Privacy Policy

Last updated: February 4, 2025


Privacy Policy

Sanad Foundation (“Company,” “We,” “Us,” or “Our”) is a nonprofit organization devoted to empowering families and communities through trust-based, small-scale charitable giving. This Privacy Policy explains Our practices regarding the collection, use, and disclosure of Your information when You use the Sanad application (“Service”). By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.


1. Interpretation and Definitions

Interpretation
Words with capitalized initial letters have defined meanings. These definitions apply regardless of singular or plural use.

Definitions

  • Account: A unique account created for You to access Our Service.
  • Affiliate: An entity that controls, is controlled by, or is under common control with the Company.
  • Application: The “Sanad” software provided by the Company.
  • Company: Sanad Foundation, based in Washington, United States.
  • Device: Any device capable of accessing the Service, such as a computer, smartphone, or tablet.
  • Personal Data: Any information that relates to an identifiable individual.
  • Service: The Sanad application and related services.
  • Service Provider: Any third-party organization that processes data on Our behalf (e.g., Stripe for payments, Twilio for SMS services).
  • Usage Data: Data collected automatically when You use the Service (e.g., IP addresses, browser versions).
  • You: The individual or entity using the Service.

2. What Is Sanad?

Sanad is built on the cornerstone of TRUST. It is a platform designed for micro-charity and small-scale, personal donations:

  • Support Individuals or Families You Know: Connect directly with those in need within your personal network.
  • Get Personal: Build meaningful, direct connections with recipients.
  • Transparency and Traceability: Track every step of the donation process, from contribution to final use of funds.
  • Discover Opportunities: Find charitable opportunities through trusted connections and personal referrals.

This Privacy Policy underscores Our commitment to safeguarding Your information as We facilitate these trusted, person-to-person charitable interactions.


3. Types of Data Collected

  1. Personal Data
    While using Our Service, We may collect the following types of Personal Data to fulfill Our nonprofit mission effectively:
    • Phone Number: Used for authentication, identity verification, and important communications related to Your Account.
    • First and Last Name: Helps personalize Your experience and facilitate trust-based interactions with other users.
    • Payment Information: Collected for receiving charitable funds. We do not store or collect information that could be used to withdraw funds without authorization.
    • Profile Details (Optional): You may choose to provide additional profile information (such as a short bio or email address) to enhance trust and transparency within the community.
  2. Usage Data
    Automatically collected Usage Data may include:
    • Internet Protocol (IP) address of Your Device.
    • Browser type, version, and the time You spend on specific pages.
    • Mobile Device identifiers, operating system details, and diagnostic data.
  3. Information Collected While Using the Application
    With Your permission, We may request access to:
    • Location Data: Used primarily to validate phone numbers and determine appropriate country codes in Your contact list.
    • Contacts List: To identify registered/unregistered users and allow You to invite or discover charitable opportunities within Your personal network.
    • Camera Access: To capture payment card information through Stripe’s secure payment portal (optional feature).

4. Legal Basis for Processing (Where Applicable)

Where required by law (such as in certain jurisdictions), We only process Your Personal Data when:

  • You have given Us explicit consent to do so.
  • It is necessary for the performance of a contract (e.g., providing the Service You requested).
  • It is necessary to comply with a legal obligation.
  • It is necessary to protect Your vital interests or the interests of another person.
  • It is necessary for Our legitimate nonprofit interests, provided those interests are not overridden by Your data protection rights.

5. How We Use Your Personal Data

The Company uses Your Personal Data for the following purposes:

  1. Service Provision and Improvement
    • Enable You to create and manage campaigns or donate to individuals or families in need.
    • Maintain, personalize, and enhance the Service for a more seamless user experience.
  2. Identity Verification and Security
    • Verify Your identity via SMS or other authentication methods.
    • Protect against fraudulent transactions and unauthorized access.
  3. Facilitate Charitable Transactions
    • Process and trace donations, ensuring transparency in micro-charity efforts.
    • Collaborate with trusted Service Providers like Stripe to handle payment processing securely.
  4. Invitations and Community Building
    • Allow You to invite personal contacts via verbal consent followed by SMS invitations (see Section 13 for more details), fostering a trusted network of donors and recipients.
    • Validate phone numbers and approximate location to ensure authenticity of invitations.
  5. Compliance with Legal Obligations
    • Retain records of campaigns and transactions as required by nonprofit regulations or other applicable laws.
    • Respond to lawful requests by public authorities or other legal obligations.

6. Sharing Your Personal Data

We may share Your information in the following scenarios:

  1. With Service Providers
    • Twilio: For secure SMS authentication and user invitations.
    • Stripe: For payment processing, including optional camera-captured card details.
      These Service Providers have access to Personal Data only to perform tasks on Our behalf and are obligated not to disclose or use it for other purposes.
  2. With Other Sanad Users (Trust Networks)
    • When You donate, share campaigns, or invite users, Your name (and any additional profile data You choose to share) may be visible to the recipient and those in Your trusted network.
  3. With Affiliates
    • We may share Your information with Our Affiliates, in which case We will require those Affiliates to honor this Privacy Policy.
  4. Legal Compliance
    • If required by law or in response to valid requests by public authorities (e.g., a court or government agency).
    • To protect Our rights, investigate fraud, or respond to a government request.

