Pledge4Play Privacy Policy
Effective date: July 14, 2026 Last updated: July 15, 2026
1. Who we are
Pledge4Play ("Pledge4Play," "we," "us," or "our") is a fundraising platform built for youth sports clubs, school athletic programs, booster clubs, individual athletes, and other activity-based programs. Organizations and individual athletes use Pledge4Play to run fundraising campaigns; donors use it to support those campaigns; and parents, guardians, and participants use it to manage participation and outreach.
Pledge4Play is operated from the United States. The web app is available at pledge4play.com. The mobile app is available on the Apple App Store and Google Play under the name Pledge4Play.
This Privacy Policy explains what information we collect, why we collect it, who we share it with, and the choices you have. We've tried to write it in plain language that parents and teenagers can read, not just lawyers. If something is unclear, please contact us at privacy@pledge4play.com.
2. The short version
Here's the gist, before we get into the details:
- We collect the minimum we need to run fundraising campaigns: names, phone numbers, emails, fundraiser details, and donation records.
- We do not see, store, or transmit the contents of the text messages you send through the app. Outreach messages are sent from your own phone, through your own carrier, to your own contacts. They never touch our servers.
- We do not upload your phone's contact list. When you pick contacts in the app, that data stays on your device.
- We do not store full credit card numbers, bank account numbers, or Social Security numbers. Stripe handles all of that.
- Minors can use the platform, but with built-in parent/guardian consent flows for the actions where it matters most — like creating an organization or running an individual fundraiser.
- Public donation pages show participants by first name + last initial by default, never full name, never address, never contact info.
The rest of this document explains each of those points in detail.
3. Information we collect
We try to collect only what we need to make fundraising work. The categories below mirror the actual data we store in our database.
3.1 Account information
When you sign up, we collect:
- Phone number (required on mobile — used as your sign-in method)
- Email address (required on web — used as your sign-in method via magic link; optional on mobile)
- First name and last name
- Age (required on mobile so we can apply minor-specific protections)
- Profile photo (optional)
Phone numbers are stored in standard E.164 format. We do not collect or store any password, because Pledge4Play does not use passwords — sign-in is by SMS code on mobile or by emailed magic link on web.
3.2 Organization information
When an adult creates an organization, we collect:
- Organization name, type, and the sport or activity it serves
- Logo and website (optional)
- Primary contact name, email, phone
- City, state, ZIP, and country
- For nonprofit verification: Employer Identification Number (EIN) and a record of who signed our Platform Fundraising Agreement, when, and what version
We do not request or store full IRS determination letters as scanned documents in production data — verification is performed by our staff against IRS records using the EIN you provide.
3.3 Fundraiser information
For each fundraiser we store details like the name, description, goal amount, start and end dates, join codes, and group settings. For individual fundraisers created by a minor, we also store the parent or guardian's first name, last name, phone number, and (optionally) email — supplied by the minor when they create the fundraiser, to be confirmed or corrected by the parent or guardian on approval.
3.4 Participant information
For each participant in a fundraiser we store the participant's first name, last name, optional photo, group assignment (if the fundraiser uses groups), goal amount, and the running total raised. Public-facing pages display participants by first name and last initial by default. An organization can opt to show full names or to display participants anonymously, but the privacy-first default is first-initial only — and this default is the one we recommend everywhere minors are involved.
3.5 Donation information
When a donor gives to a fundraiser, we record:
- The donation amount and currency
- The fundraiser, participant, and (if applicable) group the donation is attributed to
- The donor's name and email (collected by Stripe at checkout and passed to us)
- An optional message from the donor
- A Stripe payment identifier so we can reconcile the payment
We do not receive the donor's full credit card number, CVV, expiration date, bank account number, or routing number. Stripe collects those directly. We only store the identifier Stripe gives us.
3.6 Stripe Connect information (organizations and individual fundraisers)
When an organization or an individual fundraiser's payout account holder goes through Stripe Connect to receive payouts, Stripe collects identity verification data ("Know Your Customer" or KYC information) directly. This typically includes legal name, date of birth, address, last four of SSN, and bank account details. We do not see or store this data. Stripe shares with us only:
- A Stripe connected account ID
- A status flag indicating whether onboarding is
not_started,pending,complete, orrestricted
For individual fundraisers created by a minor, the parent or guardian is the Stripe Connect account holder and the legal recipient of payouts. The minor cannot complete this step.
