Version 2026-08-10

Privacy Notice

Data handled

GFSN stores account name, email, password hash, role, account timestamps, adult confirmation, accepted legal versions, contribution country/type/date/description/quantities, calculated estimates, status, admin notes or reasons, audit events, and an optional private photo. We do not ask for beneficiary identity, payment details, bank data, or recipient selection.

Purposes

Data is used to authenticate accounts, save private records, calculate estimates, let admins review records, maintain an audit trail, produce verified-only aggregate statistics, and protect the service.

Who can see data

You can see your own records. Admins can see account and contribution details needed for review. Public impact pages show only aggregate verified totals—never names, emails, descriptions, photos, or individual users.

Photos

Photos are optional, sanitized by re-encoding to remove embedded metadata where supported, stored in protected storage, and delivered only through an authenticated owner/admin endpoint. Do not upload identifiable beneficiaries, children, or unrelated third parties.

Storage and security

The application uses password hashing, secure session cookies, CSRF protection, prepared database statements, private file names, MIME validation, output escaping, and access checks. Local laptop hosting is not suitable proof of secure public deployment. Backups and logs may contain protected data and must remain outside public access.

Retention and choices

Pending records can be withdrawn and become voided. Administrative correction and audit history are retained for accountability. Final deletion/retention rules and a channel for access or correction requests must be approved before launch.

Operator

Operator: Vivan Goel. Public contact details require confirmation. Qualified privacy and UAE review remain release gates.