Privacy Policy for charity: water

Privacy Notice Introduction & Scope

charity: water knows that you care how information about you is used and shared, and we appreciate you trusting that we will do so carefully and sensibly. This Privacy Policy explains our practices and the choices you can make about the way your information is collected and used by charity: water. It applies to donor information that we collect both online and offline.

This Privacy Notice ("Notice") applies to personal data charity: water and its affiliates ("charity: water," "we," "us," or "our") collects. This Notice also covers rights and choices related to your personal data.

Data We Collect

We collect data about you in different ways. For example, we collect data:

  • Directly from you. This includes when you make an account, sign up to get our emails, donate to us, or contact us.
  • Automatically. This includes through cookies, server logs, and other tools on our website or apps.
  • From other sources.

These can include our affiliates, vendors, social media, publicly available sources, and other companies.

The following are a few examples of our collection and use of data:

Account Registration

Examples of Personal data:

We collect your name and contact information when you make an account. We also collect data on the actions that you perform while logged in. You will have the option of adding other information like your picture.

Primary Purpose and Legal Basis:

We have a legitimate interest in providing account related functionalities to users. Accounts can offer easy navigation through the donation process. It can also help save your preferences, or give you access to your donation history.

Donor Information

Examples of Personal data:

We collect the name and contact information of our donors, including the employees of our corporate donors with whom we may interact. We may also collect background information about our donors from third party sources, including their likelihood and ability to make future donations.

Primary Purpose and Legal Basis:

We have a legitimate interest in contacting our donors and communicating with them about activities such as projects, services, and billing. We have a legitimate interest in better understanding our donors. If required by law, we obtain the consent of our donors prior to obtaining information about them from third party sources.

Use of Our Website

Examples of Personal data:

We use technology (e.g., a cookie or a pixel) to learn how you engage with our websites. This may include which links you click or what you type into our online forms. We may also track your IP address, the website that referred you to us, and data about your device.

Primary Purpose and Legal Basis:

We have a legitimate interest in making our website operate. We also use it to understand how you interact with our websites, gather analytics, improve our websites, and learn your preferences. We may also use this data to help detect and prevent fraud. Where required by law, we base the use of technologies upon consent.

Website Targeted Advertising Technology

Examples of Personal data:

We may let third parties place tracking technology on our websites (e.g., a cookie or a pixel). The third party might also collect data over time and across other websites. Among other things, they may use this data to serve ads tailored to your interests, which may include ads about donation opportunities.

Primary Purpose and Legal Basis:

Where required by law, we base the use of third-party tracking technologies upon consent. Users should click here for more information. You can also find more information about your options with regard to this technology in the Your Choices section below.

Demographics

Examples of Personal data:

We collect personal data, such as your age or your region.

Primary Purpose and Legal Basis:

We have a legitimate interest in understanding our users, donors, and potential donors better.

Email Interactions

Examples of Personal data:

If you receive email from us, we use tools to capture when you open our message, click on links or banners in it, or make purchases after receiving an email.

Primary Purpose and Legal Basis:

Where permitted by law, we use this technology to understand how you engage with our messages.

Job Applicants

Examples of Personal data:

If you apply for a job, we collect information needed to process your application. This may include your social security number. Providing this information is required for employment.

Primary Purpose and Legal Basis:

In some contexts, we are required by law to collect data about applicants. We also have a legitimate interest in using data to evaluate your application or consider you for other positions. If you become an employee, we will provide you with a separate privacy notice that explains how we collect, use, and share additional data about our employees.

Feedback/Support

Examples of Personal data:

If you provide feedback or contact us for support, we collect your name and email, as well as other content that you send.

Primary Purpose and Legal Basis:

We have a legitimate interest in receiving and acting upon feedback.

Mailing List

Examples of Personal data:

When you sign up for our mailing lists, we collect your contact information.

Primary Purpose and Legal Basis:

We have a legitimate interest in sharing information about our mission. Where required by law we will ask for your consent before communicating with you.

Mobile Devices

Examples of Personal data:

We collect information your device broadcasts when you visit our website.

