Privacy Policy

Last updated: July 28, 2026

Overview

StewardKit ("we," "our," or "us") provides a donation management platform for faith-based organizations. This Privacy Policy describes how we collect, use, and protect your personal information when you use our services.

Information We Collect

Information You Provide

  • Account Information: When you register, we collect your name, email address, and organization details.
  • Donation Information: When you make a donation, we collect your name, email, mailing address, and payment information. Payment card and bank account details are processed securely by our payment processors (CardConnect, a Fiserv company, and Stripe) and the full card or account number is never stored on our servers.
  • Payment Method Characteristics: We record non-identifying attributes of the payment method used, such as the card brand, the last four digits, whether it is a credit, debit, or business card, and the issuing institution. This information describes the card product rather than you, and we use it only to process payments, prevent fraud, and reconcile processing costs. We do not use it to profile donors, and it is not shared with the organization you give to beyond the payment details shown on your receipt.
  • Phone Number: If you provide a phone number for express checkout, we may send you a one-time verification code via SMS to authenticate your identity when accessing saved payment methods.

Information Collected Automatically

  • Usage Data: We collect information about how you interact with our platform, including pages visited and features used.
  • Device Information: We may collect information about your device, browser type, and IP address for security and analytics purposes.

How We Use Your Information

We use the information we collect to:

  • Process donations and generate tax receipts
  • Send transactional messages, including donation confirmations and verification codes
  • Provide customer support
  • Improve our services and develop new features
  • Comply with legal obligations

SMS Communications

If you provide your phone number, we may send you SMS messages solely for transactional purposes, specifically:

  • One-time verification codes to authenticate your identity when using express checkout with saved payment methods

We do not send marketing or promotional messages via SMS. Message and data rates may apply. You can opt out of SMS verification by not using the express checkout feature.

Email Analytics

Newsletters and announcements sent through StewardKit include standard delivery and engagement tracking: whether the receiving mail server accepted the message, whether images in it were loaded, and whether links in it were followed. Receipts, tax statements, sign-in links and other transactional email are not tracked this way.

Open tracking is approximate and frequently wrong in both directions. Many mail providers load images automatically for privacy or security reasons, which registers as an open that never happened, and many people read email with images switched off, which registers as no open at all. We treat these figures as a rough signal and nothing more, and we do not present them to your organization as a record of who read a message.

You can stop promotional and announcement email at any time using the unsubscribe link in any such message, or by asking your organization directly. Essential messages — schedule changes, cancellations, and receipts for money you have given — are not promotional and continue regardless.

Information Sharing

We do not sell, rent, or share your personal information with third parties for their marketing purposes. We may share information with:

  • Organizations: Donation information is shared with the organization you donate to, so they can acknowledge your gift and provide tax receipts.
  • Service Providers: We use third-party services (such as CardConnect/Fiserv and Stripe for payment processing, and Twilio for SMS) that help us operate our platform. These providers are contractually obligated to protect your information.
  • Legal Requirements: We may disclose information if required by law or to protect our rights and safety.

Data Security

We implement industry-standard security measures to protect your personal information:

  • All data is transmitted using TLS/SSL encryption
  • Payment information is processed by PCI DSS Level 1 compliant providers (CardConnect, a Fiserv company, and Stripe); card numbers are tokenized and never reach our servers
  • Access to personal data is restricted to authorized personnel only
  • We regularly review and update our security practices

Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Donation records are retained for at least 7 years for tax purposes.

Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information (subject to legal retention requirements)
  • Opt out of non-essential communications

Children's Privacy

Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Email: [email protected]