Privacy Policy

FundlyHub is a DBA of CYTY Inc.

Effective date:
Last updated:

About this policy

This Privacy Policy explains how CYTY Inc., doing business as FundlyHub ("CYTY," "FundlyHub," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you access or use the FundlyHub website, applications, and related services (collectively, the "Services").

FundlyHub is a brand and DBA of CYTY Inc. CYTY Inc. is the legal entity responsible for the operation of the Services and the handling of personal information described in this Privacy Policy.

The Services are available in English, Russian, Ukrainian and Spanish. This document is currently authoritative in English only. Official translations are pending legal review, and the English version is the only legally binding version.

1. Legal entity and contact information

Legal entity
CYTY Inc.
DBA
FundlyHub
Business address
262 Chapman Rd, Ste 240
Newark, County of New Castle
Delaware, USA
Physical address
6929 Sunrise Blvd #105B
Citrus Heights, CA 95610
Contact email (privacy and technical)
tech@cyty.io

CYTY Inc. acts as the data controller / business under applicable U.S. privacy laws, except where third parties act as independent controllers.

2. Scope

This Privacy Policy applies to personal information collected through the FundlyHub Services. It does not apply to third-party websites, services, or applications that may be linked from the Services.

3. Information we collect

3.1 Information you provide

  • Account and profile

    • Name, email address, phone number
    • Login credentials (passwords stored in hashed form)
    • Profile photo (optional for an account, required before you publish a campaign)
    • A private contact email, which our team uses to reach you about your fundraiser and which is never shown publicly
    • Profile details you choose to add: your profile handle, city and state, and website or social links
    • Your settings: language, notification choices and whether your profile is public or private
    • Organization or beneficiary information (if applicable)
  • Organizations

    • Legal name, organization type, EIN, address, website, "doing business as" names, locations, mission, contact email, logo and banner
    • Team members you add by the email address of their FundlyHub account, with their role and position
    • Verification documents you upload: an EIN letter, a 501(c)(3) determination letter, a W-9, a voided check or other documents
  • Fundraiser and project content

    • Titles, descriptions, images, videos, updates, comments
    • Goal, category, location, end date, milestones and, when you raise money for someone else, the beneficiary's name
    • Public display preferences (e.g., anonymous donations)
    • Campaign visibility, including the passcode or the email addresses you list for a private campaign
    • Likes, follows and GIFs you add to comments
    • What you give our AI tools: a description of your cause, a link to a campaign you ask us to import, a prompt for a cover image, or a photo you ask us to fit to a square
  • Donations and payment information

    • Donation amount, currency, date, and time
    • Optional tips to FundlyHub
    • Transaction identifiers and receipts
    • The name and email address you enter for your receipt, any message you leave, and whether you chose to give anonymously
    • Your email address, which is recorded when you enter it, including when a donation is not completed
    • Creator subscriptions you start or offer: the tier, price, billing period and status

    FundlyHub does not store full payment card numbers. Payment information is processed directly by our payment processor. We see only the card brand and the last four digits.

  • Ambassador program

    • Your application: full name, email address, location, an optional social media or website link, your relevant experience and why you want to be an ambassador
  • API keys

    • The name you give a key, and when it was created, last used and set to expire
    • We store a keyed hash of the key, not the key itself. The full key is shown to you once.
  • Communications

    • Customer support messages, including messages in the chat window
    • Feedback, surveys, dispute or fraud reports
    • Reports you file about a campaign
    • Messages you send to an organizer through "Contact the organizer", with the name and email address you enter. We pass the message on by email so the organizer can reply to you.