3.7 Family links
If you are a parent or guardian and you link your account to a participant who is your child, we store the link between your user record and the participant record. One parent or guardian can be linked to multiple children across multiple fundraisers.
3.8 Notifications
We store in-app notifications addressed to you (for example, "Your child created a fundraiser that needs your approval" or "A donation came in"). When a notification is created for a parent or guardian who hasn't yet signed up, we store the recipient's phone number on the notification record so it can be claimed and routed to their account when they do sign up. Once claimed, the phone number on the notification record is replaced with the user's account ID.
3.9 Technical data we collect automatically
When you use the website or app, we automatically collect:
- Approximate location derived from IP address (country/region level only — we do not collect precise GPS location)
- Device type, operating system, and app version
- Pages or screens viewed and basic interaction events
- Timestamps of sign-in and last activity
- Crash logs and error reports
We use this information to keep the platform running, debug problems, and understand usage patterns. We do not use it to build advertising profiles.
3.10 Corporate matching information
If a company submits a corporate donation match, we collect the company name, contact name, contact email, the match details (type, amount), an optional company logo, and a Stripe payment record for the match. Once approved, the company's name and logo are displayed publicly on the fundraiser's donation page.
3.11 Cookies and web analytics
Our website uses Google Analytics 4, a service provided by Google, to understand how visitors use the site in aggregate — which pages are viewed, how people arrive, and overall engagement. To do this, Google Analytics sets a small number of first-party cookies (such as _ga) and collects a pseudonymous identifier along with the technical data described in Section 3.9. We use this only to measure and improve the site.
We run Google Analytics in a measurement-only configuration:
- Google Signals is turned off, so analytics data is not linked to Google advertising identities.
- Ads personalization is turned off, and we do not allow analytics data to be used to personalize advertising.
- Google acts as our data processor for this data under Google's data-processing terms. We do not sell it or share it for cross-context behavioral advertising (see Sections 4.4 and 8.5).
Your choices. We honor the Global Privacy Control (GPC) signal: if your browser or a browser extension sends a GPC signal, we do not load Google Analytics at all, and no analytics cookies are set. You can also opt out at any time using the analytics opt-out control in our website footer, or by blocking or deleting cookies in your browser settings — the site works normally without them. Consistent with Section 9, we do not use analytics data to target advertising at anyone we know or reasonably believe to be under 13.
4. Information we do NOT collect
Some of what we don't collect is just as important as what we do.
4.1 We do not see or store your text messages
Outreach text messages sent through the Pledge4Play mobile app are sent from your own phone, using your own phone number, through your own mobile carrier, into the existing one-on-one text thread between you and each contact you pick. We use the phone's native messaging system (expo-sms). There is no Pledge4Play SMS server, no Twilio, no third-party SMS API, no shortcode. The contents of those messages — including any personalization you write — never reach our servers.
We log only that you initiated outreach for a particular fundraiser. We do not log who you sent to, what you said, or whether the recipient replied.
4.2 We do not upload your contact list
When you pick contacts to send outreach to, the mobile app reads your device contacts (using expo-contacts) so you can choose recipients. That contact data stays on your device. It is not uploaded to Pledge4Play. Phone numbers and names of your contacts are passed only to the phone's native messaging system, on your device, when you tap Send.
If you deny the contacts permission on iOS or Android, the app continues to work — you just won't be able to use the contact picker, and you can still send messages by typing numbers manually through your phone.
4.3 We do not store full payment information
We do not collect, transmit, or store:
- Full credit card numbers
- CVVs or expiration dates
- Bank account or routing numbers
- Social Security Numbers
- Government ID numbers (passport, driver's license)
Stripe collects this information directly when a donor checks out, when an organization onboards to Stripe Connect, or when a parent or guardian completes KYC for an individual fundraiser. Stripe is a PCI-DSS Level 1 certified payment processor. Stripe's privacy policy is available at https://stripe.com/privacy.
