Privacy Policy

Your privacy is important to us. Learn how we collect, use, and protect your personal information.

Last updated: 12/5/2025

1. Information We Collect

Personal Information

  • Account Information: Email address, name, password (encrypted)
  • Donation History: Amounts, dates, projects supported, payment methods
  • Communication Preferences: Email settings, notification preferences, quiet hours
  • Tax Information: Receipts, annual statements, tax document access logs

Automatically Collected Information

  • Usage Data: Pages visited, features used, session duration
  • Device Information: IP address, browser type, operating system
  • Security Logs: Login attempts, access patterns, security events

2. How We Use Your Information

Service Delivery

  • • Process donations and payments
  • • Generate tax receipts and statements
  • • Send impact notifications and updates
  • • Provide customer support

Communication

  • • Send donation confirmations
  • • Notify about evidence updates
  • • Share platform updates
  • • Respond to support requests

Security & Compliance

  • • Prevent fraud and abuse
  • • Maintain audit trails
  • • Comply with tax regulations
  • • Ensure platform security

Improvement

  • • Analyze usage patterns
  • • Improve user experience
  • • Develop new features
  • • Monitor platform performance

3. Data Sharing

We Do NOT Sell Your Data

We never sell, rent, or trade your personal information to third parties for marketing purposes.

Limited Sharing

Payment Processors

Stripe and Paystack receive payment information necessary to process transactions. They are PCI-compliant and bound by strict data protection standards.

Email Service Provider

MailerSend processes email addresses and content for notification delivery. They are SOC 2 compliant and do not use your data for their own purposes.

Legal Requirements

We may share information when required by law, court order, or to protect our rights and the safety of our users.

4. Data Security

Encryption

  • • TLS 1.3 for data in transit
  • • AES-256 for data at rest
  • • End-to-end encryption for sensitive data
  • • Encrypted backups and archives

Access Control

  • • Role-based access control (RBAC)
  • • Multi-factor authentication
  • • Principle of least privilege
  • • Regular access reviews

Infrastructure

  • • Google Cloud Platform security
  • • Firestore security rules
  • • App Check protection
  • • Rate limiting and DDoS protection

Monitoring

  • • 24/7 security monitoring
  • • Automated threat detection
  • • Incident response procedures
  • • Regular security audits

5. Your Rights

Access & Portability

You can request a copy of all personal data we hold about you in a machine-readable format.

Contact: privacy@ebun.com

Correction

You can update your account information and correct any inaccurate data through your dashboard.

Available in: Account Settings

Deletion

You can request deletion of your account, subject to legal and tax compliance requirements.

Note: Tax records retained for 7 years

Communication Control

You can control email notifications, set quiet hours, and manage communication preferences.

Available in: Notification Settings

6. Data Retention

Retention Periods

Account InformationUntil account deletion
Tax Documents7 years (legal requirement)
Audit Logs3 years
Security Logs1 year
Usage Analytics2 years (anonymized)

Automatic Deletion

We automatically delete personal data when retention periods expire, except where legal requirements mandate longer retention (e.g., tax records).

7. Cookies & Tracking

Essential Cookies

These cookies are necessary for the platform to function properly and cannot be disabled.

  • Session cookies: Maintain your login session and security
  • Authentication cookies: Verify your identity and permissions
  • Security cookies: Protect against CSRF attacks and maintain security

Analytics Cookies

These cookies help us understand how you use our platform to improve your experience.

  • Usage analytics: Track page views and feature usage (anonymized)
  • Performance monitoring: Identify and fix technical issues
  • Error tracking: Improve platform stability and user experience

Third-Party Cookies

Payment processors and other service providers may set their own cookies.

  • Stripe: Payment processing and fraud prevention
  • Paystack: Nigerian payment processing
  • MailerSend: Email delivery tracking

8. Contact Us

Privacy Questions

Email
privacy@ebun.com
Response Time
Within 48 hours

Data Protection Officer

Email
dpo@ebun.com
Specialized Support
For complex privacy requests

Your Privacy Matters

We're committed to protecting your privacy and being transparent about our data practices. If you have any questions or concerns about this privacy policy, please don't hesitate to contact us.