Primary Purpose and Legal Basis:

We have a legitimate interest in identifying unique visitors and understanding how users engage with us on their mobile device.

charity: water store

Examples of Personal data:

We collect your name, billing, shipping, and email addresses, phone number, and credit or debit card information when you place an order.

Primary Purpose and Legal Basis:

We use your information to perform our contract to provide products to you.

Donations

Examples of Personal data:

We collect your name, billing, email addresses, phone number, and credit or debit card information when you make a donation.

Primary Purpose and Legal Basis:

We use your information to process your donation.

Co-branded Programs

Examples of Personal data:

We collect data that you provide as part of co-branded offer, or promotion, with other entities.

Primary Purpose and Legal Basis:

We may collect your information with another organization, such as a company that allows us to ask you for a donation on their website. When data is jointly collected, your information may be submitted, or sent, to both organizations. This privacy notice applies to our use of your data. You should review the privacy notice of the other entity to understand their use of your data.

Public Health and Safety

Examples of Personal data:

We may collect data from employees, guests, and others who visit our offices or attend our events. This may include body temperature, symptoms of illness, and underlying health conditions.

Primary Purpose and Legal Basis:

We have a legitimate interest in protecting the health and safety of our employees and guests. In some jurisdictions we may be required by law, regulation, or government order to collect and retain data related to public health and safety. We have a legal obligation to comply in such areas.

Surveys

Examples of Personal data:

We collect data you share through surveys. If a third-party offers a survey, the third party's privacy notice also applies to the collection, use, and disclosure of your data.

Primary Purpose and Legal Basis:

We have a legitimate interest in understanding your opinions.

Sweepstakes or contests

Examples of Personal data:

When you enter a sweepstakes or contest, we collect data about you such as your contact information.

Primary Purpose and Legal Basis:

We have a legitimate interest in operating the sweepstakes. We may also be required by law to collect such data.

User Content

Examples of Personal data:

If you choose to engage in forums, blogs, or other similar features offered by us, including submitting a review about your experience or creating a public team, we may maintain records about the content you post. This might include comments, reviews or questions as well as metadata associated with your content.

Primary Purpose and Legal Basis:

We use this data to understand your opinions and foster a safe environment on our websites.

Whistleblower hotline

Examples of Personal data:

We have a third party that runs a whistleblower hotline. We collect the personal data that individuals who use that hotline provide. This may include in their contact information, or information that relates to other individuals or employees. If you provide your contact information, we may not be able to keep it confidential in all cases.

Primary Purpose and Legal Basis:

We have a legitimate interest collecting information about issues that might violate our policies or procedures. In some situations we may need to disclose the information that someone provides to us. When that occurs, the disclosure might be based on their consent, our compliance with laws mandating disclosure, our legitimate business interest in running our business, or protecting someone.

How We Use Data

We also use data to:

  • Identify you when you visit our sites.
  • Complete transactions.
  • Improve or create experiences and offerings.
  • Streamline checkouts.
  • Conduct analytics.
  • Connect with you (e.g., addressing your requests, inquiries, issues, or feedback).
  • Promote our mission.
  • Market the products or services of our business partners.
  • Find and prevent malicious, deceptive, fraudulent, or illegal activity.
  • Find and prevent security incidents.
  • Enforce our policies and agreements.
  • Debug, find, and fix errors that impair our website and services.
  • Comply with legal or regulatory obligations.
  • Establish or exercise our rights
  • Defend against legal claims.
  • Manage our relationships.
  • For other reasons with your consent.

The sections above describe our main purposes in collecting your data, but often we have multiple purposes. For instance, if you make an online purchase or donation, we may collect your information to perform our contract with you. We also have a legitimate interest in maintaining that data so that we can easily address questions from you. As a result, our collection and processing of your data is based in different contexts on your consent, our need to perform a contract, our legal obligations, and/or our legitimate interest in conducting our business.

To the extent we store and use deidentified personal data, we will not try to reidentify the information, except to test our deidentification methods.