4.4 We do not sell your data
We do not sell personal information for money, and we do not currently share personal information with advertisers or run targeted advertising on the platform. As noted in Section 5, if we introduce advertising or other practices that would trigger "sale" or "sharing" rights under state privacy laws (such as the CCPA), we will update this policy with the required disclosures and opt-out mechanisms before doing so.
5. How we use information
We use the information we collect to:
- Create and manage your account
- Send you sign-in codes and magic links
- Operate fundraisers — assigning donations to the correct participant, group, fundraiser, and organization
- Show donation totals, leaderboards (for organizational fundraisers — individual fundraisers do not have leaderboards), and progress
- Process donations and payouts through Stripe
- Send transactional notifications (donation received, fundraiser approved, payout setup complete, etc.)
- Verify nonprofit status when an organization requests it
- Approve, decline, or moderate fundraisers, corporate matches, and verifications through our platform admin tools
- Detect and prevent fraud, abuse, or violations of our terms
- Diagnose technical issues and improve the platform
- Comply with legal obligations
We may use machine learning and AI tools to support these purposes — for example, to detect fraud or abuse, to improve product features such as suggested donation amounts or fundraising tips, or to help users draft outreach messages, fundraiser descriptions, or thank-you notes. Where we use third-party AI services to power these features, we choose providers whose terms prohibit them from training their general-purpose models on our users' data. We do not currently use your personal information to train our own general-purpose AI models. If our practices in this area change in a material way, we will update this policy and notify you before the change takes effect.
Pledge4Play does not currently use your personal information for targeted or behavioral advertising. If we introduce advertising features in the future, we will update this policy with the specific information required by applicable law (including how to opt out, how we handle the data of minors, and how we honor signals like Global Privacy Control), and we will notify you before any such change takes effect. We will not introduce targeted advertising directed at users we know or reasonably believe to be under 13.
6. Who we share information with
We share information with the following categories of third parties, only as needed to operate the platform:
6.1 Service providers
| Provider | What it handles | What it sees |
|---|---|---|
| Firebase / Google Cloud | Authentication, database (Firestore), Cloud Functions, app analytics, crash reporting | Most of the data described in Section 3, because Firebase is our primary backend |
| Google Analytics 4 | Aggregate website usage analytics (web only) | Pseudonymous usage and device data via first-party cookies; measurement-only, not used for advertising (see Section 3.11) |
| Stripe and Stripe Connect | Payment processing, payouts, KYC for connected accounts | Donor payment info, organization and individual KYC data, payout bank info — collected by Stripe directly, not by us |
| Vercel | Web app hosting | Web traffic data, server logs |
| Expo / EAS | Mobile app build pipeline and over-the-air updates | App build metadata; device info during update checks |
| Apple App Store and Google Play Store | App distribution | Whatever Apple and Google collect at install and update time, governed by their privacy policies |
Each of these providers has its own privacy policy that governs what it does with data on its systems. We choose providers we believe handle data responsibly, but we are not responsible for their independent practices.
6.2 Within an organization
If you are a participant or parent/guardian in an organizational fundraiser, the organization's admins can see:
- Your name (and your child's name, if applicable)
- Your group assignment (if the fundraiser uses groups)
- The total amount raised attributed to you or your child
- Your contact email or phone (if you provided it)
Donors who give to your participant are typically identified to admins by their name and donation amount, and to the public by name only on a thank-you list — unless they choose to donate anonymously.
6.3 On public donation pages
Public donation pages show only:
- Organization name and logo
- Fundraiser name and progress
- Participants by their public display name (first name + last initial by default)
- Donor names on a thank-you list (if shown), donation amount (if not made anonymously), and any public message the donor leaves
Public pages never show contact information for participants, parents, or organization admins.
6.4 With law enforcement or to comply with legal process
We may disclose information if we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process, or is necessary to protect the rights, property, or safety of Pledge4Play, our users, or others. Where lawful and reasonable, we will attempt to notify the affected user before disclosure.
