Privacy Policy

Last updated: August 10, 2026

ScanRaise is operated by StanHattie LLC ("we", "us", "our"). This Privacy Policy describes how we collect, use, and protect your information when you use our platform.

1. Information We Collect

Organization accounts: Name, email address, phone number, organization name, address, and role within the organization.

Donors: Name and email address (if provided), donation amount, and any messages included with donations. This applies to donations made through individual fundraiser QR codes, organization-level donation pages, event ticket purchases, and merchandise orders.

Text-to-give users: Mobile phone number and message text when you contact our text-to-give number. Our delivery record stores privacy-protecting digests, provider message identifiers, delivery status, and provider failure details. See the SMS / Text Messaging section (5b) below.

Event attendees: Name and email address provided during ticket purchase or free event registration.

Store buyers: Name, email address, size selection, and order details for merchandise purchases.

Auction bidders: Name, email address, bid amounts, and buy-now purchase details.

Raffle entrants: Name, email address, ticket quantity, and entry details.

P2P fundraiser creators: Name, email address, display name, personal story text, goal amount, and optional photo URL. Edit access is managed via time-limited HMAC tokens sent to the creator's email.

Email campaign recipients: Email addresses of donors who have transacted with an organization. Unsubscribe preferences are recorded per organization.

Organizer mailing lists: Organization administrators may import contact names, email addresses, list membership, and custom fields used for their own fundraising communications.

Donor CRM data: Organizations may add tags and notes to donor records. Tags and notes are visible only to organization admins.

Fundraiser participants: Adult organizers control the participant display name. ScanRaise's roster templates and Clever import format names as first name and last initial, but other manual and connected roster paths can store a display name supplied by the organizer. Organizers should use first name and last initial for children and must review imported names before publishing participant pages. Participants may use a private phone-browser activity tracker. Participants can optionally connect Fitbit, select a day, review the daily summary of steps, distance, and active minutes, and choose whether to import it.

Campaign content: Organization logos, campaign descriptions, and milestone information uploaded by organizers.

2. Information Collected Automatically

When you use ScanRaise, we automatically collect: device information, IP address, browser type, operating system, pages visited, QR codes scanned, and time spent on the platform. We use cookies for essential platform functionality and analytics.

3. Payment Data and Stripe

ScanRaise stores the donor identity and transaction history described above for receipts, reporting, and the donor CRM. Stripe hosts Checkout and handles payment credentials. ScanRaise does not collect or store full credit card numbers or bank account details. Stripe returns limited transaction data such as the donation amount, Stripe transaction identifiers, and transaction status. Stripe's handling of payment information is governed by Stripe's Privacy Policy.

4. How We Use Your Information

5. How We Share Your Information

We never sell your personal information to third parties.

Optional integrations and public data sources

5a. Subprocessors

ScanRaise uses the following service providers to operate the platform. Each processes only the data needed to perform its specific function.

This list is kept current. When a new subprocessor is added, we update this page before it begins processing user data.

5b. SMS / Text Messaging (Text-to-Give)

If you use our text-to-give service by texting an organization's keyword, a fundraiser code, or an organization name to (833) 991-9251, we receive your mobile phone number and message text. We use them only to match and send the requested reply, honor opt-out requests, prevent duplicate replies and abuse, and record or troubleshoot delivery. ScanRaise's queryable delivery record stores privacy-protecting digests instead of the raw phone number and message body, together with provider message identifiers, the matched destination, delivery status, and any provider failure code or reason. Text-to-give is entirely user-initiated: we send SMS only in direct response to a message you send us first.

6. Children's Privacy (COPPA)

ScanRaise is a fundraising platform for organizations and their adult administrators, and it can support participants under 13. Organizers control participant display names and should use first name and last initial for children. A participant under 13 may use a private activity tracker or submit a scavenger location or secret-code check-in only after ScanRaise records a parental-consent grant. Without a recorded grant, those features are blocked. The current workflow sends a parent-directed email link and records the grant action, timestamp, and IP address. Additional consent verification and parent review, deletion, and refusal controls remain part of the product requirement. Participants under 13 do not create ScanRaise accounts or provide their own email addresses. We retain parental-consent evidence and protect and delete raw tracking details as described below.

