta and PIPA BC respectively) that applies in place of PIPEDA for provincially regulated organisations operating within those provinces. Where Funraisin handles personal data of individuals in those provinces, we comply with the applicable provincial legislation. Contact dpo@funraisin.co for any provincial privacy enquiries.
Appendix D: United States
This Appendix applies to individuals located in the United States whose personal data is handled by Funraisin, and supplements the main Privacy Policy above.
There is currently no single federal privacy law in the United States. Privacy rights are governed by a combination of sector-specific federal laws and a growing body of state legislation. Funraisin monitors applicable state laws and complies with those that apply to our operations and to the personal data we process.
Our role under US state privacy laws
A critical distinction applies under most US state privacy laws: Funraisin operates primarily as a service provider or processor when handling data on behalf of our charity customers. Under most state laws, the obligations to provide privacy notices, obtain consent, and respond to consumer rights requests fall on the data controller — the charity or nonprofit running the campaign — not on Funraisin as the service provider.
Funraisin contractually commits, through our Data Processing Agreement, not to sell or share personal data, not to retain or use it outside the scope of providing our platform services, and to assist our customers in fulfilling their obligations to individuals under applicable US state law.
California — CCPA and CPRA
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the most comprehensive state privacy law in the United States. California residents have the following rights:
- Right to know — to request disclosure of the categories and specific pieces of personal data we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it
- Right to delete — to request deletion of personal data we have collected, subject to certain exceptions
- Right to correct — to request correction of inaccurate personal data
- Right to opt out of sale or sharing — Funraisin does not sell personal data. We do not share personal data for cross-context behavioural advertising
- Right to limit use of sensitive personal information — to direct us to limit our use of sensitive personal information to what is necessary to provide our services
- Right to non-discrimination — we will not discriminate against you for exercising any CCPA/CPRA right
Shine the Light: California residents may request information about disclosures of personal data to third parties for their own direct marketing purposes in the preceding calendar year. Funraisin does not make such disclosures.
Submitting a request: California residents may submit a rights request by emailing dpo@funraisin.co. We will verify your identity before processing the request and respond within 45 days, with a single 45-day extension available where reasonably necessary.
Children's Online Privacy — COPPA
The Children's Online Privacy Protection Act (COPPA) prohibits the collection of personal data from children under the age of 13 in the United States without verifiable parental consent. Funraisin's platform is not directed at children, and we do not knowingly collect personal data from children under 13.
Our charity customers are responsible for ensuring that their campaigns, forms, and event registrations comply with COPPA where applicable. Specifically:
- Customers must not use Funraisin to collect personal data from users they know to be under 13 years of age without implementing a verifiable parental consent process;
- Where a customer's campaign is directed at or likely to attract children under 13, they must notify Funraisin in advance and implement appropriate age-gating or parental consent mechanisms;
If we become aware that personal data has been collected from a child under 13 without appropriate parental consent, we will take steps to delete that data promptly. If you believe this has occurred, please contact dpo@funraisin.co immediately.
Texas — Texas Data Privacy and Security Act (TDPSA)
The TDPSA came into effect on 1 July 2024. Texas residents have rights substantively similar to those under the CCPA, including rights to access, correct, delete, and port their personal data, and to opt out of processing for targeted advertising. As a service provider, Funraisin's primary obligations are contractual. Individuals wishing to exercise TDPSA rights in relation to a charity campaign should contact that organisation directly. For data Funraisin holds as a controller, contact dpo@funraisin.co.
Florida — Florida Digital Bill of Rights (FDBR)
The FDBR applies to controllers that operate in Florida and meet applicable processing thresholds. Where Funraisin's customers meet those thresholds, they are the data controller responsible for honouring Florida residents' rights. Funraisin will assist customers in fulfilling those obligations in accordance with our DPA.
New York — SHIELD Act
New York's SHIELD Act imposes data security requirements on any business handling personal data of New York residents, regardless of where the business is located. Funraisin maintains reasonable administrative, technical, and physical safeguards commensurate with the size and complexity of our business and the sensitivity of the data we hold, including our SOC 2 Type 2 certified security programme.
All US states — general rights and contact
Regardless of your state of residence, you may contact us at dpo@funraisin.co to: ask what personal data Funraisin holds about you as a controller; request access, correction, or deletion of that data; or ask us to direct you to the appropriate data controller if your enquiry relates to a charity campaign. We will respond to all verified US privacy requests within 45 days.
Note: The US state privacy law landscape continues to evolve. Funraisin conducts an annual review of newly enacted state laws to assess whether additional obligations are triggered. We will update this policy as material changes are required.
If you have any questions or concerns regarding this Privacy Policy please contact us at dpo@funraisin.co, or by mail to:
Attn: Data Protection Officer
Funraisin, 1 Sussex St, Barangaroo, NSW, 2000
Australia