3.2 Information collected automatically

  • IP address and approximate location
  • Device identifiers, browser type, operating system
  • App usage data, logs, pages viewed, referring URLs
  • Cookies and similar technologies (see Section 8)
  • Sign-in history: the time, IP address, browser and device of each sign-in
  • A visitor ID: a random ID kept in a first-party cookie (see Section 8)
  • A device signature: a keyed, one-way hash of your IP address and browser details, saved with each donation (see Section 4.4)
  • Share link visits: when you open someone's personal share link, we record the link's code, the time, your visitor ID, your browser details, the site you came from (its domain only), any campaign tags on the link and a one-way hash of your IP address. The IP address itself is not stored with the visit.
  • At checkout: the language you are using FundlyHub in and, when your device settings point to the United States, your browser's time zone (see Section 4.1)
  • Product events measured with Google Analytics, such as sign-in, checkout steps, the amount and payment reference of a completed donation, searches (including the words you search for) and share clicks
  • Error reports and, for a sample of visits, a session recording in which all text is masked and images and media are blocked
  • A signal sent every 30 seconds while a campaign page is open, used to show how many people are viewing that campaign. We keep a one-way hash of your visitor ID for about 90 seconds and publish only the count.

3.3 Information from third parties

  • Payment processing: Stripe and Stripe Connect

    CYTY Inc. uses Stripe and Stripe Connect to process donations and facilitate payouts. Stripe provides us with information such as:

    • Transaction and payout status
    • Chargebacks and disputes
    • Fraud and risk indicators
    • Connected account onboarding and verification status
    • The card brand and last four digits, the type of payment method, and the country, city and postal code of the billing address

    Stripe processes personal information according to its own privacy and data-processing terms and may act as an independent data controller for regulatory, compliance, and fraud-prevention purposes.

  • Google and Apple sign-in

    If you sign in with Google or Apple, the provider tells us your name and email address and, when it sends one, your profile picture.

  • Analytics reports

    Google Analytics gives us reports on how the Services are used: visits, pages viewed, where visitors came from, general location and device type.

  • Public registers

    When an organization registers, we check its EIN against the IRS list of eligible organizations (Publication 78) and its name against the U.S. Treasury OFAC sanctions list. We check against our own copies of these public lists.

  • Campaigns you import

    If you paste a link to a campaign you run elsewhere, we fetch that public page and copy its title, story, goal, cover image and category into your draft.

4. How we use information

We use personal information to:

  1. Operate and maintain the FundlyHub Services
  2. Create and manage user accounts
  3. Host and display fundraisers and projects
  4. Process donations, tips, and payouts via Stripe Connect
  5. Provide customer support and respond to inquiries
  6. Detect, prevent, and investigate fraud, abuse, or security incidents
  7. Comply with legal, tax, accounting, and regulatory obligations
  8. Improve and develop the Services, including analytics and performance monitoring
  9. Send a reminder if you begin a donation and do not complete it (see Section 4.1)
  10. Review campaigns before they are published, using automatic checks and AI analysis (see Section 4.2)
  11. Translate campaign content into the languages of the Services (see Section 4.2)
  12. Provide the AI writing and image tools when you ask for them (see Section 4.2)
  13. Credit visits and donations to the person whose share link brought them (see Section 4.3)
  14. Keep the anonymous gifts of one person under one alias (see Section 4.4)
  15. Show public activity such as donor lists, recent gifts, leaderboards and achievements, subject to your privacy settings (see Section 5.3)
  16. Bill creator subscriptions through Stripe
  17. Send receipts and the email notifications you have turned on
  18. Verify organizations and review the documents they upload
  19. Add gifts you made without an account to your account when its verified email address matches the one you gave at checkout
  20. Work out approximate map coordinates from a billing postal code or city, for internal statistics. The coordinates and the postal code are not shown publicly.
  21. Alert our own team when a campaign is submitted or needs review

4.1 Incomplete donation reminders

If you enter your email address to make a donation and do not complete it, CYTY Inc. may send you up to two reminder emails, approximately one hour and one day afterwards, with a link to finish. No further reminders are sent about that donation.

These reminders are limited to recipients in the United States. That determination is made from your device settings (your browser's reported time zone and language) at the moment you enter your email address. It is an approximation, not a location lookup, and where the result is unclear no reminder is sent.