7. Data Retention

We retain account information for the duration of your account plus 3 years for legal and tax compliance. Raw participant tracking payloads, complete check-in rows, and Fitbit connections in the live database are hard-deleted after 90 full days have elapsed from the campaign's effective end. Participant-level activity units remain without raw payloads for leaderboards and pledge calculations. Location-free point and check-in counts remain for scavenger results. Donation, pledge, parental consent, and audit records remain under their separate financial, legal, and compliance schedules. Donation records are retained for 7 years per IRS guidelines. Stripe retains payment data per its own retention policy. Provider-protected Railway and Backblaze backups can remain until each configured backup lifecycle expires. Backups created before the application-encryption migration can contain legacy plaintext database fields inside provider-encrypted storage until they expire or are removed. You may request deletion of your data at any time by contacting us, subject to records that law or financial integrity requires us to preserve.

8. Data Security

We use industry-standard security measures including encryption in transit (TLS/SSL), application-level encryption of raw participant tracking details before database storage, secure hosting infrastructure, and access controls. Payment data is handled by Stripe, which maintains PCI DSS compliance. No system is 100% secure, and we cannot guarantee absolute security of your data.

9. Your Rights and Choices

10. Data Erasure (Right to Be Forgotten)

To submit an access or erasure request, email support@scanraise.com and identify the organization involved. We verify the request before processing it. The current automated access export includes the donor profile and supported donation, ticket, and order history. It does not yet include every FEC or matching-gift field, auction or raffle record, P2P content, mailing-list membership, unsubscribe or audit record, or transaction state. The current erasure workflow anonymizes core identifiers in supported donations, tickets, orders, auction bids, raffle entries, and P2P creator contact fields, and deletes the donor CRM record. It does not yet remove every free-text or media field, FEC or matching-gift field, raffle winner field, public P2P field, or mailing-list membership. ScanRaise is building comprehensive export and erasure coverage for every personal-data source. A response is not described as complete unless all known sources are resolved or the requester is told what was excluded or retained and why. Anonymized financial records and other records required for legal, security, fraud-prevention, or financial-integrity purposes may be retained. Requests are scoped to one organization at a time.

11. State Privacy Rights

Iowa: Under the Iowa Consumer Data Protection Act, Iowa residents have the right to access, delete, and opt out of the sale of their personal data.

California: Under the CCPA/CPRA, California residents have the right to know what personal information is collected, request deletion, opt out of the sale of personal information, and not be discriminated against for exercising these rights.

To exercise any of these rights, contact us at support@scanraise.com.

12. Participant Tracking and Sensor Data

What we collect: GPS coordinates during active tracking or check-in, accelerometer samples used for step counting, browser and device information, and limited timing, session, and verification metadata.

Purpose: Activity verification for athon-style fundraisers (walk-a-thons, run-a-thons, swim-a-thons, read-a-thons, and similar campaigns where donors pledge per unit of activity).

Consent: Sensor collection requires an explicit participant action and any required browser permission. A Fitbit connection uses participant-initiated OAuth. Participants under 13 must also have recorded parental consent before the private tracker or Fitbit connection is available. ScanRaise does not collect participant sensor data passively.

Storage and deletion: Submitted GPS coordinates, motion samples, Fitbit activity details, provider identifiers, OAuth credentials, and detailed device, timing, session, and verification data are application-encrypted before database storage. Campaign and participant links, tracking mode and status, submission time, activity or point totals, a selected check-in waypoint, and limited provider-connection fields remain queryable during the live retention window. The live database hard-deletes raw payloads, check-in rows, waypoint links, and Fitbit connections after 90 full days have elapsed from the campaign's effective end. Provider-protected backups follow the configured Railway and Backblaze lifecycles. Backups created before the application-encryption migration can contain legacy plaintext database fields inside provider-encrypted storage until they expire or are removed. Participant-level activity, point, and count totals and a generic activity record timestamp remain without raw location, sensor, device, waypoint, or provider payloads. Required financial, parental consent, and audit records remain under their separate schedules.

