Privacy Policy
ScanRaise is operated by StanHattie LLC ("we", "us", "our"). This Privacy Policy describes how we collect, use, and protect your information when you use our platform.
1. Information We Collect
Organization accounts: Name, email address, phone number, organization name, address, and role within the organization.
Donors: Name and email address (if provided), donation amount, and any messages included with donations. This applies to donations made through individual fundraiser QR codes, organization-level donation pages, event ticket purchases, and merchandise orders.
Text-to-give users: Mobile phone number and message text when you contact our text-to-give number. Our delivery record stores privacy-protecting digests, provider message identifiers, delivery status, and provider failure details. See the SMS / Text Messaging section (5b) below.
Event attendees: Name and email address provided during ticket purchase or free event registration.
Store buyers: Name, email address, size selection, and order details for merchandise purchases.
Auction bidders: Name, email address, bid amounts, and buy-now purchase details.
Raffle entrants: Name, email address, ticket quantity, and entry details.
P2P fundraiser creators: Name, email address, display name, personal story text, goal amount, and optional photo URL. Edit access is managed via time-limited HMAC tokens sent to the creator's email.
Email campaign recipients: Email addresses of donors who have transacted with an organization. Unsubscribe preferences are recorded per organization.
Organizer mailing lists: Organization administrators may import contact names, email addresses, list membership, and custom fields used for their own fundraising communications.
Donor CRM data: Organizations may add tags and notes to donor records. Tags and notes are visible only to organization admins.
Fundraiser participants: Adult organizers control the participant display name. ScanRaise's roster templates and Clever import format names as first name and last initial, but other manual and connected roster paths can store a display name supplied by the organizer. Organizers should use first name and last initial for children and must review imported names before publishing participant pages. Participants may use a private phone-browser activity tracker. Participants can optionally connect Fitbit, select a day, review the daily summary of steps, distance, and active minutes, and choose whether to import it.
Campaign content: Organization logos, campaign descriptions, and milestone information uploaded by organizers.
2. Information Collected Automatically
When you use ScanRaise, we automatically collect: device information, IP address, browser type, operating system, pages visited, QR codes scanned, and time spent on the platform. We use cookies for essential platform functionality and analytics.
3. Payment Data and Stripe
ScanRaise stores the donor identity and transaction history described above for receipts, reporting, and the donor CRM. Stripe hosts Checkout and handles payment credentials. ScanRaise does not collect or store full credit card numbers or bank account details. Stripe returns limited transaction data such as the donation amount, Stripe transaction identifiers, and transaction status. Stripe's handling of payment information is governed by Stripe's Privacy Policy.
4. How We Use Your Information
- Provide, maintain, and improve the platform
- Process donations and fund transfers
- Send donation receipts and campaign updates
- Detect and prevent fraud
- Comply with legal obligations
- Analyze usage to improve our services
5. How We Share Your Information
- With Organizations: The organization receiving or fulfilling a transaction can receive the donor or buyer name, email address, amount, message, order or ticket details, and supported cross-transaction history for contact, reporting, fulfillment, and fundraising
- Connected social services: When an organization administrator directs ScanRaise to connect or publish through Meta or Bluesky, we send the authorized account identifiers and selected post content to that service
- Legal requirements: When required by law, subpoena, or court order
- Business transfers: In connection with a merger, acquisition, or sale of assets
We never sell your personal information to third parties.
Optional integrations and public data sources
- PowerSchool (powerschool.com) - Optional district sign-in when configured. A user's browser connects to the district's PowerSchool OIDC service, and ScanRaise receives the basic identity claims authorized for login.
- Skyward or another district SAML identity service - Optional district sign-in when configured. A user's browser connects to the district identity provider, and ScanRaise receives the identity and role attributes authorized for login.
- FRED (stlouisfed.org) - Economic context for organization insights when configured. An organization's state selects a public economic series identifier sent to FRED. No donor, participant, or registered-user record is sent.
- American Heart Association TeamRaiser (heart.org) - Optional public school and participant search. ScanRaise sends user-entered school or team search text and receives public fundraising team and participant results. No donor or registered-user account data is sent.
5a. Subprocessors
ScanRaise uses the following service providers to operate the platform. Each processes only the data needed to perform its specific function.