Every reminder contains a one-click unsubscribe link that requires no account and no sign-in. You will not receive a reminder if you have unsubscribed, if you have turned off donation reminders in your notification settings, if you chose to donate anonymously, or if the donation was in fact completed.

4.2 Automated review and AI tools

Before a campaign is published it passes an identity check of the organizer's profile (profile photo, first and last name, verified email address and phone number), an automatic content review and an AI analysis. For the AI analysis we send the campaign's title, summary, category, type, goal, location and story to OpenAI, and the beneficiary's name when the campaign is for someone else. The analysis returns a story quality score and suggestions. Campaigns the AI approves are published at once. Campaigns it is unsure about go to our team, usually within 24 hours. Otherwise you get a list of things to fix.

Each campaign also gets an internal trust score from 0 to 100, based on your profile, your payout verification status, the content of the campaign and your track record. Donors do not see it.

The same provider powers the optional tools in the campaign builder and the chat assistant: text suggestions, category detection, importing a campaign from a link, cover image generation and photo fitting. These tools receive what you give them.

Campaign titles, summaries, stories, updates and milestones are translated automatically into English, Russian, Ukrainian and Spanish. To do this we send the original text to our translation provider. A translated update carries a "Show original" link.

4.3 Share links and the ambassador program

When you share a fundraiser while signed in, FundlyHub gives you a personal link of the form fundlyhub.org/r/ followed by your code. When someone opens it we record the visit (see Section 3.2) and set or read the visitor ID cookie. If you are signed in when you open someone's link, the link's code is also saved on your account.

A donation is credited to the sharer when it arrives within 30 days of the visit. If the donor opened several people's links, the most recent one counts. Visits from bots and link previews are counted separately and are never credited with a donation.

Sharers who have the Ambassador role see the results in the ambassador portal: visits, where the clicks came from and the gifts credited to them. Donor names appear there only for donors who did not give anonymously, and donor email addresses never appear.

4.4 Anonymous gifts

If you tick "Make my donation anonymous", your name is hidden from the public donor list and from the organizer. If you were signed in, the gift still appears in your own donation history.

So that repeat anonymous gifts from one person appear as one anonymous donor, we link them using the first of these that is available: your account if you are signed in, an email address saved with the gift, the visitor ID cookie, or the device signature described in Section 3.2. A device signature is matched only against anonymous gifts from the last 30 days.

Publicly, an anonymous donor appears under a generated alias, such as "Kind Neighbor", and a key that cannot be turned back into your identity. We do not publish your name, your email address, your account ID or the device signature.

5. How we share information

5.1 Stripe and Stripe Connect

We share necessary personal and transactional information with Stripe to:

  • Process payments and payouts
  • Conduct identity verification and fraud prevention
  • Meet legal and regulatory requirements

To receive payouts, creators and organizations give Stripe their identity details and their bank account or debit card through Stripe's own onboarding form. A payout bank account record in our database holds no full account number or routing number: it can hold the account holder's name, the bank's name, the account type (checking or savings), the last four digits of the account number and of the routing number, Stripe's ID for the account, whether it is verified and whether it is the default, and when it was added, updated and verified. Creator subscriptions are also billed by Stripe.

Organizers using FundlyHub may receive limited donor information necessary to acknowledge donations and comply with applicable legal or tax obligations. At present the product shows organizers a donor's display name, the amount, the date and any message, and does not show them donor email addresses. If you give anonymously, your name is hidden from the public donor list and from the organizer.

5.2 Service providers

We may share information with service providers acting on our behalf, including:

  • Cloud hosting and infrastructure providers

    Amazon Web Services hosts the Services: servers, databases, file storage and delivery, and sign-in through Amazon Cognito. Upstash provides caching and rate limiting.

