Privacy first

The safest recordis the one we never collect.

Shelters and food banks hold some of the most sensitive information about people in crisis. GiveKrate is built so that information never has to touch a donation platform.

We don't store client or guest records

GiveKrate tracks goods, not the people receiving them. There is no field for a guest's name, case number, immigration status, or shelter stay because there's no reason for a donation platform to hold it.

Donors give the minimum

An email address and a name for the receipt. Addresses are optional and only used to match needs by distance; you can turn location matching off entirely and browse by organization instead.

Access is by role, not by account

Volunteers can log an intake without seeing donor contact details or financial reports. Managers grant and revoke roles, and every role change is written to an audit log.

Encrypted in transit and at rest

All traffic runs over TLS, data is encrypted at rest, and backups are encrypted with separate keys. Access to production data is limited and logged.

Your data leaves when you do

Organizations can export a full copy of their inventory, intake, and reporting history at any time, and request deletion. Deletion is completed within 30 days, backups included.

No selling, no ad tracking

We don't sell or rent donor data, and we don't run third-party advertising trackers on donor-facing pages. Analytics are aggregate and cookie-light.

Data retention at a glance

  • Donation and intake recordsKept as long as the organization's account is active. They're the audit trail
  • Donor contact detailsKept while you have an account; deleted within 30 days of a deletion request
  • Photos taken at intakeRetained 90 days, then purged; the drafted line items remain
  • Access and audit logsRetained 12 months

Questions from a board, funder, or compliance officer? Ask us directly.