- Railway (railway.com) - Application hosting, PostgreSQL live database, and provider-managed database backups. After the encryption migration, raw participant tracking details are application-encrypted before Railway stores them. Older backups are protected by Railway storage encryption but can contain legacy plaintext database fields until they expire or are removed.
- Cloudflare (cloudflare.com) - Frontend hosting, DNS, and CDN
- Stripe (stripe.com) - Payment processing (PCI DSS Level 1) for donations, event tickets, store orders, auctions, and raffles
- Resend (resend.com) - Transactional email delivery (magic-link sign-in, donation receipts, ticket and order confirmations, campaign notifications)
- Backblaze B2 (backblaze.com) - Encrypted storage (SSE-B2 / AES-256 at rest) for uploaded files and daily database backups. Backup objects follow the configured provider lifecycle. Older backup objects can contain legacy plaintext database fields inside the provider-encrypted archive until they expire or are removed.
- Migadu (migadu.com) - Inbound email hosting for support inboxes
- Twilio (twilio.com) - Inbound and outbound SMS for text-to-give on our dedicated toll-free number
- Microsoft (microsoft.com) - Entra ID OIDC sign-in for staff who use Microsoft 365 / Entra (cert-based
client_assertionJWT, no client secret) - Google (google.com) - Google Workspace / Google for Education OIDC sign-in for staff who use Google for school
- Google Maps Geocoding (cloud.google.com) - Used by political campaigns only. Converts imported voter addresses into latitude/longitude coordinates, and reverse-geocodes the GPS coordinate of each canvasser door-knock into a street address. No donor data and no registered-user account data is sent to Google.
- Clever (clever.com) - K-12 sign-in for teachers via Clever Library. Teachers grant ScanRaise access from inside Clever; we receive their basic profile and (when granted) their classroom sections and student names by first name and last initial.
- ClassLink (classlink.com) - K-12 SSO for districts that use ClassLink (admin, parent, and teacher roles)
- Fitbit (fitbit.com) - Optional participant-initiated OAuth integration that, under activity and profile scopes, returns the selected day's daily summary of steps, distance, and active minutes after the participant asks ScanRaise to retrieve it.
- Anthropic (anthropic.com) - Campaign messaging analysis and draft assistance. Relevant organizer-provided campaign text and campaign context can be processed to produce the requested insight.
- OpenStreetMap (openstreetmap.org) - Map tile delivery for map-enabled pages. A visitor's browser sends the tile request, IP address, and ordinary request metadata to the tile infrastructure.
- unpkg (unpkg.com) - Browser delivery of selected frontend libraries. A visitor's browser sends the asset request, IP address, and ordinary request metadata.
- Google Analytics 4 (google.com) - Aggregate traffic analytics (only with cookie consent; Consent Mode v2)
- Microsoft Clarity (clarity.microsoft.com) - Session recording and heatmaps (only with cookie consent; hard-gated)
- Plausible (plausible.io) - Cookieless traffic analytics
- UptimeRobot (uptimerobot.com) - External uptime monitoring (no user data)
- Sentry (sentry.io) - Error reporting and service reliability. Error events can include request context needed to diagnose a failure; we limit use to operating and securing the service.
This list is kept current. When a new subprocessor is added, we update this page before it begins processing user data.
5b. SMS / Text Messaging (Text-to-Give)
If you use our text-to-give service by texting an organization's keyword, a fundraiser code, or an organization name to (833) 991-9251, we receive your mobile phone number and message text. We use them only to match and send the requested reply, honor opt-out requests, prevent duplicate replies and abuse, and record or troubleshoot delivery. ScanRaise's queryable delivery record stores privacy-protecting digests instead of the raw phone number and message body, together with provider message identifiers, the matched destination, delivery status, and any provider failure code or reason. Text-to-give is entirely user-initiated: we send SMS only in direct response to a message you send us first.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
- Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services.
- A keyed privacy-protecting digest of the phone number and its current STOP or START state are kept on an application suppression list so ScanRaise does not send another text-to-give reply while the state is STOP.
- You can opt out at any time by replying STOP, or get assistance by replying HELP. Full SMS Program terms are in our Terms of Service.