6.5 In the event of a business transfer
If Pledge4Play is acquired, merged, or sells substantially all of its assets, user information may be transferred as part of that transaction. We will notify users by email or in-app notice before any such transfer takes effect.
7. How we protect information
We use industry-standard safeguards to protect your information:
- All traffic between the web app, the mobile app, and our backend is encrypted in transit using TLS.
- Data stored in Firestore is encrypted at rest by Google Cloud.
- Sign-in is passwordless, which removes one of the most common attack vectors.
- Sensitive operations (creating fundraisers, approving them, processing donations, awarding admin access) run on the server, in Cloud Functions, with permission checks — not on the client.
- Donation totals and other financial fields can only be written by Cloud Functions, never by client code, so a compromised client cannot inflate or alter them.
- Stripe Connect onboarding happens on Stripe's own domain, not on ours, so identity-verification data and bank-account data never pass through our systems.
No system is perfectly secure. If a breach happens that affects your information, we will notify you and the appropriate authorities as required by applicable law.
8. Your rights and choices
You have meaningful control over the information you provide.
8.1 Access and correction
You can view and edit your profile information directly in the app: your name, photo, email, and (where applicable) phone number. You can also see the organizations and fundraisers you are part of.
8.2 Deletion
You can request that we delete your account by contacting privacy@pledge4play.com from the email or phone number associated with your account. Some information may need to be retained — for example, donation records that we are required to keep for tax, accounting, or anti-fraud purposes; or records associated with an active or recently closed fundraiser where deleting your record would prevent us from delivering payouts to others. Where retention is required, we will keep only what is necessary, and we will delete or de-identify the rest.
8.3 Marketing communications
We don't send marketing emails or texts at this time. The notifications we send are transactional — sign-in codes, donation receipts, fundraiser approvals, and similar. If we ever introduce marketing communications, we will ask for your consent and provide a clear opt-out.
8.4 Permissions on your device
You control which permissions the mobile app has. On iOS and Android you can grant or revoke:
- Contacts — needed to use the contact picker for outreach. Without this permission, you can still use the rest of the app.
- Notifications — needed to receive transactional alerts.
- SMS / Messages — used to launch the native messaging composer for outreach.
8.5 State-specific rights
Depending on where you live, you may have additional rights — for example, under the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), or similar state privacy laws. These can include the right to know what personal information we hold about you, the right to delete it, the right to opt out of certain disclosures, and the right not to be discriminated against for exercising these rights. To exercise any of these rights, contact privacy@pledge4play.com. We will verify your identity before responding.
We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under the CCPA.
9. Children's privacy
Pledge4Play is open to participants of all ages, including minors, because youth sports fundraising is the core use case. We treat children's privacy as a first-class concern, and we have built specific protections into the product.
9.1 What minors can and cannot do
In line with our user roles:
- Minors can join an organizational fundraiser by entering a join code. They do not need parent/guardian approval to join an org fundraiser. They can record outreach activity and participate in their team's or group's campaign.
- Minors cannot create an organization.
- Minors cannot create an individual fundraiser without parent/guardian approval. When a minor starts an individual fundraiser, they enter their parent or guardian's contact information; the fundraiser is held in a
pending_approvalstate until the parent or guardian reviews it in the app and approves or declines. After approval, the parent or guardian — not the minor — completes Stripe Connect KYC and is the legal recipient of payouts. - Minors cannot complete Stripe Connect KYC under any circumstances. The Stripe Connect account holder is always an adult.
9.2 What we collect from minors
For a minor who joins an organizational fundraiser, we collect the same baseline information as for adult participants — first name, last name, age, optional photo — plus a phone number on mobile (used only for sign-in). For a minor running an individual fundraiser, we also store the parent or guardian contact information that the minor provides at fundraiser creation, which is then verified by the parent or guardian.
We do not knowingly collect more information than we need from minors. We do not show advertising to minors. We do not sell or share information about minors with third parties for any purpose other than operating the platform.
9.3 Public visibility for minors
By default, participants are shown publicly by first name and last initial only — for example, "Alex M." This default applies to all participants, but it matters most for minors. Organizations can change this setting per fundraiser, but we strongly recommend keeping the privacy-first default for any campaign that includes minors.
