This Privacy Policy explains what personal data the Charity Organization “DIRECT HELP” (EIN 932020993) (hereinafter referred to as “DIRECT HELP”, “we” or “us”) collects when you use the dhelp.org website (hereinafter referred to as the “Website”), why we collect it, who we share it with, and what you can do about it. It applies together with our Terms of service and our Cookies policy.
The Website connects two groups of people: donors, who give recurring or one-time financial support, and recipients, who receive that support directly. We collect different data from each group, and we publish some of it. Please read section 3 carefully if you are applying to become a recipient.
You can browse the Website, view recipient pages and read our public content without creating an account. Even then, we and our service providers automatically collect some technical data:
We use this data to keep the Website running, to protect it from abuse, and to understand which parts of it people actually use. A full list of the cookies we set, and how to control them, is in our Cookies policy.
When you register as a donor we ask for your name, your email address and a password. We never store your password itself — we store only a cryptographic hash of it (bcrypt), from which the original password cannot be recovered. We also record when your account was created, whether your email address has been confirmed, and your language preference.
If you choose to sign in with Google or Facebook instead, we receive from that provider your name, your email address and, where available, your profile picture. We do not receive your password for that account, and we do not post anything on your behalf.
Payments are processed by Stripe. Your card number, expiry date and security code are entered into a form served by Stripe and are sent directly to Stripe — they never reach our servers and we cannot see them. What we store on our side is limited to: the identifier Stripe assigns to you as a customer, the identifiers of your saved payment methods and subscriptions, and, for display purposes only, the card brand, the last four digits and the expiry month and year.
We also store your donation history: which recipients you support, the amount and currency, the schedule, the dates on which payments were attempted, whether each attempt succeeded or failed, and the resulting invoices and receipts. We keep this record because we are legally required to account for charitable funds, and because you and the recipient both need to be able to see it.
Recipients are not shown your email address, your payment details or your home address. Your donation is presented to them in the form described in your account settings at the time you give.
Recipients ask strangers to send them money every month. That only works if donors can see who they are helping, and it is only safe if we can verify that the person is real and that the money reaches them. Those two needs pull in opposite directions, so we split recipient data into two strictly separated parts.
The following data is published on your recipient page, which can be opened by anyone, including visitors who have not created an account, and which may be indexed by search engines and shared on social networks:
You choose this content and you can change it at any time from your profile page. Changes are reviewed by our moderators before they appear publicly. Please do not include information in your description or photographs that you are not willing to make permanently public — once a page has been public, copies may persist in search engine caches and on social networks outside our control.
The following data is used only to verify your identity and to transfer money to you. It is visible to our moderation and finance staff and to our payment partners, and it is never shown on your public page or to donors:
If you choose to verify your identity through Diia, the state service of the Ministry of Digital Transformation of Ukraine, you are redirected to Diia and you decide there which documents to share with us. Depending on your choice, we may receive an internal passport, a foreign passport, a taxpayer card, a certificate of an internally displaced person, a veteran's certificate or a pension card. We receive each document as a PDF file together with the qualified electronic signature that proves it is genuine, and we extract from it your name, your date of birth, your taxpayer number and your registered address in order to pre-fill your profile.
Using Diia is optional. If you prefer, you can upload the same documents manually instead. Documents obtained through Diia are stored with the rest of your administrative data described in section 3.2 and are never published.
We process personal data only where we have a lawful basis for doing so:
We do not sell your personal data and we do not share it for anyone else's advertising. We do rely on the following service providers, each of which receives only the data it needs to perform its function and is bound to process it on our instructions:
We may also disclose personal data where we are required to do so by law, or where it is necessary to establish, exercise or defend legal claims, or to protect the vital interests of any person.
DIRECT HELP operates internationally: recipients are located in Ukraine, donors are located in many countries, and the service providers listed above operate infrastructure in the European Union and the United States. Your personal data is therefore transferred across borders. Where such a transfer leaves the European Economic Area, we rely on the safeguards offered by the relevant provider, including the European Commission's standard contractual clauses.
All traffic between your browser and the Website is encrypted in transit. Passwords are stored only as bcrypt hashes. Card data never reaches our servers. Recipient documents are stored in private object storage that is not publicly addressable and is served only to authorized staff through short-lived links. Access to administrative recipient data is restricted to staff who need it for moderation or payouts, and their actions are recorded.
No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent authority as required by law.
Subject to the law that applies to you, you have the right to: obtain a copy of the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to how we process it; receive it in a portable, machine-readable format; and withdraw any consent you have given. You also have the right to lodge a complaint with your data protection supervisory authority.
You can correct most of your own data directly in your account. To exercise any of the other rights — including deleting your account and the data associated with it — write to us at [email protected]. We will respond within one month. Please note that we may have to keep financial records even after erasing the rest of your data, where the law requires us to.
The Website is not intended for children, and we do not knowingly allow anyone under 18 to create an account. Where a recipient's page describes a child, the account is held and the data is provided by that child's parent or legal guardian, who decides what is published. If you believe a child has given us personal data without such consent, please contact us at [email protected] and we will remove it.
We do not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing. Every recipient application and every published change is reviewed by a person.
We may update this Privacy Policy from time to time. The date of the latest revision is shown at the top of this page. If a change materially affects how we use your personal data, we will tell you before it takes effect.
If you have any questions about this Privacy Policy, or if you wish to exercise any of your rights, please write to us at [email protected].