  • Analytics and monitoring services

    Google Analytics 4 measures page views and product events. Sentry software records errors and performance, with the signed-in user's ID, name and email address attached to an error report. Our Sentry is self-hosted in the United States.

  • Email and notification providers

    Amazon SES sends our email. Telegram carries alerts to our own team when a campaign is submitted: its title, summary, goal, category and the organizer's name.

  • Customer support platforms

    Chatwoot runs the chat window. If you are signed in, it receives your name, email address and profile picture so the team knows who is writing.

  • Security and fraud-prevention vendors

    Google reCAPTCHA checks for bots on the sign-in form and the donation forms.

  • AI and translation providers

    OpenAI powers campaign review, the writing and image tools, the chat assistant and translation.

These providers are contractually restricted from using personal information for any purpose other than providing services to CYTY Inc.

Some features also call outside services that receive only what the feature needs, not your account details:

  • Google or Apple: your sign-in request, if you choose to sign in with them
  • Firecrawl: the link you ask us to import a campaign from
  • Unsplash: the words you type to search stock photos
  • GIPHY: the words you type to search GIFs for a comment, where GIF comments are turned on
  • OpenStreetMap Nominatim: a billing postal code and city, or a campaign's location, to find its place on a map
  • Zippopotam: the ZIP code you enter to set your profile's city
  • Cloudflare Stream: videos uploaded to a campaign, where video upload is turned on

We also publish a list of the services that process data for FundlyHub on the Subprocessors page.

5.3 Public information

Certain information is public by design, including:

  • Fundraiser or project pages
  • Organizer display names or organization names
  • Donation display names and messages, subject to user privacy settings
  • Gifts: a named gift shows your name, profile photo, the amount and your message on the campaign page. The recent gifts on the home page can also show the city from your card's billing address. The live map of a campaign's supporters on the home page groups donors under the person whose share link brought them. An anonymous gift shows a generated alias and the amount, with no name, photo or city.
  • Donor pages: a donor who gave without an account, or anonymously, has a public page under the name they gave or under their alias. It shows gift totals, dates, rank and the public campaigns they supported. It never shows an email address.
  • Your profile: name, photo, handle, city and state, social links, the campaigns you run and your impact numbers. Unless you set your profile to private, it also shows your achievements, organization, the causes you support, your activity and who follows you.
  • Comments, campaign updates and like counts. Who liked something is not shown.
  • Leaderboards and search results, which can include campaigns, people, organizations and donors. Email addresses are never searched.
  • People who shared a campaign: their name and photo, with the visits and donations their links brought, in the campaign's "Endorsed by" list and in the FundlyHub Ambassadors section.
  • A verified organization's profile: its names, headquarters, founded year, team members and their positions, and any verification documents the organization chooses to show.

5.4 Legal and business transfers

We may disclose information:

  • To comply with applicable laws, regulations, or legal processes
  • To protect the rights, safety, and security of CYTY Inc., users, or the public
  • In connection with a merger, acquisition, financing, restructuring, or sale of assets involving CYTY Inc.

6. Data retention

CYTY Inc. retains personal information only as long as reasonably necessary for the purposes described in this Policy, including:

  • Providing the Services
  • Meeting legal, tax, and accounting requirements
  • Resolving disputes and enforcing agreements
  • Preventing fraud and abuse

Retention periods vary by data type and legal obligation.

Some records are kept so that we can keep a promise not to contact you again. The unsubscribe list stays in place, and the record of donation reminders already sent holds a keyed hash of the email address, not the address itself.

6.1 Deactivating your account

You can deactivate your account in Profile Settings. Deactivating hides your profile from other users, pauses your active campaigns and logs you out. You can reactivate at any time by signing back in. If you have active fundraisers with money raised, deactivation is blocked until those are resolved.

6.2 Deleting your account

You can ask us to delete your account by writing to tech@cyty.io.

7. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure.

The practices in place today are listed in the Trust Center.

