Privacy Policy
Last updated: June 6, 2026
1. Introduction
ImpactSphere ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and safeguard your personal information when you use the ImpactSphere platform and related services (collectively, the "Services"). By using our Services, you consent to the practices described in this policy.
This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Information We Collect
We collect information that you provide directly, information generated through your use of the Services, and information from third parties.
2.1 Account and Profile Information
- Name and email address
- Password (stored as a cryptographic hash)
- Organization type (NGO or Company)
- Organization name, registration number, tax ID, and address
- Mission statement, activities description, and impact areas
- Representative name, role, and identification details
- Biography or provider descriptions (for service listings)
2.2 Verification Documents
- Registration certificates and statutory documents
- Proof of activity reports and partner letters
- Representative identification documents (passport, national ID)
- Tax identification documentation
2.3 Payment Information
We do not store full payment card details. Donations and service payments are processed by Stripe. We receive transaction records including payment status, amount, date, and a pseudonymous payment intent identifier from Stripe.
2.4 Usage Data
- IP address, browser type, and device information
- Pages visited, features used, and time spent on the platform
- Session tokens and authentication logs
- Search queries and filter preferences
2.5 Communications
- Support chat messages and email correspondence
- Meeting requests and scheduling data
- Project comments and service review submissions
3. How We Use Your Information
We process your personal data for the following purposes:
- Providing Services: To create and manage your account, verify your organization, list projects and services, process donations, and enable communication between users.
- Matching and Recommendations: To suggest relevant projects, NGOs, or Companies based on location, impact areas, budget, and stated preferences.
- Security and Fraud Prevention: To authenticate users, detect suspicious activity, enforce our Terms of Service, and protect the integrity of the platform.
- Customer Support: To respond to inquiries, resolve disputes, and improve our support quality.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Platform Improvement: To analyze usage trends, diagnose technical issues, and develop new features. Where possible, we use aggregated or pseudonymized data for analytics.
4. Legal Basis for Processing (GDPR)
We process personal data based on the following legal grounds:
- Contractual necessity: To perform our contract with you (e.g., account creation, transaction processing, service delivery).
- Consent: Where required, such as for accepting these Terms and Privacy Policy, or for optional marketing communications. You may withdraw consent at any time.
- Legitimate interests: For security, fraud prevention, platform analytics, and improving user experience, balanced against your rights.
- Legal obligation: To comply with tax, accounting, and regulatory requirements.
5. How We Share Your Information
We do not sell your personal information. We may share data in the following circumstances:
- Between Platform Users: When you list a project, service, or matching request, certain profile information (organization name, description, location, impact areas) is visible to other verified users to facilitate collaboration.
- Service Providers: We use trusted third parties for hosting, payment processing (Stripe), email delivery (Resend), and analytics. These providers process data only on our behalf and under strict confidentiality obligations.
- Legal Requirements: We may disclose information if required by law, subpoena, or governmental authority, or to protect our rights, property, or safety, or that of our users or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of the transaction, subject to the same privacy commitments.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with Services. We may retain certain information for longer periods where necessary for legal, tax, accounting, fraud prevention, or security purposes. Specifically:
- Account data: retained until account deletion, plus up to 2 years for legal compliance.
- Transaction records: retained for 7 years to comply with tax and accounting obligations.
- Verification documents: retained for the duration of your account plus 1 year after termination.
- Support chat logs: retained for 2 years for quality assurance and dispute resolution.
7. Security Measures
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), password hashing, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
8. Your Rights
Under the GDPR and applicable laws, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Data Portability: Request a machine-readable copy of your data to transfer to another service.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact us at impactsphere2026@gmail.com. We will respond within 30 days.
9. Cookies and Similar Technologies
We use cookies and similar technologies to maintain your session, remember preferences, and analyze platform usage. Session cookies are essential for authentication and security. You can manage cookie preferences through your browser settings. Disabling essential cookies may impair platform functionality.
10. International Data Transfers
Our servers and some service providers may be located outside your country of residence, including within the European Economic Area (EEA) and the United States. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data.
11. Children's Privacy
ImpactSphere is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete the information.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or for legal reasons. Material changes will be communicated via email or a prominent notice on the platform at least 15 days before taking effect. We encourage you to review this policy periodically.
13. Contact and Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: impactsphere2026@gmail.com
Address: ImpactSphere, Lisbon, Portugal
If you are based in the European Union and believe we have violated your data protection rights, you also have the right to lodge a complaint with your local supervisory authority.