6. Children's Privacy (COPPA)
ScanRaise is a fundraising platform for organizations and their adult administrators, and it can support participants under 13. Organizers control participant display names and should use first name and last initial for children. A participant under 13 may use a private activity tracker or submit a scavenger location or secret-code check-in only after ScanRaise records a parental-consent grant. Without a recorded grant, those features are blocked. The current workflow sends a parent-directed email link and records the grant action, timestamp, and IP address. Additional consent verification and parent review, deletion, and refusal controls remain part of the product requirement. Participants under 13 do not create ScanRaise accounts or provide their own email addresses. We retain parental-consent evidence and protect and delete raw tracking details as described below.
7. Data Retention
We retain account information for the duration of your account plus 3 years for legal and tax compliance. Raw participant tracking payloads, complete check-in rows, and Fitbit connections in the live database are hard-deleted after 90 full days have elapsed from the campaign's effective end. Participant-level activity units remain without raw payloads for leaderboards and pledge calculations. Location-free point and check-in counts remain for scavenger results. Donation, pledge, parental consent, and audit records remain under their separate financial, legal, and compliance schedules. Donation records are retained for 7 years per IRS guidelines. Stripe retains payment data per its own retention policy. Provider-protected Railway and Backblaze backups can remain until each configured backup lifecycle expires. Backups created before the application-encryption migration can contain legacy plaintext database fields inside provider-encrypted storage until they expire or are removed. You may request deletion of your data at any time by contacting us, subject to records that law or financial integrity requires us to preserve.
8. Data Security
We use industry-standard security measures including encryption in transit (TLS/SSL), application-level encryption of raw participant tracking details before database storage, secure hosting infrastructure, and access controls. Payment data is handled by Stripe, which maintains PCI DSS compliance. No system is 100% secure, and we cannot guarantee absolute security of your data.
9. Your Rights and Choices
- Request access to, correction of, or deletion of personal data, subject to identity verification and applicable retention exceptions
- Opt out of marketing communications
- Manage cookie preferences through your browser settings
- Disconnect your Stripe account at any time
- Unsubscribe from organization email campaigns via one-click unsubscribe link
- Request an organization-scoped access export. The current automated export covers the donor profile and supported donation, ticket, and order history
- Request organization-scoped erasure. The current automated workflow anonymizes identifiers in supported records, but it does not yet cover every data source and field
10. Data Erasure (Right to Be Forgotten)
To submit an access or erasure request, email support@scanraise.com and identify the organization involved. We verify the request before processing it. The current automated access export includes the donor profile and supported donation, ticket, and order history. It does not yet include every FEC or matching-gift field, auction or raffle record, P2P content, mailing-list membership, unsubscribe or audit record, or transaction state. The current erasure workflow anonymizes core identifiers in supported donations, tickets, orders, auction bids, raffle entries, and P2P creator contact fields, and deletes the donor CRM record. It does not yet remove every free-text or media field, FEC or matching-gift field, raffle winner field, public P2P field, or mailing-list membership. ScanRaise is building comprehensive export and erasure coverage for every personal-data source. A response is not described as complete unless all known sources are resolved or the requester is told what was excluded or retained and why. Anonymized financial records and other records required for legal, security, fraud-prevention, or financial-integrity purposes may be retained. Requests are scoped to one organization at a time.
11. State Privacy Rights
Iowa: Under the Iowa Consumer Data Protection Act, Iowa residents have the right to access, delete, and opt out of the sale of their personal data.
California: Under the CCPA/CPRA, California residents have the right to know what personal information is collected, request deletion, opt out of the sale of personal information, and not be discriminated against for exercising these rights.
To exercise any of these rights, contact us at support@scanraise.com.
12. Participant Tracking and Sensor Data
What we collect: GPS coordinates during active tracking or check-in, accelerometer samples used for step counting, browser and device information, and limited timing, session, and verification metadata.
Purpose: Activity verification for athon-style fundraisers (walk-a-thons, run-a-thons, swim-a-thons, read-a-thons, and similar campaigns where donors pledge per unit of activity).
Consent: Sensor collection requires an explicit participant action and any required browser permission. A Fitbit connection uses participant-initiated OAuth. Participants under 13 must also have recorded parental consent before the private tracker or Fitbit connection is available. ScanRaise does not collect participant sensor data passively.