8. Cookies and tracking technologies

8.1 What are cookies

Cookies are small text files stored on your device that help websites function and improve user experience. We may also use similar technologies such as pixels, SDKs, and local storage.

8.2 Types of cookies we use

  • Strictly necessary cookies

    • Required for authentication, security, and core functionality
    • Cannot be disabled through our systems
    • Examples: the sign-in cookies, which only our servers can read (one lasts 1 hour, the one that renews it lasts up to 90 days), and a 10-minute cookie used while you sign in with Google or Apple
  • Functional cookies

    • Remember user preferences and settings
    • Improve usability
    • Examples: your language, light or dark theme, recent searches, and the draft of a campaign you are building, which the website keeps in this browser. Some of these are kept in the browser's local storage, not in a cookie.
  • Analytics cookies

    • Measure usage and performance
    • Help improve features and reliability
    • We use Google Analytics 4 for this
  • Visitor ID cookie

    • A random ID in a first-party cookie named visitor_id, readable only by our servers and kept for up to two years
    • Used to credit donations to share links (see Section 4.3), to keep anonymous gifts from one browser under one alias (see Section 4.4) and to count how many people are viewing a campaign
  • Cookies set by other services

    • The payment form is loaded from Stripe, the bot check from Google reCAPTCHA and the chat window from Chatwoot
    • When a campaign embeds a video from YouTube, Vimeo, Wistia, Loom, Instagram, Facebook or TikTok, your browser loads the player from that site
    • These services may set their own cookies or use similar storage under their own privacy policies

FundlyHub does not use cookies for cross-context behavioral advertising.

8.3 Managing cookies

You can control or delete cookies through your browser or device settings. Disabling cookies may limit certain features of the Services.

8.4 Do Not Track and Global Privacy Control

Some browsers offer "Do Not Track" signals. FundlyHub does not currently respond to Do Not Track signals.

FundlyHub honors Global Privacy Control (GPC) signals where required by applicable law.

9. Children's privacy

The Services are not directed to children under the age of 13. CYTY Inc. does not knowingly collect personal information from children under 13. If such information is identified, it will be deleted.

10. California privacy notice (CCPA / CPRA)

This section applies to California residents.

10.1 Categories of personal information collected

  • Identifiers (name, email, phone number, IP address, cookie and device identifiers)
  • Commercial information (donation and transaction data)
  • Internet or network activity
  • Approximate geolocation data
  • User-generated content
  • Inferences used for platform functionality

10.2 Sale or sharing of personal information

CYTY Inc. does not sell personal information and does not share personal information for cross-context behavioral advertising as defined by California law.

10.3 California consumer rights

California residents may have the right to:

  • Know and access personal information
  • Request deletion of personal information
  • Request correction of inaccurate personal information
  • Opt out of sale or sharing (if applicable)
  • Not be discriminated against for exercising privacy rights

10.4 Exercising your rights

Requests may be submitted by contacting:

Email: tech@cyty.io

We will verify requests as required by law.

11. Other U.S. compliance disclosures

  • FTC Act

    This Policy is intended to prevent unfair or deceptive practices.

  • CAN-SPAM

    Every non-transactional email includes a one-click unsubscribe link that works without an account or sign-in. The confirmation page names the address and tells you what it is about to stop before anything changes, and it always offers a single press that stops every non-transactional email to that address, whichever message you followed the link from. Receipts for donations you make and messages about your account's security are still delivered.

  • TCPA

    SMS communications, if offered, require appropriate consent.

  • State privacy laws

    CYTY Inc. may extend similar rights to residents of other U.S. states as required.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Updates will be reflected by the "Last Updated" date. Material changes may be communicated through the Services or by email.

13. Contact us

Company
CYTY Inc.
DBA FundlyHub
Business address
262 Chapman Rd, Ste 240
Newark, County of New Castle
Delaware, USA
Physical address
6929 Sunrise Blvd #105B
Citrus Heights, CA 95610