logo
Create campaign Login/Sign-up
← Back to home
Legal

Privacy Policy

Last updated 27 Jul 2026

Contents
  • 1. Scope
  • 2. Information we collect
  • 3. How we use information
  • 4. Legal bases (EEA/UK and similar)
  • 5. How we share information
  • 6. International transfers
  • 7. Cookies, SDKs, and push notifications
  • 8. Security and storage of sensitive data
  • 9. Data retention
  • 10. Your rights and choices
  • 11. Children
  • 12. Third-party links and services
  • 13. Automated decisions
  • 14. Changes to this Policy
  • 15. Contact us

1. Scope

This Privacy Policy explains how Cashviber collects, uses, shares, and protects personal information across all surfaces of the Services (as defined in our Terms & Conditions):

  • the Campaign Site (fundraising.cashviber.com),
  • the Mobile App (iOS and Android), and
  • the Admin Portal ([ADMIN_DOMAIN], used only by authorized Operators).

It applies to Organizers, Donors, Wallet users, visitors, and Operators. Where a specific surface or role has particular practices, we note it. Defined terms have the meaning given in the Terms.

2. Information we collect

2.1 Information you provide

  • Account & identity data: name, username / $handle, email, phone number, password (stored hashed), profile photo, bio, language and currency preferences, and address.
  • Identity-verification (KYC) data: date of birth and government-issued identification documents and related images you submit for verification. This is sensitive data and is treated with heightened protection (Section 8).
  • Financial & transaction data: bank-account or payout details and payment-method identifiers (typically collected and tokenized by our Payment Partners, not stored in full by us), Wallet balances, transactions, contributions, withdrawals, and payout history.
  • Campaign & content data: Campaign titles, descriptions, goals, categories, and media (photos/videos) you upload, and messages or support requests you send us.

2.2 Information collected automatically

  • Device & usage data: IP address, device and OS identifiers, app version, language, pages/screens viewed, actions taken, referring URLs, timestamps, and diagnostic/crash logs.
  • Approximate location: derived from IP address for security, fraud-prevention, and compliance. We do not collect precise GPS location unless you grant permission for a feature that requires it.
  • Cookies & similar technologies on the Campaign Site and Admin Portal, and mobile SDKs/identifiers in the App (Section 7).

2.3 Information from third parties

  • Payment Partners and verification providers (e.g., payment/account processors, bank-linking and KYC/identity providers) return verification results, tokens, and transaction status.
  • Referrals and other users (e.g., a $handle or contact who sends or requests money from you).
  • App stores and, if you use it, social sign-in.

2.4 Operator (Admin Portal) data. For authorized Operators we process work-related account, role/permission, authentication, and activity-log/audit data to secure and administer the platform.

3. How we use information

We use personal information to:

  • provide and operate the Services — create and manage accounts, publish Campaigns and media, process contributions, run the Wallet, and enable send/request/withdraw and QR/$handle payments;
  • verify identity and comply with law — KYC, AML/CTF, sanctions screening, tax, accounting, and record-keeping obligations, and Payment Partner requirements;
  • prevent fraud and secure the Services — detect, investigate, and prevent fraud, abuse, and unauthorized access; apply limits, holds, and risk checks;
  • communicate with you — transactional, security, and service messages; support; and, with any required consent, product updates and marketing (which you can opt out of);
  • improve and develop the Services — analytics, troubleshooting, and quality;
  • administer the Admin Portal — access control, monitoring, and audit; and
  • enforce our Terms and establish, exercise, or defend legal claims.

4. Legal bases (EEA/UK and similar)

Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Services you request); legal obligation (KYC/AML, tax, responding to lawful requests); legitimate interests (security, fraud prevention, improving the Services, and limited marketing — balanced against your rights); and consent (e.g., certain cookies, precise location, and some marketing), which you may withdraw at any time. For sensitive identity data, we rely on the bases permitted for such data (e.g., substantial public interest / legal obligation / explicit consent, as applicable).

