Privacy Policy
Effective Date: June 17, 2026
1. INTRODUCTION AND SCOPE
At Request Desk ("we," "us," or "our"), we believe privacy is a fundamental human right. This Privacy Policy outlines our commitment to protecting your personal information when you use our website, tools, and services, in compliance with the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), and the Children's Online Privacy Protection Act (COPPA).
2. DATA WE COLLECT
We design our products with a strict focus on data minimization—collecting only the data absolutely necessary to verify, track, and fulfill donation requests for local nonprofits.
-
Active Collection (Information You Provide):
- Nonprofit representative contact information (name, contact email address).
- Organization identifiers (nonprofit name, Tax ID / EIN).
- Request details (event date, date materials are needed, items requested, quantities, budget requests, and description of request purpose).
- Business owner account credentials (email address, password) and custom budget configuration data.
-
Passive Collection (Automated Information):
- Server Logs: Our local server infrastructure automatically generates system logs capturing diagnostic request routes and timestamp metadata strictly for performance tracking and security mitigation.
- No Tracking Cookies or Telemetry: We do not deploy third-party advertising tracking scripts, analytics cookies, or web analytics platforms. Your browsing behavior remains confidential and cookie-free.
3. HOW WE SHARE YOUR DATA (SUB-PROCESSORS)
We do not sell, rent, or trade your personal data. We share information strictly with vetted third-party service providers ("Sub-processors") required to operate our core services:
- Porkbun LLC: For secure SMTP and IMAP email transmission, automated forwarding, and notification handling.
- Local Host Infrastructure: Local processing server and JSON file database storage (`db.json`) used for tracking donation state, email records, and fulfillment queues.
4. EUROPEAN PRIVACY RIGHTS (GDPR & ePrivacy Directive)
If you are located in the European Economic Area (EEA) or the UK, you possess specific statutory rights regarding your personal data. Our lawful basis for processing is the performance of a contract (delivering the donation tracking interface) and our legitimate interest in securing our donation ecosystem.
You have the right to:
- Access & Portability: Request a copy of the personal data we hold about you.
- Erasure ("Right to be Forgotten"): Request that we delete your personal data from our systems.
- Rectification: Correct inaccurate or incomplete data.
- Restrict Processing: Request a temporary freeze on your data processing.
To exercise these rights, please contact us at legal@requestdesk.community.
5. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, the CPRA grants you the right to know what personal information is collected, request its deletion, and correct inaccuracies.
- Do Not Sell or Share My Personal Information: We do not sell your data or share it with third parties for cross-context behavioral advertising.
- Automated Decision-Making Technology (ADMT): We do not utilize your personal information for ADMT profiling or automated decision-making.
We will not discriminate against you for exercising your privacy rights.
6. CHILDREN'S PRIVACY (COPPA)
Our Service is designed for nonprofit representatives and small businesses. In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from individuals under the age of 13. If we become aware that a minor under 13 has provided us with personal information, we will immediately execute a hard deletion of that data from our servers.
7. INTERNATIONAL DATA TRANSFERS
Your information, including personal data, is processed and stored on servers in the United States. By using our service, you consent to the transfer of your data to the United States, which may have data protection laws different from those of your country of residence.
8. DATA RETENTION
We retain your personal data only as long as necessary to fulfill donation request cycles, verify tax identity status, or comply with legal audit logs. Upon request or account termination, active database records are purged within 30 days.