Storage and deletion: Submitted GPS coordinates, motion samples, Fitbit activity details, provider identifiers, OAuth credentials, and detailed device, timing, session, and verification data are application-encrypted before database storage. Campaign and participant links, tracking mode and status, submission time, activity or point totals, a selected check-in waypoint, and limited provider-connection fields remain queryable during the live retention window. The live database hard-deletes raw payloads, check-in rows, waypoint links, and Fitbit connections after 90 full days have elapsed from the campaign's effective end. Provider-protected backups follow the configured Railway and Backblaze lifecycles. Backups created before the application-encryption migration can contain legacy plaintext database fields inside provider-encrypted storage until they expire or are removed. Participant-level activity, point, and count totals and a generic activity record timestamp remain without raw location, sensor, device, waypoint, or provider payloads. Required financial, parental consent, and audit records remain under their separate schedules.
No sale: We never sell, license, or share raw biometric or sensor data with third parties.
Fitness accounts: Participants can optionally connect Fitbit, select a day, review the daily summary of steps, distance, and active minutes, and choose whether to import it. The connection uses participant-initiated OAuth with activity and profile scopes. Fitbit OAuth access and refresh tokens are application-encrypted before database storage. The imported activity record includes the selected date and the reviewed steps, distance, and active minutes used for the campaign.
BIPA compliance: We do not collect fingerprints, voiceprints, retina scans, or facial geometry. GPS coordinates and accelerometer readings are not classified as biometric identifiers under the Illinois Biometric Information Privacy Act.
Data subject requests: You may submit an access or deletion request for verification data at any time. We verify and process it under the current workflow and retention exceptions described in sections 7, 9, and 10.
Children: Activity tracking for participants under 13 requires parental consent as described in our COPPA section above.
12a. Political Canvassing Data
This section applies only to organizations that run political canvassing campaigns on ScanRaise (campaigns marked is_political). It does not apply to standard nonprofit, school, church, or sports fundraising.
Voter file imports: Campaign administrators may upload a voter file as a CSV. ScanRaise stores the street address, city, state, ZIP code, and optional party affiliation for each row. Voter names are stripped at the time of import and are never stored. The original CSV is not retained after parsing. Imports are capped per campaign as a cost guardrail on geocoding.
Canvasser GPS: Canvassers use a mobile web app to log doors. GPS collection is strictly opt-in: on first visit the canvasser sees a consent screen and must grant browser geolocation permission. GPS is then used to (a) stamp each door log with a coordinate, (b) sort the nearest pending voter addresses for the canvasser, and (c) render the canvasser's position on the turf map. GPS is not collected when the consent screen is declined.
Door logs: Each door knock writes a row containing the GPS coordinate, the reverse-geocoded street address, the outcome (knocked, no answer, conversation, refused, do-not-contact), and free-text notes typed by the canvasser. The submitted coordinate, reverse-geocoded address, and notes are application-encrypted before database storage. The outcome, event time, and a queryable link to a matched imported voter address remain available during the live retention window. Door logs are visible to campaign administrators and to the canvasser who created them.
Retention: Voter address rows and complete door-log rows, including voter-address links and event times, are hard-deleted from the live database after 90 full days have elapsed from the campaign's effective end. Participant-linked door totals and counts by outcome remain without raw locations, voter-address links, notes, or event times. Provider-protected backup copies follow the configured backup lifecycle and older backups can contain legacy database fields until they expire or are removed. Donations recorded against a political campaign are retained per the standard 7-year IRS schedule described in section 7.
FEC reportable mode: Pro political campaigns may enable FEC reportable mode. The product requirement is to collect contributor name, address, employer, and occupation when itemization rules apply and include those fields in an FEC CSV export. Reportability can depend on a contributor's aggregate contributions during the applicable reporting period, not only one transaction. ScanRaise does not determine legal eligibility or file with the Federal Election Commission. The campaign administrator must verify aggregation, field completeness, corrections, and filing requirements with campaign finance counsel before relying on an export.
No sale, no sharing: Voter file data, canvasser GPS, and door logs are never sold or licensed. Google Maps Geocoding, listed in section 5a, receives addresses for forward geocoding and door coordinates for reverse geocoding.
Subject access and erasure: A registered voter may contact ScanRaise to request that their address row be deleted from any active political campaign. Because names are not stored, identification is by street address.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email or by posting notice on the platform. The "Last updated" date at the top reflects the most recent revision.
Contact
StanHattie LLC
731 SE Alices Rd PMB 1035
Waukee, IA 50263
(833) 278-5002
support@scanraise.com