CauseHub

Privacy policy

Version 1.8, 29 September 2026 (when an organiser posts a receipt or delivery, we email the donors of that cause once, with a link to stop these emails; before that: a sign-in log with IP address and place for the safety of your account, kept in full for 90 days; before that: the site in five languages; we remember the language you used so we can write to you in it, a small cookie keeps a language you pick yourself, and public cause text is machine-translated by the AI providers listed below). We will tell you here, and by email if you have an account, before any important change.

We built CauseHub to collect as little about you as possible. No ads, no tracking cookies, no data sales, and no profiling of your giving. This page lists everything we collect, why, who else sees it and for how long.

Who is responsible

The controller is SevinHub, Sergiu Vincze, Belgian sole proprietorship (eenmanszaak), Blivensstraat 43 bus 101, 2100 Antwerpen, Belgium, KBO/BCE 1042.245.006. Contact for anything about your data: admin@sevinhub.com.

When you donate

You do not need an account. We collect:

  • Your email address, to send your receipt, to tell you once when the organiser posts a receipt or delivery for the cause you gave to (every such email has a link to stop them), to handle refunds, and to prevent fraud. CauseHub never shows it publicly, never shows it to the organiser on CauseHub and never uses it for marketing.
  • If you stop proof emails, we keep only a keyed fingerprint (hash) of your address, so we remember not to write to it; never the address itself.
  • Your name, only if you give it. It is shown on the supporters list only if you tick that option, and shown to the organiser unless you choose to hide it.
  • A public message, only if you write one and choose to show your name.
  • The donation itself: cause, amount, processing cost you covered, optional tip, payment method type, date and status, and the reference numbers the payment provider gives us.
  • A shortened IP address (the last part removed, for example 203.0.113.0/24) stored with the donation to detect fraud and repeated attacks.
  • The language you used on the site (for example Dutch), stored with the donation, so your receipt and any later message about it are written in that language.

Your card or bank details go only to Stripe, on Stripe's own page. We never see or store them.

Good to know: your payment goes directly into the organiser's own Stripe account, so, as with any online payment to a seller, the organiser can see in their Stripe account the details you enter on Stripe's payment page, such as your email address and the name on your card. CauseHub's "hide my name" options control what CauseHub shows, not what Stripe shows the organiser. Organisers may use these details only to handle your donation.

When you create an account

  • Name and email address. Your name is shown on causes you organise.
  • The language you used when you registered, so security notices and decisions about your causes are written in that language.
  • Password, stored only as an Argon2id hash. When you choose it, we check it against known data breaches using the Have I Been Pwned service: only the first 5 characters of a SHA-1 hash of the password leave our server, never the password.
  • Two-step verification: the secret key for your authenticator app, encrypted, and your recovery codes, stored only as hashes.
  • Confirmation that you are 18 or older, when you accepted the terms, when you last signed in, and a count of failed sign-in attempts (to lock out password guessing).
  • A sign-in log: each time someone signs in to your account, or tries with a wrong password or code, we record the date and time, the full IP address, the country and city estimated from it, a short browser description (for example "Chrome on Android") and the result. The place is looked up in a database on our own server (IP Geolocation by DB-IP), so your address is not sent to anyone. You see your last 10 sign-ins under Account security. It helps you and us notice when someone else uses your account.

When you organise a cause

  • The cause: title, summary, story, how the money will be used, category, country, town if you give one, goal, photos and an optional YouTube link. This is public once the cause is approved.
  • An optional faith connection of the cause, for example a church roof. Because it can reveal religious belief, it is special category data under Article 9 GDPR: you choose to publish it with your cause, and you can remove it while the cause is a draft or by writing to us. We never use it for anything else.
  • The name of the person, organisation or group you raise for, and your relationship to them. These are not shown publicly. We use them for review and to screen against official sanctions lists.
  • Your confirmations that the story is true, that people shown agreed, and that you follow the dignity guidelines, with the time you gave them.
  • Updates and proof you post: text, receipts and photos. Photos are re-encoded and all hidden data is removed, including GPS location.
  • Your payout account status: the Stripe account number and the status flags Stripe reports (for example "can receive donations"). Stripe collects your identity documents and bank details directly. We do not receive or store them.
  • Sanctions screening results: whether your name or the beneficiary's name resembles an entry on the EU, UN, UK or US sanctions lists. A possible match is always checked by a person; nobody is blocked automatically.

When you set up a creator profile

Handle, display name and short description. If you verify your channel, we receive your YouTube channel id and channel name from Google, then revoke our access immediately. We do not keep any Google token.

When you report something

Your name, email, the reason and your explanation, as the Digital Services Act requires, so we can tell you our decision, plus the language you used, so we answer in it. The organiser is not told who reported them. Reports about child sexual abuse material can be made without name or email.