How We Share Data

In addition to the specific situations discussed elsewhere in this Notice we may share personal data in the following situations:

  • Affiliates and Acquisitions. We may share data with our affiliates (e.g., parent organizations, sister organizations, subsidiaries, joint ventures, or other companies under common control). If an organization acquires or enters negotiations to acquire, our organization, or our assets, we may share data with that company.
  • Other Disclosures without Your Consent. We may share data to cooperate with law enforcement, participate in a legal process, or for legal compliance. We may share your data to establish or exercise our rights, to defend against legal claims, to investigate, prevent, or act on possible illegal activities, threats to safety of person or property, or a violation of our policies. Your data may be shared to ship products to you.
  • Public. Some of our websites allow for comments, posts, and discussion in a public forum. If you post on these pages, what you share may be publicly available.
  • Service Providers. We may share your data with service providers. Service providers may help us to run our website, conduct surveys, provide technical support, process payments, fulfill orders, and more.
  • Professional Services. We may share personal data with our professional service providers, such as auditors or lawyers.
  • Other Disclosures with Your Consent. We may share your data with third parties when you consent or direct us to.

Some jurisdictions require us to disclose whether the following categories of personal data are collected, shared with third parties for a "business purpose," or "sold," or transferred for "valuable consideration." The table below indicates the categories of personal data we collect and transfer in a variety of contexts. We do not "sell" your personal data for money.

Identifiers - this may include things like name, alias, postal address, unique personal identifier, online identifier, email address, or account name.

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Business partners.
  • Data analytics providers.
  • Internet service providers.
  • Operating systems and platforms.
  • Other Service Providers.
  • Payment processors and financial institutions.
  • Professional services organizations, this may include auditors and law firms.
  • Social networks.

Sharing for Targeted Advertising:

  • Advertising networks.

Financial Information - this may include bank account number, credit card number, debit card number, and other financial information. This information is collected by our payment processors.

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Other Service Providers.
  • Payment processors and financial institutions.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • N/A

Commercial information - this may include information about products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Business partners.
  • Data analytics providers.
  • Internet service providers.
  • Other Service Providers.
  • Payment processors and financial institutions.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • Advertising networks.

Internet or other electronic network activity information - this may include browsing history, search history, and information regarding an individual's interaction with an internet website, app, or ad.

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Data analytics providers.
  • Internet service providers.
  • Other Service Providers.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • Advertising networks.

Audio, visual, or similar information

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Other Service Providers.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • N/A

Professional or employment-related information - this includes, for example, information submitted by job applicants.

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Other Service Providers.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • N/A

Inferences drawn from any of the information listed above

Disclosures for a Business Purpose:

  • Affiliates or subsidiaries.
  • Data analytics providers.
  • Professional services organizations, this may include auditors and law firms.

Sharing for Targeted Advertising:

  • N/A

Your Choices

Some areas give you a right to make the following choices:

  • Access. You may request access to your personal data or confirmation that we have data about you. In certain limited cases, you may ask to receive access to your data in a portable, machine-readable form.
  • List of Third-Party Recipients. In some areas, you may have the right to obtain a list of specific third parties to which we have disclosed information. For a list of the specific third parties to whom we have disclosed information, please navigate to the "Manage My Choices" link on our cookie banner, and then click on "show cookies." Please note, some areas also allow you to obtain a list of the categories of third parties to which we have disclosed personal information. You can find that information in the table above under the "How We Share Data" section.
  • Change. Our website allows you to change your account profile. If our website does not permit you to update or correct certain information, you can ask us to correct inaccurate or incomplete data by contacting us at the address below. We may keep historical data in our backup files as permitted by law.
  • Deletion. You may ask us to delete your personal data. If required by law, we will grant such a request, but note that in many cases, we must keep your personal data to comply with legal obligations, resolve disputes, enforce agreements, or for other business purposes.
  • Opt-out of Targeted Advertising. You may opt-out of online tracking based targeted advertising (e.g., cookies) by selecting "Manage My Choices" in our footer. Note that if you change browsers or devices, or if you clear your browser's cache, you may need to click the link again to apply your preference. We attempt to recognize Global Privacy Control (GPC) signals broadcast from web browsers as a valid opt-out request where required by applicable law. Please note that the GPC will apply only to your current browser. We do not recognize the "Do Not Track Signal." If there is a conflict between the GPC signal and a manual choice that you have made on our website regarding targeted advertising, we will honor your manual choice.
  • Objection to or Restriction of Certain Processing. In certain circumstances, you may object to the processing of your personal data, or ask that we restrict processing of your personal data. To do so, follow the instructions below.
  • Promotional Emails. You may provide us with your email address to allow us to send newsletters, surveys, offers, or other promotional content, as well as targeted offers from third parties. You can stop receiving such emails by following the unsubscribe instructions at the bottom of those emails. If you choose not to receive such emails, we may still send you service-related communications.
  • Promotional Text Messages. If you get a text message from us that has promotional content, you can opt-out of future text messages by replying "STOP."
  • Revocation Of Consent. Where we process your personal data based upon consent, you may revoke consent. Note, if you revoke consent for processing personal data, we may no longer be able to provide you some types of services.

