Privacy Policy

Last updated: July 28, 2026

1. Scope and current implementation

This page describes data practices visible in the current BluGives web application. It is not a claim that every backend, hosting, identity-provider, payout, or payment-provider practice is controlled by this repository. When a third-party service is used, its own terms and privacy notice also apply.

2. Information you provide

Account registration sends your name, email address, phone number, password, selected role, and email confirmation code to the configured BluGives API. After registration, profile features may collect location, biography, photo, hardship tags, preferences, social-account links, and recipient payout details. Support email may contain the information you choose to send.

Do not send passwords, one-time codes, complete payment-card data, or unnecessary identity documents through profile stories, chat, analytics events, or support email.

3. Browser storage and authentication

The current web application stores an authentication token and serialized user data in browser local storage so the session can continue across page loads. Temporary social-authentication state and recent payment-result context may use session storage. Browser storage can be exposed on a compromised or shared device, so sign out when finished and avoid using an untrusted browser.

4. Social sign-in and account links

If you choose a supported social provider, BluGives exchanges authorization data with that provider and the configured API. The application may receive account identifiers, profile fields, provider status, or other data returned by that integration. A connected account is a limited profile signal; it does not prove legal identity, financial need, truthfulness, or use of funds.

5. Payments and payout details

Production payment-provider authorization and capture are not implemented in this web repository. No donor should enter a PayPal or other provider password into BluGives. The interface must not report or record a successful payment until a real provider confirms it.

Recipient profiles can submit payout identifiers to the configured API. Treat those identifiers as sensitive financial-contact data. This site must not collect a donor's third-party payment-provider password or report a successful payment without a real provider confirmation.

6. Optional analytics

Google Analytics and Vercel Analytics load only after you select “Allow analytics” in the current web interface. If allowed, the site can measure page activity and product events such as registration started, sign-up completed, login, recipient viewed, donation started, checkout unavailable, and payment-result page viewed. Event properties are designed to avoid names, emails, phone numbers, passwords, one-time codes, payment-card data, profile stories, and other sensitive form content.

Your choice is stored in local storage under blugives:analytics-consent. You can clear site storage in your browser to reset the choice. Selecting “No analytics” prevents those analytics scripts from loading through this interface.

7. Sharing and external services

Data may be sent to the configured BluGives API, hosting infrastructure, a social provider you choose, and analytics providers you permit. A future production payment integration would also send information to its disclosed provider. BluGives does not claim on this page that an unlisted vendor receives no data; infrastructure and backend operators must maintain a current subprocessors inventory.

8. Security, retention, and deletion limits

No web service can guarantee perfect security. The current repository uses browser and response-header safeguards, but it does not publish a complete backend security audit or a field-by-field retention schedule. Backend, hosting, social-provider, and future payment-provider records may follow separate retention requirements. A deletion request may not remove records that another provider controls or records that must be retained for legal, fraud-prevention, dispute, or accounting reasons.

9. Your choices and requests

You can sign out, unlink supported social accounts where the product permits, change your analytics choice by clearing site storage, and request access, correction, or deletion. Start with the Data Deletion page or email giveablu@gmail.com. Response timing and outcome depend on the request, applicable law, and systems involved.

10. Age limits and changes

The Terms require users to be at least 18 or the age of majority in their jurisdiction. BluGives may update this notice when product or provider behavior changes. The updated date above should change when material practices change.