When you just visit

  • No tracking cookies. A session cookie is set only when you use a form or sign in. It is strictly necessary for security and is deleted when you close the browser or after 12 hours.
  • Your colour theme (light or dark) is remembered in your own browser only if you choose one. It never reaches us. The Auto setting works out day or night on your device from its clock and stores nothing.
  • Your language is in the web address (for example /nl/). On a first visit without a language in the address we follow your browser's language setting. If you pick a language from the flag menu, a cookie named ch_lang keeps that choice for one year so the site opens in it next time. It holds only the two-letter language code, is needed to honour the choice you made, and is not used for anything else. Delete it in your browser to go back to following your device.
  • Page statistics on public pages. The home page, explore, cause pages, creator pages, fees, trust, transparency and the legal pages load Rybbit, a cookieless analytics script, so we can see which pages are read and where visitors come from. It records the page viewed, the referring site, your browser, device type, screen size and language, page load timings, and a country derived from your IP address; Rybbit states that the IP address itself is never stored. It sets no cookies and writes nothing to your browser's storage. It does not run on donation, thank-you, receipt, report, account, dashboard or owner pages, and it never receives your email, name, amount or any donation data. Any content blocker stops it, and nothing on the site depends on it.
  • A daily visitor count. To publish user numbers as the Digital Services Act requires, we count unique visitors per day with a keyed hash of the IP address and browser. The key is random, changes every day and is destroyed the next day, so we cannot recognise you across days and no identifier is ever stored.
  • Server logs (IP address, page, time, browser) kept for 14 days for security, then deleted.

Why we may do this (legal bases)

  • To carry out our agreement with you (Article 6(1)(b)): processing donations, accounts, causes, refunds and receipts.
  • Legal obligations (Article 6(1)(c)): accounting records, sanctions law, the Digital Services Act and answering lawful requests from authorities.
  • Legitimate interests (Article 6(1)(f)): preventing fraud, card testing and abuse, keeping the platform secure, the audit log of security events, the sign-in log, the cookieless page statistics described above, and telling donors once when proof is posted for a cause they gave to. Our interest is keeping donors and causes safe and knowing which pages are read; you can object, and we will weigh your situation.
  • Consent (Article 6(1)(a)): showing your name publicly. You can withdraw it at any time from your receipt page.
  • Special category data (Article 9): a faith connection you choose to publish with your cause (Article 9(2)(a) and (e)).

Who else processes your data

  • Stripe (Stripe Payments Europe Ltd, Ireland) processes payments, verifies organisers' identity, pays out and fights fraud. For identity checks and fraud prevention Stripe acts as a separate controller under its own privacy policy.
  • Cloudflare runs the Turnstile human check on donation and report forms. It reads technical signals from your browser to tell people from bots and does not use them for advertising.
  • Google, only if you verify a YouTube channel, and YouTube, only if you press play on a video (loaded from youtube-nocookie.com).
  • Have I Been Pwned, only the 5-character hash prefix described above.
  • AI translation providers: Groq (United States), OpenRouter (United States) and Google Gemini. The public text of a cause and of its proof entries (title, summary, story, what the money pays for, updates) is sent once to be translated into the languages of the site; the first provider that answers is used and nothing else is sent, never beneficiary names kept private, emails, names of donors or donation data. Machine translations are marked as such on the page and we can correct them. An organiser who does not want this can write to us and we translate by hand.
  • Rybbit (app.rybbit.io) hosts the page statistics described above under its own privacy policy. It receives only the technical facts listed there, from public pages, and nothing about donations or accounts.
  • Our hosting provider Contabo, in the European Union (France), where the site and database run.
  • Our email server at our web host Interserver, in the United States, which sends the emails we send you (confirmations, receipts, proof notices, decisions). It receives only your email address and the text of the email.

Some of these companies, including our email server, process data in the United States. Transfers rely on the EU-US Data Privacy Framework where the company is certified, and otherwise on the European Commission's standard contractual clauses.

How long we keep it

  • Donation and payout records: for the period Belgian accounting law requires (currently 7 years after the end of the financial year). If you erase your details, the record stays without your email and name.
  • Your account and causes: while your account exists. Ended causes stay public for 24 months, then are unlisted; the financial records stay as above.
  • Reports and their decisions: 12 months after the decision, or longer if a case is still open.
  • Security and audit log: 7 years, because it proves who changed money-related settings. It holds account numbers and shortened IP addresses, not names or emails.
  • Sign-in log: the full IP address and the city for 90 days; after that only the shortened IP address and the country, deleted after one year.
  • Emails we sent you: 12 months.
  • Rate-limit counters: at most one day. Visitor-count hashes: one day. Server logs: 14 days.
  • Page statistics at Rybbit: aggregate, without IP addresses, for up to 3 years.

Your rights

You can ask to see your data, correct it, erase it, restrict or object to its use, and receive it in a portable format. Donors can erase their contact details themselves from their private receipt page. For everything else write to admin@sevinhub.com from the email address you use with us; we answer within one month. You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be).

Automated decisions

We make no decisions about you by automated means alone. Sanctions screening and fraud signals only flag things for a person to review.

Children

You must be 18 to organise a cause and 16 to donate. Causes about children follow extra rules: first names only, never a school or address, and consent from a parent or guardian.

Security

Encrypted connections, hashed passwords, encrypted two-step secrets, an append-only audit log, strict separation of who can change money records, and regular encrypted backups. If a breach puts your data at risk, we tell the Data Protection Authority within 72 hours and tell you without delay when the risk to you is high. Found a security problem? See our security contact.