Not all the rights above are absolute, and they do not apply in all circumstances. We may limit or deny a request because the law permits or requires us to. We will not discriminate against individuals who exercise a privacy right.

Submitting Requests

You may exercise the above rights through by contacting us via the contact information below. If you disagree with our denial of a request, you may appeal our decision by contacting us with the subject line "Appeal."

We will require you to prove your identity when making most types of requests. We may verify your identity by phone or email. Depending on your request, we may ask for information such as your name or the date of your last donation, or that provide us a signed declaration confirming your identity.

In some circumstances, you may designate an authorized agent to exercise rights on your behalf. If you are an authorized agent, you must attach a copy of a completed Authorized Agent Designation Form which shows that you may act on another's behalf.

How We Protect and Retain Data

No method of internet transmission or electronic storage is fully secure. While we use reasonable efforts to protect personal data, we cannot guarantee its security. If we are required to inform you about a security incident, we will do so electronically, in writing, or by phone, as the law permits.

Some of our websites permit you to create an account. You are responsible for selecting a unique and complex password and keeping it confidential. You are responsible for any access to or use of your account by someone who has obtained your password, whether or not you approved of such access or use. Notify us of unauthorized use of your password or account immediately.

We keep your personal data for only as long as necessary to fulfil the purposes in this Notice unless a longer retention period is required or permitted by law. This includes the purposes of satisfying legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the data. We also weigh the potential risk of harm from unauthorized use or disclosure of the data, the purposes for which we obtained the data and whether we can meet those purposes through other means, as well as applicable legal requirements.

Transmission Of Data To Other Countries

As a multi-national organization, we send data between and among our affiliates. As a result, we may process your data in a country with less stringent privacy laws than the laws in the country that you reside. Where possible, we treat personal data using the same privacy principles that guide the law of the country in which we first receive your data. By submitting your personal data to us you agree to the transfer, storage, and processing of your data in a country other than your country of residence including, but not limited to, the United States. For more information on our attempts to apply the privacy principles applicable in one area to data when it goes to another, contact us using the contact information below. You may also request a copy of any Standard Contractual Clauses we use for the transfer of your data outside of the EEA, which includes the categories of information transferred by contacting us using the contact information below.

Third-Party Applications/Websites

We may provide links to websites and other third-party content or services that we do not own or operate. We have no control over the privacy practices of websites or services we do not own. For details about such third parties' privacy practices, see their privacy notices.

Changes To This Privacy Notice

We may change our Notice and privacy practices. New notices will be published on our website. If changes are material, the Notice that was in place when you submitted personal data to us will generally govern that data unless you consent to the new Notice. Our Notice shows "effective" and "last updated" dates below. The effective date is the date the current version took effect. The last updated date is the date the current version was last substantively changed.

Contact Information

If you have questions, comments, or complaints on our privacy practices, or if you need to access this Notice in a different form due to a disability, please contact us. We will try to address your requests and provide you with additional privacy-related information.

info@charitywater.orgcharity: water Donation Processing Center
230 Franklin Rd., Ste. 11-II
Franklin, TN 37064(646) 688-2323

If you have further queries or requests relating to how we use Personal Data please contact our UK data protection officer at hello@charitywateruk.org. If you are not satisfied with our response and are in the European Union or United Kingdom, you may have a right to lodge a complaint with your local supervisory authority.

Last updated: June 2025