7. Retention of Your Personal Data

We retain Your Personal Data only as long as is necessary for the purposes set out in this Privacy Policy and to comply with legal obligations (e.g., nonprofit record-keeping requirements). Usage Data may be retained for internal analysis and security purposes.


8. Transfer of Your Personal Data

Your data may be transferred to—and maintained on—servers located outside of Your state, province, country, or other governmental jurisdiction where the data protection laws may differ. By using the Service, You consent to such transfers.


9. Security of Your Personal Data

We implement commercially reasonable security measures designed to protect Your Personal Data. These include:

  • Secure Socket Layer (SSL) encryption where appropriate.
  • Encrypted storage of donation-related payment data (Stripe).
  • Robust access controls to protect sensitive information.

While We strive to use acceptable means to protect Your Personal Data, no method of transmission or storage is 100% secure.


10. Children’s Privacy

Our Service is not intended for children under the age of 18. We do not knowingly collect Personal Data from individuals under 18. If You become aware that a child has provided Us with Personal Data, please contact Us so that We can take appropriate action.


11. Links to Other Websites

Our Service may contain links to third-party websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.


12. Third-Party Services

We partner with:


13. Proof of Consent for SMS Communications

Sanad Foundation follows strict compliance standards regarding user consent for SMS messages. Sanad encourages verbal consent for SMS invitations between friends.

User Consent – Opt-In
You must have permission from each Recipient before you send any Messages to such Recipient through the service. If you do not have permission to send Messages to a Recipient, you must not send any Messages through the service to such Recipient.

    Below is how this process works:

    1. Verbal Consent Among Friends
      • User (Inviter) will first explain Sanad’s purpose to their friend, describing how the app can connect people to vital resources and real-time assistance.
      • The Inviter explicitly states they would like to send an invite text and clarifies that the Invitee can reply YES to join or STOP to decline.
      • If the friend verbally agrees, the Inviter proceeds to send an SMS invite.
      • If the friend declines, the Inviter respects that decision and no SMS is sent.
    2. Registration and Phone Number Verification
      • A one-time passcode (OTP) is sent to verify the phone number provided.
      • By entering this OTP, users confirm consent to receive authentication-related SMS.
    3. Secure Login Authentication
      • OTPs are used to verify identity each time a user logs in, ensuring account security and preventing unauthorized access.
    4. Scope of SMS Communications
      • SMS messages are strictly limited to account verification, login authentication, and user-to-user invitations based on prior verbal consent.
      • Sanad does not send marketing or promotional messages via SMS.
    5. User Control and Opt-Out Mechanisms
      • Recipients of a verbal invite who are not interested can simply decline before any SMS is sent or reply STOP upon receiving the invite.
      • If a user wishes to stop receiving authentication SMS, the only method is to delete the Sanad account (as OTP-based login is integral to the Service’s security model).

    14. How Sanad Promotes Transparency and Trust

    1. Localized Impact: By focusing on personal networks, We minimize fraud risks, as donors typically know the recipients or are connected through a trusted chain of referrals.
    2. Traceable Donations: Donors can see how and when their funds were used, ensuring complete transparency.
    3. Micro-Charity: Transactions are smaller-scale, and more directly meaningful.
    4. Personal Connections: We encourage donors and recipients to maintain open communication and updates, reinforcing trust.

    15. Your Privacy Rights

    Depending on Your jurisdiction, You may have the right to:

    • Access, update, or delete the Personal Data We hold about You.
    • Withdraw consent to Our processing of Your Personal Data, where applicable.
    • Request restrictions on or object to the processing of Your Personal Data.
    • Request a portable copy of the Personal Data You have provided to Us.

    To exercise any of these rights, please contact Us using the information below. We will respond to Your request in accordance with applicable laws.


    16. Delete Your Personal Data

    You can request deletion of Your Account or Personal Data at any time by:

    • Using the “Delete Account” feature within the Application.
    • Contacting Us directly at [email protected].

    Important Considerations

    • Certain transactional records (e.g., donations, campaigns) may be retained to comply with legal or nonprofit regulatory obligations.
    • Once Your Account is deleted, You will no longer receive SMS invitations or updates from Sanad.

    17. Changes to This Privacy Policy

    We reserve the right to update this Privacy Policy at any time. If We make any material changes, We will notify You via email or through a prominent notice on the Service. The updated policy is effective upon posting unless otherwise indicated.


    18. Contact Us

    If You have any questions about this Privacy Policy or wish to exercise Your privacy rights, please contact Us at:


    By using Sanad, You acknowledge that You have read and understood this Privacy Policy and agree to Our collection, use, and disclosure of Your Personal Data in accordance with its terms. We appreciate Your trust in helping individuals and families through micro-charity, and We are committed to maintaining the highest standards of data protection and transparency.