Public donation pages never show:
- A participant's full last name (unless the organization explicitly opts out of the default)
- A participant's date of birth or age
- A participant's address, email, or phone number
- A parent's or guardian's contact information
9.4 Parent and guardian consent
For the high-trust actions described above — creating an individual fundraiser as a minor — we require active, in-app consent from a parent or guardian. The parent or guardian receives a notification, opens the app, reviews the fundraiser details, confirms or corrects their email, and approves or declines. Approval is logged with a timestamp and the parent or guardian's account ID. A minor cannot bypass this step.
For minors joining an organizational fundraiser, we follow the organization's own onboarding rules and rely on the organization's pre-existing relationship with the family. Organizations using Pledge4Play represent and warrant that they have appropriate consent from parents or guardians to enroll minor participants.
9.5 COPPA notice and parental rights
If you are the parent or guardian of a child under 13 who has used Pledge4Play, you can:
- Review the personal information we have collected from or about your child
- Request that we delete your child's information
- Refuse further collection of information from your child
To exercise any of these rights, email privacy@pledge4play.com from an email address we can verify against your account or your child's account, and we will respond within the timeframes required by COPPA. If we cannot verify your relationship to the child, we may ask for additional information before acting.
We do not condition a child's participation in any activity on the child providing more personal information than is reasonably necessary for that activity.
10. How long we keep information
We keep information only as long as we need it for the purposes described in this policy or as required by law.
- Active accounts: while the account is in use.
- Inactive accounts: we may delete or archive accounts that have been inactive for an extended period (for example, two years with no sign-in and no fundraiser activity). We will give notice before doing so where we have a working email or phone number.
- Donation and payout records: retained for the period required by tax, accounting, and anti-fraud rules — typically at least seven years in the United States.
- Nonprofit verification records: retained for as long as the organization is active and for a reasonable period afterward to support audit and dispute resolution.
- Notifications: retained for in-app history, with older notifications periodically pruned.
- Logs and analytics: retained for a limited operational window (typically 90 days for raw logs, longer for aggregate analytics).
When we delete information, we delete it from active systems and from routine backups on the next backup rotation.
11. International data transfers
Pledge4Play is operated from the United States, and our primary data systems run in the United States. However, our service providers — including Firebase/Google Cloud, Stripe, Vercel, and Expo — operate global infrastructure, and information may be processed in other countries in the course of normal operations (for example, if a user accesses the app from outside the United States, or if a service provider routes traffic through a regional data center).
Where data is transferred internationally, our service providers contractually commit to appropriate safeguards. If you access Pledge4Play from outside the United States, you understand that your information will be transferred to and processed in the United States.
We do not currently market the platform to users in the European Economic Area, the United Kingdom, or other regions with comprehensive cross-border data-transfer rules. If we begin operating in those regions, we will update this policy with the additional rights and safeguards required by local law.
12. Third-party links
The app and website may include links to third-party websites — for example, social media sharing links to Facebook, X (Twitter), LinkedIn, Instagram, or TikTok. Those services have their own privacy policies, and we are not responsible for their practices. When you click a share link, you are leaving Pledge4Play. We do not post on your behalf and do not require you to authenticate any social media accounts to us. We share with the destination platform only the donation link and the pre-written post text — not your account information.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify users by email, in-app notification, or both, in advance of the change taking effect
- Where required by law, request renewed consent before the change applies to information we already hold
Continuing to use Pledge4Play after a change takes effect means you accept the updated policy. If you do not accept a change, you can request account deletion under Section 8.2.
14. Contact us
If you have questions, concerns, or requests about this Privacy Policy or how Pledge4Play handles your information, please contact us:
Email: privacy@pledge4play.com
A mailing address will be posted here once our incorporation is complete; in the meantime, email is the fastest way to reach us, and we respond to all privacy requests received there.
For COPPA-specific requests (parental review, deletion, refusal of further collection), please put "COPPA Request" in the subject line so we can route it appropriately.
Pledge4Play — Helping kids play, one pledge at a time.