5. How we share information

We do not sell your personal information. We share it only as needed:

  • With Payment Partners and verification providers to process payments, link accounts, verify identity, and meet compliance obligations.
  • With service providers / sub-processors who host, store, secure, email, analyze, or support the Services on our behalf under contract (e.g., cloud/hosting and communications providers). A current list is available at [SUBPROCESSORS_URL].
  • With other users and the public, by design of the Services: your public profile and $handle may be discoverable (subject to your discoverability/"find me" settings); Campaign pages and their media are public; and a Donor's name may appear on a Campaign unless the Donor contributes anonymously. Do not upload anything to a Campaign you do not want to be public.
  • For legal reasons — to comply with law, regulation, legal process, or enforceable governmental request; to enforce our Terms; and to protect the rights, safety, and property of Cashviber, our users, or the public.
  • In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. International transfers

We may process and store information in countries other than yours, including where our infrastructure and providers operate. Where required, we use appropriate safeguards for cross-border transfers (e.g., Standard Contractual Clauses or an equivalent mechanism). Details: [TRANSFERS_CONTACT].

7. Cookies, SDKs, and push notifications

The Campaign Site and Admin Portal use cookies and similar technologies for essential functions (sessions, security, language), and, where applicable and consented, for analytics. The Mobile App uses device identifiers and SDKs for similar purposes and for crash reporting. You can control cookies via your browser and, on mobile, via OS-level permissions and settings. With your permission, the App may send push notifications; you can disable them in your device settings. See [COOKIE_POLICY_URL] for details and choices.

8. Security and storage of sensitive data

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and monitoring. Identity/KYC documents are stored on access-restricted, non-public storage and are served only through short-lived, signature-protected links to authorized viewers (the user themselves or an authorized Operator) — they are not publicly accessible. Payment-card and full bank details are handled by PCI-compliant Payment Partners and are not stored in full by us. No system is perfectly secure; you are responsible for keeping your credentials confidential and notifying us of any suspected compromise at [SECURITY_EMAIL].

9. Data retention

We retain personal information for as long as your account is active and as needed to provide the Services, and thereafter as required to comply with legal, tax, accounting, AML/KYC record-keeping, and dispute-resolution obligations (which for financial records may be several years), after which we delete or anonymize it. Retention periods vary by data type and legal requirement.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent. You can update much of your information in-app. To exercise other rights, contact [PRIVACY_EMAIL]; we will verify your identity and respond within the time the law requires. You will not be discriminated against for exercising your rights. We may decline requests where an exception applies (e.g., where we must retain data for legal/AML reasons).

  • EEA/UK: you may lodge a complaint with your local data-protection authority.
  • California (CCPA/CPRA): you have rights to know, delete, correct, and to opt out of "sale"/"sharing" — we do not sell or share personal information as defined by the CCPA/CPRA — and to limit use of sensitive personal information. Submit requests to [PRIVACY_EMAIL].

11. Children

The Services are not directed to children under 18, and we do not knowingly collect their personal information. If you believe a minor has provided us data, contact [PRIVACY_EMAIL] and we will delete it.

12. Third-party links and services

The Services link to and integrate third parties (Payment Partners, verification providers, app stores, maps, social-sharing). Their handling of your data is governed by their own privacy notices, which we encourage you to read. We are not responsible for third-party practices.

13. Automated decisions

We use automated tools for fraud, risk, and compliance screening. Where such processing produces legal or similarly significant effects and the law grants you rights (e.g., under GDPR Art. 22), you may request human review by contacting [PRIVACY_EMAIL].

14. Changes to this Policy

We may update this Policy. We will post the updated version with a new effective date and, for material changes, provide reasonable notice. Your continued use after the changes take effect constitutes acceptance where permitted by law.

15. Contact us

Millennial R&D, LLC — "Cashviber"

[REGISTERED_ADDRESS]

Privacy: [PRIVACY_EMAIL] · Data Protection Officer / EU-UK Representative (if applicable): [DPO_CONTACT] · Security: [SECURITY_EMAIL]

*See also our Terms & Conditions.*

Terms & Conditions · Privacy Policy

Copyright © 2026 Millennial R&D, LLC. All Rights Reserved.