No sale: We never sell, license, or share raw biometric or sensor data with third parties.

Fitness accounts: Participants can optionally connect Fitbit, select a day, review the daily summary of steps, distance, and active minutes, and choose whether to import it. The connection uses participant-initiated OAuth with activity and profile scopes. Fitbit OAuth access and refresh tokens are application-encrypted before database storage. The imported activity record includes the selected date and the reviewed steps, distance, and active minutes used for the campaign.

BIPA compliance: We do not collect fingerprints, voiceprints, retina scans, or facial geometry. GPS coordinates and accelerometer readings are not classified as biometric identifiers under the Illinois Biometric Information Privacy Act.

Data subject requests: You may submit an access or deletion request for verification data at any time. We verify and process it under the current workflow and retention exceptions described in sections 7, 9, and 10.

Children: Activity tracking for participants under 13 requires parental consent as described in our COPPA section above.

12a. Political Canvassing Data

This section applies only to organizations that run political canvassing campaigns on ScanRaise (campaigns marked is_political). It does not apply to standard nonprofit, school, church, or sports fundraising.

Voter file imports: Campaign administrators may upload a voter file as a CSV. ScanRaise stores the street address, city, state, ZIP code, and optional party affiliation for each row. Voter names are stripped at the time of import and are never stored. The original CSV is not retained after parsing. Imports are capped per campaign as a cost guardrail on geocoding.

Canvasser GPS: Canvassers use a mobile web app to log doors. GPS collection is strictly opt-in: on first visit the canvasser sees a consent screen and must grant browser geolocation permission. GPS is then used to (a) stamp each door log with a coordinate, (b) sort the nearest pending voter addresses for the canvasser, and (c) render the canvasser's position on the turf map. GPS is not collected when the consent screen is declined.

Door logs: Each door knock writes a row containing the GPS coordinate, the reverse-geocoded street address, the outcome (knocked, no answer, conversation, refused, do-not-contact), and free-text notes typed by the canvasser. The submitted coordinate, reverse-geocoded address, and notes are application-encrypted before database storage. The outcome, event time, and a queryable link to a matched imported voter address remain available during the live retention window. Door logs are visible to campaign administrators and to the canvasser who created them.

Retention: Voter address rows and complete door-log rows, including voter-address links and event times, are hard-deleted from the live database after 90 full days have elapsed from the campaign's effective end. Participant-linked door totals and counts by outcome remain without raw locations, voter-address links, notes, or event times. Provider-protected backup copies follow the configured backup lifecycle and older backups can contain legacy database fields until they expire or are removed. Donations recorded against a political campaign are retained per the standard 7-year IRS schedule described in section 7.

FEC reportable mode: Pro political campaigns may enable FEC reportable mode. The product requirement is to collect contributor name, address, employer, and occupation when itemization rules apply and include those fields in an FEC CSV export. Reportability can depend on a contributor's aggregate contributions during the applicable reporting period, not only one transaction. ScanRaise does not determine legal eligibility or file with the Federal Election Commission. The campaign administrator must verify aggregation, field completeness, corrections, and filing requirements with campaign finance counsel before relying on an export.

No sale, no sharing: Voter file data, canvasser GPS, and door logs are never sold or licensed. Google Maps Geocoding, listed in section 5a, receives addresses for forward geocoding and door coordinates for reverse geocoding.

Subject access and erasure: A registered voter may contact ScanRaise to request that their address row be deleted from any active political campaign. Because names are not stored, identification is by street address.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email or by posting notice on the platform. The "Last updated" date at the top reflects the most recent revision.

Contact

StanHattie LLC
731 SE Alices Rd PMB 1035
Waukee, IA 50263
(833) 278-5002
support@scanraise.com