Privacy Policy

GiveRadar is a free charity intelligence platform operated by Timmermans Media OÜ, registered in Tallinn, Estonia. This policy explains what personal data we collect, why, how long we keep it, and the rights you have over it. We wrote it to be read, not survived.

Last updated: July 12, 2026
The short version
We publish charity data compiled from official public sources. How that works.
Your account email is never sold or shared, and we send no marketing you did not ask for. Who we share with.
Your donation tracker is private: only you can see it, and we never publish or share it. Your tracker.
Analytics only runs if you accept it. Essential and security cookies always run. Cookies.
Email info@giveradar.com to access, correct, or delete anything we hold. Your rights.
01

Who we are

GiveRadar is operated by Timmermans Media OÜ, a company registered in Tallinn, Estonia. For anything you read on charity pages, we present data published by others and attribute it to its source. For your account and the choices you make on the site, Timmermans Media OÜ is the data controller.

You can reach us about any privacy question, or to exercise any of the rights described below, at info@giveradar.com.

02

Information we collect

You can search GiveRadar and read any charity page without an account and without giving us personal data. We collect information only when you choose to use a feature that needs it:

Account data. Your email address, a hashed password, and an optional display name when you register.
Donation tracker records. Amounts, dates, currencies, and recurring commitments you add to your private tracker. Section 5.
Watchlist and alert preferences. The charities you save and whether you have turned on change alerts. Section 6.
Charity claim data. A work email, job title, verification codes, and any evidence documents you upload to claim an organization. Section 7.
Contributions. Reviews you write (email-verified) and edits you make to a profile you have claimed.
Technical and usage data. Your IP address, browser and device information, and, for API users, per-request logs. Section 8 and Section 9.
03

How we use your information, and our lawful basis

Under the GDPR we must have a lawful basis for each use of personal data. Here is every purpose and the basis it rests on:

Purpose
Lawful basis
Provide your account and the features you use
Performance of our agreement with you
Security, including Google reCAPTCHA on sign-up and login
Legitimate interest
Analytics (Google Analytics)
Consent
Change-alert digest emails
Consent
Reviewing and verifying charity claims
Legitimate interest / agreement
API quota enforcement and abuse prevention
Legitimate interest / agreement
Publishing charity data from public sources
Legitimate / public interest
04

Charity data we publish

Charity pages compile data from official government registries, tax authorities, and open data portals, supplemented by vetted charity directories where a country publishes no public registry data. Some of this is personal data already made public by those sources: the names and roles of trustees and officers, and compensation figures where a registry discloses them. Every data point is attributed to the source it came from. Our lawful basis for publishing it is our legitimate interest, and the public interest, in charity transparency.

If you are named in registry data we display and want it corrected or removed, email info@giveradar.com. We action corrections within about 5 business days and removals of personal data within 30 days. See our data sources and methodology for how the data is assembled.

05

Your donation tracker

The donation tracker lets you record gifts you have made: the amount, date, currency, and any recurring commitment. This information is private. Only you can see it. We never publish it, never share it, and never use it for advertising. We hold it for the lifetime of your account and delete it when you delete your account. Our lawful basis is the performance of our agreement with you and, where relevant, your consent.

06

Watchlists and change alerts

You can save charities to a watchlist. Change alerts are off by default: we email you a digest only if you turn them on yourself. When alerts are on we send a periodic email summarizing changes to the charities you follow. Every one of those emails has an unsubscribe link, and you can turn alerts off at any time in your account settings. Our lawful basis for sending them is your consent.

07

Charity claims and verification uploads

To claim a charity profile you provide a work email and job title, and we send a verification code. In some countries we also ask an owner to upload official evidence of authority, such as a registration decree or certificate (PDF, JPG, or PNG). These documents are stored in private storage that is never served on the web, and are reviewed only by GiveRadar staff handling the claim.

We keep verification uploads for as long as the claim remains active. If a claim is rejected or expires, we retain the associated data only as long as needed to prevent repeat abuse and then delete it. Our lawful basis is the performance of the claim process you started and our legitimate interest in preventing fraudulent claims.

08

Cookies and analytics

We use as few cookies as we can, and we do not use a third-party consent-management service. There are exactly two categories:

Essential. Your session, security tokens (CSRF), your cookie choice itself, and Google reCAPTCHA on sign-up and login to prevent abuse. These are strictly necessary and always run.
Analytics. Google Analytics gives us anonymous usage statistics. It loads only if you accept it. Your choice is stored in a gr_consent cookie for 6 months, and if you decline or later turn analytics off we delete the Google Analytics cookies for this site.

You can change your choice any time from Cookie settings in the footer.

09

API request logs

If you use the GiveRadar API, we log each request, including the API key used, timestamp, endpoint, and originating IP address. We use these logs to enforce rate limits and quotas and to detect and prevent abuse. Logs are automatically purged on a schedule and retained for no longer than 90 days. Our lawful basis is the performance of our API agreement with you and our legitimate interest in protecting the service.

10

How long we keep your data

We keep personal data only as long as we need it for the purpose it was collected:

Account data
Kept for the life of your account; deleted when you delete the account.
Donation tracker records
Kept for the life of your account; deleted with it.
Verification uploads
Kept while a claim is active; deleted after a rejected or expired claim.
API request logs
Automatically purged; retained no longer than 90 days.
Analytics data
Only collected with consent; governed by Google Analytics retention.

You can delete your account, and all data tied to it, at any time by emailing info@giveradar.com. We complete deletion within 30 days.

11

Who we share data with

We do not sell your personal data, and we do not share your account email for marketing. We do rely on a small set of processors to run the service, each bound by a data processing agreement and each used only for the purpose listed:

Processor
Purpose
Location
Google
Analytics (with consent) and reCAPTCHA security
EU / US
Cloudflare
Content delivery and network security
Global
Hetzner
Hosting and data storage
Germany / Finland
Stripe
Payments for paid API plans
EU / US
Transactional email provider
Verification codes and alert digests
EU / US

We may also disclose data where the law requires it, or to protect the rights and safety of GiveRadar and its users.

12

International data transfers

Some of the processors above are based outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses, or an equivalent approved safeguard, to protect it. You can ask us for details of the safeguards that apply to a specific transfer.

13

Your rights, security, and changes

Under the GDPR you have the right to access the personal data we hold about you, to correct it, to have it erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw any consent you have given. To exercise any of these, email info@giveradar.com; we respond within one month. If you are unhappy with our response, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.

Security. Passwords are hashed, evidence uploads are kept in private storage that is never web-served, and access to personal data is limited to staff who need it. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.

Changes. When we make a substantive change to this policy we update the "last updated" date at the top. Continued use of GiveRadar after a change means you accept the updated policy.

Questions about your data?
We answer privacy questions directly, no ticket system.
Email info@giveradar.com
Research without an account

Check any charity before you give

No sign-up needed to search 7.9M+ nonprofits across 100+ countries. Nothing is tracked unless you say so.